DStv Channel 403 Friday, 04 September 2026

Making Sense | Could Your Smartwatch Put Your Company At Risk? | 4 September 2026

The Next Cybersecurity Boundary Is No Longer The Device

Wearable technology is exposing a deeper weakness in workplace security: many organisations still govern technology by object, while risk increasingly travels through capability.

For years, the corporate security model has been built around recognisable endpoints. A laptop is enrolled, a phone is managed, a USB drive is restricted, and access is granted or denied according to the device in front of the IT team. That logic works only while technology stays inside familiar categories. Once cameras, messaging, cloud processing and artificial intelligence migrate into watches, rings and glasses, the label on the object tells an organisation less and less about the risk it carries.

The real shift is from devices to capabilities

A smartwatch is easy to dismiss as an accessory until it begins displaying company email, calendar information or private messages. Smart glasses may look like ordinary eyewear while carrying recording or audio functions. The important distinction is therefore not whether the object resembles a computer. It is whether it can see, hear, store, display, transmit or process information that belongs inside a controlled environment.

That distinction exposes a weakness in conventional technology policy. A document that names laptops, mobile phones and tablets may be perfectly sensible when it is written, yet become outdated without a single rule technically changing. The underlying security principles may still be sound, but the categories around them have moved. As Tebogo Sibidla observes, businesses often categorise technology according to how it looks rather than examining its actual capabilities.

The more durable approach is therefore to govern behaviour rather than product labels. Recording remains recording whether the camera sits inside a phone or a pair of glasses. Data transfer remains data transfer whether it happens through a laptop or a watch. External AI processing raises the same control questions regardless of the shape of the device initiating it.

The weakest point may be ordinary behaviour

The most revealing risk created by wearables is that information does not need to be stolen in the dramatic sense to be exposed. A notification can appear on a bright watch face while its owner is sitting in public. A calendar can reveal that a confidential meeting is taking place. Smart glasses can potentially capture what their wearer is looking at, while an AI feature may need to send information elsewhere before returning a summary or response.

Those scenarios blur the line between a cyber incident and an everyday action. The employee may not be acting maliciously. The technology may be functioning exactly

as designed. Yet the organisation can still lose control over information because convenience has quietly changed where that information is visible, processed or stored.

That is an important shift in thinking. Cybersecurity is often imagined as defending against hostile action from outside an organisation. Wearables remind businesses that exposure can also emerge from perfectly ordinary behaviour inside it. The security question is no longer only whether somebody can break in. It is whether information can drift out through functions so normal that nobody thinks of them as security events.

Governance has to follow the information

This is why the obvious response, simply banning the device, is unlikely to be enough. Wearable technology is moving closer to ordinary life, and some devices combine personal, practical and professional functions. The organisation therefore has to distinguish between the object itself and the particular capability creating the risk.

That demands greater coherence between policies that are often written separately. IT rules, artificial-intelligence policies, confidentiality requirements and bring-your-own-device frameworks cannot operate as isolated documents if one personal device can interact with all four at once. Sibidla’s argument is that when personal technology interacts with company systems or information, employees should understand that company rules follow that interaction.

The same principle should shape policy design. Instead of trying to predict every product that may enter the workplace, organisations can ask more durable questions. What information can this technology access? What can it capture? Where can that information travel? Who can process it? What happens once control moves beyond the employee or the company?

The policy challenge is bigger than wearables

Smartwatches and smart glasses matter because they expose the problem early. The same governance gap will return as computing capability disappears into more ordinary objects. If policy remains tied to product names, organisations will continually find themselves writing rules for technology that has already changed shape.

A capability-based approach has a better chance of surviving that cycle. It recognises that the object is temporary while the underlying risks are remarkably consistent: access, visibility, recording, transmission, processing and control.

Cybersecurity used to be largely about protecting the machines employees used. Increasingly, it will be about protecting information as computing becomes harder to see. The organisations best prepared for that shift will not be those with the longest list of prohibited gadgets, but those whose rules still make sense when the computer no longer looks like a computer.

References

Making Sense, 04 September 2026. Gareth Edwards in conversation with Tebogo Sibidla, Director at Werksmans Attorneys.

Catch up on all Making Sense episodes here:  https://www.enca.com/making-sense-podcast

You May Also Like