**Ujir Soni ** is a Chartered Accountant, Cybersecurity Citizen, CEO of Advanced Threat Solutions, and has been in the security-related industry for the past 10 years.
Image: Supplied
South Africa's private security industry has become too important to remain trapped in an old business model.
With hundreds of thousands of security officers protecting homes, businesses, infrastructure and communities, the sector is an essential part of the country's security architecture. PSiRA's current strategy emphasises professionalisation and stronger regulation. Yet professionalisation cannot mean merely better compliance. It must mean transforming security companies into integrated risk-management businesses.
That transformation requires three professions to move from the back office to the centre of the security enterprise: accounting, auditing and cybersecurity.
Accounting may seem far removed from physical security, but it is fundamental to it. Security companies manage large workforces, payrolls, overtime, vehicles, equipment, contracts, procurement and client payments.
Weak financial controls create opportunities for fraud, corruption, ghost employees, inflated invoices and resource diversion. A company unable to account for its own assets and expenditure cannot credibly protect the assets of its clients. Accounting therefore becomes a security control: it provides the financial intelligence required to identify anomalies, leakage and emerging operational risks.
Auditing goes further. Its role should no longer be confined to checking whether financial statements are accurate. Modern security requires assurance that the organisation is doing what it claims to do. Are officers deployed where contracts require them? Are patrols actually conducted? Are access-control systems functioning? Are incident reports reliable? Are suppliers legitimate? Are surveillance systems maintained? Are client records protected?
Internal audit should become an early-warning mechanism, connecting financial, operational, technological and compliance risks. PSiRA's regulatory mandate already places public interest and effective control at the heart of private security. The next step is for security companies themselves to embrace assurance as a competitive advantage.
Then comes cybersecurity, the new perimeter.
The traditional security perimeter was a wall, gate, fence or armed guard. Today it is also a network. Security companies increasingly depend on connected cameras, biometric systems, access-control platforms, cloud services, GPS tracking, mobile applications and databases. Compromise the technology and criminals may bypass the physical perimeter altogether.
South Africa's government has acknowledged that the threat environment now includes hybrid threats and is investing in cybersecurity and artificial intelligence. The 2025 Cybersecurity Indaba similarly highlighted AI-powered attacks, deepfakes and data manipulation. For security companies, the message is blunt: a company that cannot secure its own digital infrastructure is selling protection it does not possess.
But the most visible transformation may come from artificial intelligence.
AI-enabled cameras can increasingly detect people, vehicles, objects, unusual movement and predefined behaviours, while software can analyse video continuously rather than relying on a human operator to watch multiple screens. South African technology providers are already deploying AI video analytics, and the local CCTV market is projected to expand substantially. This technology will inevitably automate some repetitive surveillance work.
That does not mean the guard becomes obsolete. This is not technological substitution; it is the redesign of professional security itself.
It means the guard's role must become more valuable.
A camera does not possess human judgement. It cannot reassure a frightened resident, manage a confrontation sensitively, search a complex scene, protect a vulnerable person or make every contextual decision required during an emergency. Nor can it replace the physical presence that deters crime. The future should be humans augmented by machines.
AI can watch continuously. Guards can interpret, verify, intervene and respond. That division of labour could make security both more effective and more humane. Machines can undertake repetitive observation, flag anomalies and reduce the burden of screen-watching. Trained officers can concentrate on investigation, response, customer interaction, access control and situations where physical judgement is indispensable.
This could also change the economics of guarding. Rather than deploying large numbers of people to perform monotonous observation, security companies could use technology to monitor wider areas while investing more heavily in fewer but better-trained officers. The objective should be to move people from repetitive tasks into higher-value security work, while creating careers in control-room operations, AI supervision, cybersecurity, investigation, risk analysis and technology maintenance.
The result could be a more risk-averse industry in the best possible sense: not timid, but systematically unwilling to tolerate preventable risk.
Consider the implications for a manufacturing plant. An AI camera identifies an unusual movement; a cybersecurity system detects an attempted intrusion; an auditor identifies a control weakness; an accountant spots an anomalous procurement transaction; and a trained response officer investigates the physical situation. These are no longer separate security events. They are interconnected indicators of risk.
The same logic applies to homes. Smart cameras, alarms, access controls and human response can create layers of protection in which technology detects, people decide and trained officers act. The objective is not surveillance for its own sake. It is earlier detection, faster intervention and fewer losses.
But there is a serious warning. AI surveillance can create new risks: privacy violations, biased identification, excessive monitoring, insecure databases and decisions made without sufficient human oversight. South Africa's regulatory environment, including POPIA and the Cybercrimes Act, makes responsible data governance increasingly important. Security companies must therefore become more technologically capable without becoming less accountable.
The industry's future depends on understanding that security is no longer a single profession. It is an ecosystem.
The guard remains its human face and physical frontline. The accountant protects its financial integrity. The auditor tests whether its controls can be trusted. The cybersecurity professional protects its digital perimeter. AI extends its eyes and ears. Management must integrate all of them into one intelligence-led risk system.
South Africa does not need a security industry that simply employs more people to stand watch. It needs a security industry capable of knowing what to watch, why it matters, how risks connect and when human intervention is required.
The security company of tomorrow will therefore not abandon the guard. It will professionalise the guard, augment the guard and place the guard within a far more intelligent security architecture.
That is the real transition: from guarding assets to managing risk.
And if South Africa gets it right, the prize is not merely a more technologically advanced security industry. It is safer homes, safer businesses, better-protected infrastructure and a security profession equipped for the risks of the twenty-first century.
Ujir Soni is a Chartered Accountant, Cybersecurity Citizen, CEO of Advanced Threat Solutions, and has been in the security-related industry for the past 10 years.