African industries may overestimate cyber defences

SMART Fire & Safety 2025 Information Security

KnowBe4 released a new report, Africa Human Risk Management Report 20251. The report reveals a mismatch between employer perceptions and employee experience of organisational cybersecurity in key African industries, with potentially costly consequences.

The report captures insights from cybersecurity decision-makers across 30 African countries. One of the biggest themes the survey uncovers is a mismatch between perception and reality; what employers believe is not necessarily what employees feel or experience.

In key growth industries across the continent, cybersecurity preparedness and the actual structures needed to support secure behaviour seem misaligned.

The report highlights, for instance, that just 10% of cybersecurity leaders are fully confident that staff would report a phishing attack or other cyberthreat, despite rating employee security awareness of cyberthreats at four out of five or higher. Furthermore, a significant perception gap exists between decision-makers and general employees in Africa regarding security awareness training, with 68% of leaders believing that training is tailored to roles, compared to only a third of employees feeling adequately trained.

This contrast is underscored by the data, which shows a difference between what leaders believe about the effectiveness of security awareness training and what employees actually experience. This is further emphasised by the fact that many organisations only conduct annual or biannual training that is too generic to effectively change behaviour, contributing to uncertainty about its effectiveness.

Previous end user-based responses2 revealed that only 43% of African respondents felt confident in their ability to recognise a cyberthreat, and just one in three believed their security awareness training was adequately tailored to their role. This comparison suggests the development of a dangerous perception gap in many organisations.

“There is a disconnect between what leaders think is happening and what employees are actually experiencing,” says Anna Collard, SVP content strategy & evangelist at KnowBe4 Africa. “The data shows that without procedural and cultural follow-through, awareness simply does not translate into readiness.”

The KnowBe4 Africa Human Risk Management Report 2025 offers a glimpse into human cyber risk, reflecting the real challenges – and overlooked opportunities – facing African organisations.

Key findings

Confidence vs. awareness: While cybersecurity awareness is high, leaders express uncertainty about their workforce’s ability to act on that awareness. Many feel employees may overestimate their capabilities in recognising, reporting, and mitigating threats. Larger organisations face greater challenges as they tend to train less frequently (often biannually or annually) and have lower confidence in their employees’ incident response capabilities compared to smaller organisations.

The need for adaptive and personalised security awareness training: Many organisations, across various sectors, fail to personalise security awareness training to specific roles or risk exposures. Sectors such as manufacturing and healthcare are particularly susceptible to using one-size-fits-all training approaches, where 50% and 40%, respectively, report no personalisation whatsoever. Tailoring addresses the specific needs and risks associated with different roles and sectors, resulting in more effective security awareness.

Widespread BYOD usage: A large percentage of employees (between 41% and 80%) use their personal devices for work. The BYOD (Bring Your Own Device) trend introduces security risks because personal devices often lack adequate security measures. This can make organisations more vulnerable to breaches.

AI policy development is lagging: Many organisations (46%) are still in the process of developing policies for using AI tools in the workplace. Without clear guidelines, employees might use AI in ways that create security vulnerabilities for their organisations. Establishing clear AI governance is crucial to mitigate these risks.

Regional variation: Southern Africa trains more, East Africa governs AI better, and West/Central Africa sees the most human-related security incidents.

“This report reveals a critical paradox in African cybersecurity: while organisations feel aware and prepared, significant blind spots remain, especially concerning how they manage human risk,” Collard notes. “The continent’s cybersecurity posture may be more confident than it is truly resilient.”

The report concludes with a roadmap for turning awareness into action, including role-specific training, measurable outcomes, AI policy development and better reporting structures.

[Resources]

[1] tinyurl.com/49svc9ta

[2] tinyurl.com/39r4ncmv




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.