{"id":79106,"date":"2025-08-04T15:05:35","date_gmt":"2025-08-04T12:05:35","guid":{"rendered":"https:\/\/gulftech-news.com\/en\/?p=79106"},"modified":"2025-08-04T15:05:36","modified_gmt":"2025-08-04T12:05:36","slug":"from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them","status":"publish","type":"post","link":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/","title":{"rendered":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them"},"content":{"rendered":"\n<p><strong><em>The KnowBe4 Africa Human Risk Management Report 2025 reveals mismatches between leadership belief and employee reality<\/em><\/strong><\/p>\n\n\n\n<p>Cybersecurity in Africa is entering a new phase. As organisations mature their defences and invest in security awareness training (SAT), a difficult-to-spot, but critical gap is emerging \u2013 not between tools and cyber threats, but between what leaders believe about their employees, and what they actually experience.<\/p>\n\n\n\n<p>The&nbsp;<strong>KnowBe4 Africa Human Risk Management Report 2025&nbsp;<\/strong>(<a href=\"https:\/\/r.news.africa-wire.com\/mk\/cl\/f\/sh\/7nVU1aA2ng5gPlTjlvs1RxWEe5g65sx\/6EjGSycKBF6O\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/apo-opa.co\/4fhcmPo<\/a>) provides a glimpse into this mismatch. The results show that many leaders are overestimating their employees\u2019&nbsp; preparedness, and underestimating the gaps in trust, training, and action.<\/p>\n\n\n\n<p>Says Anna Collard, SVP of Content Strategy and Evangelist at KnowBe4 Africa, \u201cIt\u2019s not just that awareness alone isn\u2019t enough \u2013 it\u2019s that the level of employee\u2019s awareness is being misunderstood by the organisational leaders responsible for it..\u201d<\/p>\n\n\n\n<p><strong>The perception gap is growing, but measurable<\/strong><\/p>\n\n\n\n<p>While 50% of decision-makers in 2025 rate employee cyber threat-reporting confidence at 4 out of 5, in 2024, only 43% of employees said that they&nbsp; felt confident recognising a threat, while one-third disagreed that their training was sufficient.<\/p>\n\n\n\n<p>68% of decision-makers believe that SAT within their organisations is tailored by role. But only 33% of employees in 2024 felt that to be true \u2013 with 16% actively disagreeing.<\/p>\n\n\n\n<p>The implications are serious, because a workforce that appears trained and aware on paper may in fact be uncertain, unsupported, and vulnerable.<\/p>\n\n\n\n<p>\u201cThis discrepancy between perception and experience is exactly where human risk thrives,\u201d says Collard. \u201cIf leaders don\u2019t correct course, they\u2019re building security strategies on false confidence.\u201d<\/p>\n\n\n\n<p><strong>Why measuring awareness is no longer enough<\/strong><\/p>\n\n\n\n<p>One of the most frequently cited challenges in the report is deceptively simple: measuring if SAT&nbsp; works. More than four in ten respondents said that they struggle to track whether their security awareness programmes translate into safer behaviours.<\/p>\n\n\n\n<p>A key contributing factor, identified in the report,&nbsp; is that many organisations still rely on one-size-fits-all SAT, often delivered only annually or biannually, without role-specific customisation or behavioural feedback loops.<\/p>\n\n\n\n<p>While 68% say they offer role-based training, this claim is undermined by the fact that \u201clack of role alignment\u201d remains one of the top challenges respondents report. The discrepancy is clearest in sectors like manufacturing and healthcare, where generic SAT is most common.<\/p>\n\n\n\n<p>Size, it seems, also matters. Larger organisations are consistently less confident in employee readiness, train less frequently, and struggle more to measure outcomes..<\/p>\n\n\n\n<p>Collard says: \u201cAwareness without action is like an alarm that no one responds to. Organisations are investing in security awareness training, but without the structure, tailoring, and follow-through to translate that into secure behaviour.\u201d<\/p>\n\n\n\n<p><strong>Beyond BYOD: The new blind spot is AI<\/strong><\/p>\n\n\n\n<p>One of the most urgent themes to emerge is the rapid rise of \u201cshadow AI\u201d use. With nearly half of all organisations still busy developing formal AI policies, yet up to 80% of employees using personal devices for work, the risk of unmonitored, unsanctioned AI usage is rising fast.<\/p>\n\n\n\n<p>East Africa is leading the way with more proactive AI governance, while Southern Africa, despite topping training frequency, lags behind on AI policy implementation.<\/p>\n\n\n\n<p>\u201cTechnology has moved faster than policy,\u201d Collard explains. \u201cAnd unless AI tools are properly governed, they become as much a risk vector as they are an asset.\u201d<\/p>\n\n\n\n<p><strong>The road ahead: Action, alongside awareness<\/strong><\/p>\n\n\n\n<p>This report outlines five imperatives for African organisations:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Customise SAT by role\u00a0<em>and\u00a0<\/em>risk exposure.<\/li>\n\n\n\n<li>Track what matters \u2013 not just participation, but\u00a0<em>behavioural outcomes<\/em>.<\/li>\n\n\n\n<li>Formalise reporting structures employees trust and understand.<\/li>\n\n\n\n<li>Close the AI policy gap before misuse becomes systemic.<\/li>\n\n\n\n<li>Contextualise strategies based on region and sector \u2013 because resilience is not one-size-fits-all.<\/li>\n<\/ol>\n\n\n\n<p>\u201cThe human element is often spoken about, but rarely measured in ways that lead to action that acknowledges context. Our goal is to help organisations stop guessing and start structuring their defences around real, contextual insights,\u201dsays Collard.<\/p>\n\n\n\n<p>\u201cThis is a moment to move from compliance-driven box-ticking to culture-driven resilience. We have the data. Now we need the will.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The KnowBe4 Africa Human Risk Management Report 2025 reveals mismatches between leadership belief and employee reality Cybersecurity in Africa is entering a new phase. As organisations mature their defences and invest in security awareness training (SAT), a difficult-to-spot, but critical gap is emerging \u2013 not between tools and cyber threats, but between what leaders believe &hellip;<\/p>\n","protected":false},"author":2,"featured_media":79107,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[644],"tags":[3399,1034],"class_list":["post-79106","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-communications-technology","tag-cisos","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News<\/title>\n<meta name=\"description\" content=\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News\" \/>\n<meta property=\"og:description\" content=\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/\" \/>\n<meta property=\"og:site_name\" content=\"Gulf Tech News\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-04T12:05:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-04T12:05:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121\" \/>\n\t<meta property=\"og:image:width\" content=\"250\" \/>\n\t<meta property=\"og:image:height\" content=\"65\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"bessan helmi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"bessan helmi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/\",\"url\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/\",\"name\":\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News\",\"isPartOf\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121\",\"datePublished\":\"2025-08-04T12:05:35+00:00\",\"dateModified\":\"2025-08-04T12:05:36+00:00\",\"author\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\"},\"description\":\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them\",\"breadcrumb\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage\",\"url\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121\",\"contentUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121\",\"width\":250,\"height\":65,\"caption\":\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gulftech-news.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\",\"url\":\"https:\/\/gulftech-news.com\/en\/\",\"name\":\"Gulf Tech News\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gulftech-news.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\",\"name\":\"bessan helmi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"caption\":\"bessan helmi\"},\"url\":\"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News","description":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/","og_locale":"en_US","og_type":"article","og_title":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News","og_description":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them","og_url":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/","og_site_name":"Gulf Tech News","article_published_time":"2025-08-04T12:05:35+00:00","article_modified_time":"2025-08-04T12:05:36+00:00","og_image":[{"width":250,"height":65,"url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121","type":"image\/png"}],"author":"bessan helmi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"bessan helmi","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/","url":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/","name":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them - Gulf Tech News","isPartOf":{"@id":"https:\/\/gulftech-news.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage"},"image":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage"},"thumbnailUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121","datePublished":"2025-08-04T12:05:35+00:00","dateModified":"2025-08-04T12:05:36+00:00","author":{"@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c"},"description":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them","breadcrumb":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#primaryimage","url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121","contentUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/08\/unnamed.png?v=1754309121","width":250,"height":65,"caption":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them"},{"@type":"BreadcrumbList","@id":"https:\/\/gulftech-news.com\/en\/2025\/08\/04\/from-perception-to-protection-what-africas-chief-information-security-officers-cisos-dont-know-about-employees-could-cost-them\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gulftech-news.com\/en\/"},{"@type":"ListItem","position":2,"name":"From perception to protection: What Africa\u2019s Chief Information Security Officers (CISOs) don\u2019t know about employees could cost them"}]},{"@type":"WebSite","@id":"https:\/\/gulftech-news.com\/en\/#website","url":"https:\/\/gulftech-news.com\/en\/","name":"Gulf Tech News","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gulftech-news.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c","name":"bessan helmi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","caption":"bessan helmi"},"url":"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/"}]}},"_links":{"self":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/79106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/comments?post=79106"}],"version-history":[{"count":1,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/79106\/revisions"}],"predecessor-version":[{"id":79108,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/79106\/revisions\/79108"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media\/79107"}],"wp:attachment":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media?parent=79106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/categories?post=79106"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/tags?post=79106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}