African organisations are overestimating their cybersecurity readiness while under-managing the human risks at the heart of their digital defences, according to the KnowBe4 Africa Human Risk Management Report 2025. The study, based on input from 124 senior cybersecurity professionals across 30 countries, highlights a troubling disconnect between perceived awareness and actual preparedness.
Despite most organisations ranking policy awareness at 4 out of 5, only 10% of decision-makers expressed full confidence in their teams’ ability to report threats. In fact, over 41% cited measuring the effectiveness of security awareness training (SAT) as their biggest challenge.
“The human element in cybersecurity isn’t just misunderstood, it’s under-managed,” the report notes, pointing to gaps in incident reporting, training customisation, and emerging technology governance.
BYOD Culture and Shadow AI Fuel Emerging Threats
The report reveals that up to 80% of employees across Africa use personal devices for work, with North Africa showing the highest BYOD (Bring Your Own Device) exposure. At the same time, 46% of organisations admitted their AI governance policies are still “in development,” leaving room for unregulated tool use, known as “shadow AI”, to grow unchecked.
Training Misalignment and Infrequent Testing
While 68% of respondents claimed to tailor SAT by role, the report suggests much of this is “aspirational.” Many organisations still rely on one-size-fits-all training, with limited behavioural tracking or accountability. Simulated phishing tests, a key tool in behavioural conditioning, were infrequent, only 7% of firms conduct them monthly, and 40% do so just twice a year.
This lack of training frequency, the report warns, exposes companies to the “prevalence effect,” where rare threats are easily missed due to unfamiliarity.
Regional and Role-Based Disparities
Readiness levels vary significantly by region. East Africa leads in AI policy adoption, while West and Central Africa report the highest rates of human-related security incidents. Southern Africa conducts training more frequently, but lags in AI governance.
Role-based perceptions also diverge. While CISOs (Chief Information Security Officers) and CIOs (Chief Information Officers) emphasise strategic risks such as policy gaps and reporting failures, security awareness leads focus more on content relevance and delivery. Security staff, closest to day-to-day operations, often feel under-supported due to unclear escalation processes.
Gap Between Leaders and Employees
The report also compares findings with data from the 2024 Annual African Cybersecurity & Awareness Report, which surveyed employees directly. While 50% of leaders expressed confidence in employees’ threat reporting abilities, only 43% of employees felt fully confident recognising threats. Similarly, while most leaders claimed role-specific training, only one-third of employees agreed they received training suited to their job.
Recommendations: From Awareness to Action
The report calls for urgent structural reforms, including:
- Role-specific training tied to actual job functions.
- Clear metrics to measure training outcomes and employee readiness.
- Formal incident reporting frameworks with transparent escalation paths.
- Enforced AI policies to manage the growing risks of unregulated tool use.
- Context-specific strategies that reflect regional and sectoral nuances.
As digital transformation accelerates across Africa, the findings underline the need for not just more awareness, but deeper, actionable resilience. Cybersecurity, the report argues, must be embedded across both systems and behaviours to secure Africa’s future.
