New Report Highlights a Paradox in Africa’s Cybersecurity Readiness
A new report by KnowBe4 has revealed a worrying disconnect between how African organisations perceive their cybersecurity readiness and the reality experienced by employees. The Africa Human Risk Management Report 2025, which surveyed decision-makers across 30 countries, highlights a mismatch that could leave key industries dangerously exposed to cyberattacks. At the heart of the findings

New Report Highlights a Paradox in Africa’s Cybersecurity Readiness
A new report by KnowBe4 has revealed a worrying disconnect between how African organisations perceive their cybersecurity readiness and the reality experienced by employees. The Africa Human Risk Management Report 2025, which surveyed decision-makers across 30 countries, highlights a mismatch that could leave key industries dangerously exposed to cyberattacks.
At the heart of the findings is a paradox while leaders believe their organisations are well-prepared, employees often feel undertrained and uncertain about how to respond to threats. For instance, although most cybersecurity leaders rate employee awareness of cyber threats highly scoring four out of five or more only 10% are confident staff would report a phishing attempt or other suspicious activity. This suggests that awareness is not necessarily translating into action.
Training Gaps and Misaligned Perceptions
Another striking gap exists around training. The report shows that 68% of leaders believe training is tailored to specific roles, yet only one in three employees agrees. Many organisations continue to rely on generic, annual or biannual training sessions, which do little to build lasting behavioural change. Industries such as manufacturing and healthcare are especially at risk, with around half admitting their training programmes lack any personalisation.
This lack of role-specific education is contributing to low confidence among employees themselves. Earlier end-user surveys revealed that just 43% of African staff feel confident they can recognise a cyber threat, and only one in three believes their training reflects their actual work risks. The result is a widening perception gap that could prove costly in the event of a major cyber incident.
Human Risk Factors Compounding Cybersecurity Threats
Beyond training, other human risk factors are compounding the challenge. The report highlights the widespread use of personal devices for work (BYOD), with between 41% and 80% of employees admitting to the practice. These devices often lack enterprise-grade security, creating additional vulnerabilities for attackers to exploit.
Another concern is the slow pace of AI policy development. Nearly half of organisations are still working on formal guidelines for AI use in the workplace. Without clear governance, employees may unintentionally expose sensitive data or create new points of weakness through unsanctioned AI tools.
Regional Insights Across Africa
Regional differences also emerged. Southern Africa tends to conduct more frequent training, East Africa is ahead in AI governance, while West and Central Africa experience the highest rates of human-related security incidents.
Turning Awareness into Action
Anna Collard, SVP content strategy and evangelist at KnowBe4 Africa, warns: “Awareness doesn’t automatically translate into readiness. Without cultural and procedural support, organisations will remain vulnerable.”
The report concludes with a roadmap urging African businesses to turn awareness into action. This includes frequent, role-specific training, clear AI governance frameworks, improved reporting mechanisms, and measurable outcomes. Without such steps, organisations risk overestimating their defences and underestimating the human risks that remain the weakest link in cybersecurity.



