Conference paper · 2020

Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective

Sadiq Nasir & Narasimha Rao VajjhalaiD

Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020), pp. 187–190, IADIS Press · Published

Scopus

Research summary

The summary, key findings, methodology and relevance notes below are this website’s own description of the paper, written from the published abstract and text. The official abstract and citation details are given further down.

The Problem
Information security awareness and compliance are low in sub-Saharan Africa, and the behavioural, social, cultural and organizational causes in African SMEs are largely ignored by a literature centred on developed countries.
The Methodology
Research design paper for an interpretivist, qualitative, multisite exploratory case study: audio-recorded in-depth personal interviews with 50 managers across 20 medium-sized companies in Nigeria (two per sector across ten key economic sectors).
The Core Finding
The paper establishes an interpretivist, multisite case-study design — in-depth interviews with 50 managers in 20 medium-sized Nigerian companies across ten economic sectors — for identifying the non-technical drivers of information security compliance in SMEs.
The Citation
Nasir, S., & Vajjhala, N. R. (2020). Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective. In Miguel Baptista Nunes, Pedro Isaías, Philip Powell, Boyan Bontchev (Eds.), Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020) (pp. 187–190). IADIS Press. https://www.iadisportal.org/digital-library/evaluating-information-security-awareness-and-compliance-in-sub-saharan-africa-an-interpretivist-perspective

What question does this paper answer?

What social, cultural, organisational and behavioural factors influence the adoption of, and compliance with, information security policies in small and medium-sized enterprises in Nigeria, the most populous sub-Saharan African country?

What did the study find, in detail?

This short paper sets out an interpretivist, qualitative, multisite exploratory case study designed to identify the significant information security awareness and compliance challenges facing Nigerian SMEs. It argues that low awareness is only partly explained by Internet penetration, infrastructure, literacy and technology costs, and that behavioural, social, cultural and organisational issues are often ignored, especially for SMEs in sub-Saharan Africa. The design draws on audio-recorded in-depth interviews with 50 managers in 20 medium-sized Nigerian companies, two from each of ten key economic sectors.

Why does it matter?

Most information security awareness and compliance literature comes from developed countries or from Asia and the Middle East; evidence on African SMEs is scarce. Understanding the human and organisational factors behind non-compliance could help leaders avoid the loss of brand equity and revenue that follows security breaches.

Key findings

  1. Information security awareness and compliance are at low levels in sub-Saharan Africa, partly because of low Internet penetration, inadequate infrastructure, low literacy and the cost of new technology.
  2. Behavioural, social, cultural and organisational issues that also shape awareness and compliance are often ignored in the literature, which is centred on developed countries and, to some extent, Asia and the Middle East.
  3. The study is designed as an interpretivist, qualitative, multisite, exploratory case study of SMEs in Nigeria, the most populous sub-Saharan African country.
  4. Data are to come from audio-recorded in-depth interviews with 50 managers in 20 medium-sized companies spanning the ten key sectors of the Nigerian economy.

Source: Nasir & Vajjhala (2020), Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020), pp. 187–190, IADIS Press.

Study at a glance

Design and results of Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective
QuestionWhich social, cultural, organisational and behavioural factors influence information security policy adoption and compliance in Nigerian SMEs?
DesignInterpretivist, qualitative, multisite, exploratory case study (design described; future tense in the abstract)
Sample50 managers from different departments in 20 medium-sized Nigerian companies — two from each of ten key economic sectors
Data collectionAudio-recorded, in-depth personal interviews
Gap addressedLimited literature on information security awareness and compliance in African SMEs
Intended contributionHelp organisational leaders maintain higher information security and avoid breach-related loss of brand equity and revenue
CitationNasir & Vajjhala (2020)

Abstract

Information security awareness and compliance are at low levels in Sub-Saharan African countries. The low level of awareness is partly because of several factors, including low Internet penetration rates, lack of adequate technological infrastructure, low levels of literacy, and high costs of acquiring new technology. However, there are other issues, including behavioral, social, cultural, and organizational issues that are often ignored. Most of the current literature on information security awareness and compliance is centered in developed countries and, to some extent, developing countries in Asia and the Middle East. There is limited literature on information security awareness and compliance, especially in Small and Medium-Sized Enterprises (SMEs) in Africa, and in particular in Sub-Saharan African countries. The purpose of this interpretivist study is to identify the significant challenges that SMEs in Nigeria, the most populous Sub-Saharan African country face concerning information security awareness and compliance. The purpose of this qualitative, multisite, exploratory case study will be to identify and explore the various social, cultural, organizational, and behavioral factors that influence the adoption and compliance with the information security policies in Nigerian SMEs. Results of this study could assist organizational leaders with maintaining higher levels of information security in their organizations and avoiding loss of brand equity and revenue because of information security breaches. Observations from audio recorded, in-depth personal interviews with 50 managers working in different departments in 20 different medium-sized companies in Nigeria will be used in this case study. The 20 medium-sized companies included two companies each from the ten key economic sectors forming the core of Nigerian economy.

Abstract as published in Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020).

Keywords: Information Security; Awareness; Africa; Interpretivist; Compliance

Limitations

  • A four-page conference paper presenting the research design and rationale; the abstract is written prospectively and reports no interview findings.
  • No DOI is registered for this paper; the record is indexed in Scopus and available in the IADIS Digital Library.

When this research may be relevant

This paper may be relevant to researchers studying information security awareness, security policy compliance and the human factors of cybersecurity in SMEs, particularly in Nigeria and sub-Saharan Africa, and to those designing interpretivist or multisite case-study research on organisational security behaviour.

Research topics addressed: information security awareness; information security compliance; security policy compliance; SMEs; Nigeria; sub-Saharan Africa; interpretivist research; qualitative case study; organisational culture; behavioural information security

How to cite

Nasir, S., & Vajjhala, N. R. (2020). Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective. In Miguel Baptista Nunes, Pedro Isaías, Philip Powell, Boyan Bontchev (Eds.), Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020) (pp. 187–190). IADIS Press. https://www.iadisportal.org/digital-library/evaluating-information-security-awareness-and-compliance-in-sub-saharan-africa-an-interpretivist-perspective

BibTeX
@inproceedings{nasir2020information,
  title = {Evaluating Information Security Awareness and Compliance in Sub-Saharan Africa: An Interpretivist Perspective},
  author = {Nasir, Sadiq and Vajjhala, Narasimha Rao},
  booktitle = {Proceedings of the 13th IADIS International Conference Information Systems 2020 (IS 2020)},
  editor = {Miguel Baptista Nunes and Pedro Isaías and Philip Powell and Boyan Bontchev},
  pages = {187--190},
  year = {2020},
  publisher = {IADIS Press},
  url = {https://www.iadisportal.org/digital-library/evaluating-information-security-awareness-and-compliance-in-sub-saharan-africa-an-interpretivist-perspective}
}
Download citation:BibTeXRISCSL-JSONMarkdown

Related research

2025
Vajjhala & Strang (2025) · CRC Press · DOI 10.1201/9781003498094
2025
Martiri et al. (2025) · CRC Press · DOI 10.1201/9781003504979
2024
Strang & Vajjhala (2024) · 2024 4th International Conference on Pervasive Computing and Social Networking (ICPCSN) · DOI 10.1109/ICPCSN62568.2024.00008
2023
Strang & Vajjhala (2023) · Cybersecurity for Decision Makers · DOI 10.1201/9781003319887-1
2023
Vajjhala & Strang (2023) · CRC Press · DOI 10.1201/9781003319887

All publication summaries → · Selected publications →