KnowBe4 (www.KnowBe4.com), the world-renowned cybersecurity platform that comprehensively addresses human risk management, today released its new report “Africa Human Risk Management Report 2025”. The report reveals a mismatch between employer perceptions and employee experience of organisational cybersecurity in key African industries – with potentially costly consequences.
The report (https://apo-opa.co/45TKgqm) captures insights from cybersecurity decision-makers across 30 African countries. One of the biggest themes the survey uncovers is a mismatch between perception and reality: what employers believe is not necessarily what employees feel or experience.
In key growth-industries across the continent, cybersecurity preparedness and the actual structures needed to support secure behaviour seem misaligned.
The report highlights, for instance, that just 10% of cybersecurity leaders are fully confident that staff would report a phishing attack or other cyber threat, despite rating employee security awareness of cyber threats at four out of five or higher. Furthermore, a significant perception gap exists between decision-makers and general employees in Africa regarding security awareness training, with 68% of leaders believing that training is tailored to roles, compared to only a third of employees feeling adequately trained.
This contrast is underscored by the data showing that there is a difference between what leaders believe about security awareness training effectiveness and what employees actually experience. This is further emphasised by the fact that many organisations only conduct annual or biannual training that is too generic to effectively change behaviour, contributing to uncertainty about its effectiveness.
The data shows that without procedural and cultural follow-through, awareness simply doesn’t translate into readiness
Previous end-user based responses (https://apo-opa.co/4mmEnIl) revealed that only 43% of African respondents felt confident in their ability to recognise a cyber threat, and just one in three believed their security awareness training was adequately tailored to their role. This comparison suggests the development of a dangerous perception gap in many organisations.
“There’s a disconnect here – between what leaders think is happening, and what employees are actually experiencing,” says Anna Collard, SVP content strategy & evangelist at KnowBe4 Africa. “The data shows that without procedural and cultural follow-through, awareness simply doesn’t translate into readiness.”
The KnowBe4 Africa Human Risk Management Report 2025 provides a glimpse into human cyber risk that reflects the real challenges – and overlooked opportunities – facing African organisations.
Key findings include:
"This report reveals a critical paradox in African cybersecurity: while organisations feel aware and prepared, significant blind spots remain, especially concerning how they manage human risk,” Collard notes. “The continent's cybersecurity posture may be more confident than it is truly resilient."
The report concludes with a roadmap for turning awareness into action – including role-specific training, measurable outcomes, AI policy development and better reporting structures.
The full report is now available for download here (https://apo-opa.co/45TKgqm).
Distributed by APO Group on behalf of KnowBe4.