Institutional Repository

Developing a cybersecurity culture framework: a case study of Namibia’s telecommunications sector

Show simple item record

dc.contributor.advisor Abdullah, H.
dc.contributor.advisor Mujinga, M..
dc.contributor.author Endjala, Esther Ndapewa
dc.date.accessioned 2026-09-21T11:16:03Z
dc.date.available 2026-09-21T11:16:03Z
dc.date.issued 2026-08-13
dc.identifier.uri https://ir.unisa.ac.za/handle/10500/33070
dc.description.abstract In today's digital environment, where cyber threats are on the rise, organisations face cyber risks that extend beyond technical vulnerabilities. A lack of a cybersecurity culture is often the primary reason why organisational resilience is compromised, as employees' attitudes and behaviours significantly affect the effectiveness of security measures. This study addresses the problem that cybersecurity initiatives in Namibia’s telecommunications sector remain largely technical and compliance-driven, while behavioural, organisational and cultural factors that shape secure employee practices are insufficiently understood. Based on these insights, the study seeks to develop a cybersecurity culture framework comprising of six key elements: leadership commitment and support; policy reviews and communication; a Security Education, Training and Awareness (SETA) programme; collaboration and feedback; security champions and ambassadors; and a rewards scheme. A qualitative case study was conducted in a Namibian telecommunications organisation, involving 25 participants purposively selected from across management levels and from IT and non-IT departments. The data were gathered during semi-structured interviews and were analysed thematically. The study's findings reveal key gaps in existing practices, including leaders' passive involvement, inadequate continuous and role-specific training, weak awareness initiatives, and poor reinforcement mechanisms, that impede the development of a proactive security culture. Participants highlighted incentive-based recognition, gamified and tailored training, and security champions as critical enablers of behavioural change. The study contributes to the body of knowledge on organisational cybersecurity by providing context-specific insights to strengthen human-centred defences and by outlining implications for extending this approach to other critical infrastructure sectors that adopt emerging technologies. en_US
dc.format.extent 1 online resource (xiv, 198 leaves): illustrations (some color) en
dc.language.iso en en_US
dc.subject Cybersecurity culture en_US
dc.subject Cybersecurity framework en_US
dc.subject Cybersecurity governance en_US
dc.subject Cyber-threats en_US
dc.subject Employee behaviour en_US
dc.subject Human-centric security en_US
dc.subject Human-related cyber risk en_US
dc.subject Telecommunications sector en_US
dc.subject Security awareness en_US
dc.subject Leadership commitment en_US
dc.subject.lcsh Cybersecurity -- Management -- Namibia en
dc.subject.lcsh Computer security -- Human factors -- Namibia en
dc.subject.lcsh Information technology -- Security measures -- Namibia en
dc.subject.lcsh Telecommunication -- Security measures -- Namibia en
dc.subject.lcsh Telecommunication industry -- Namibia -- Management en
dc.subject.lcsh Employees -- Training of -- Namibia en
dc.subject.lcsh Information resources management -- Security measures -- Namibia. en
dc.subject.lcsh Cyberinfrastructure -- Protection -- Namibia en
dc.title Developing a cybersecurity culture framework: a case study of Namibia’s telecommunications sector en_US
dc.description.department Computing en
dc.description.degree M. Sc. (Computing) en


Files in this item

This item appears in the following Collection(s)

  • Unisa ETD [13509]
    Electronic versions of theses and dissertations submitted to Unisa since 2003

Show simple item record

Search UnisaIR


Browse

My Account

Statistics