| dc.contributor.advisor |
Abdullah, H.
|
|
| dc.contributor.advisor |
Mujinga, M.. |
|
| dc.contributor.author |
Endjala, Esther Ndapewa
|
|
| dc.date.accessioned |
2026-09-21T11:16:03Z |
|
| dc.date.available |
2026-09-21T11:16:03Z |
|
| dc.date.issued |
2026-08-13 |
|
| dc.identifier.uri |
https://ir.unisa.ac.za/handle/10500/33070 |
|
| dc.description.abstract |
In today's digital environment, where cyber threats are on the rise, organisations face cyber risks that extend beyond technical vulnerabilities. A lack of a cybersecurity culture is often the primary reason why organisational resilience is compromised, as employees' attitudes and behaviours significantly affect the effectiveness of security measures. This study addresses the problem that cybersecurity initiatives in Namibia’s telecommunications sector remain largely technical and compliance-driven, while behavioural, organisational and cultural factors that shape secure employee practices are insufficiently understood. Based on these insights, the study seeks to develop a cybersecurity culture framework comprising of six key elements: leadership commitment and support; policy reviews and communication; a Security Education, Training and Awareness (SETA) programme; collaboration and feedback; security champions and ambassadors; and a rewards scheme. A qualitative case study was conducted in a Namibian telecommunications organisation, involving 25 participants purposively selected from across management levels and from IT and non-IT departments. The data were gathered during semi-structured interviews and were analysed thematically. The study's findings reveal key gaps in existing practices, including leaders' passive involvement, inadequate continuous and role-specific training, weak awareness initiatives, and poor reinforcement mechanisms, that impede the development of a proactive security culture. Participants highlighted incentive-based recognition, gamified and tailored training, and security champions as critical enablers of behavioural change. The study contributes to the body of knowledge on organisational cybersecurity by providing context-specific insights to strengthen human-centred defences and by outlining implications for extending this approach to other critical infrastructure sectors that adopt emerging technologies. |
en_US |
| dc.format.extent |
1 online resource (xiv, 198 leaves): illustrations (some color) |
en |
| dc.language.iso |
en |
en_US |
| dc.subject |
Cybersecurity culture |
en_US |
| dc.subject |
Cybersecurity framework |
en_US |
| dc.subject |
Cybersecurity governance |
en_US |
| dc.subject |
Cyber-threats |
en_US |
| dc.subject |
Employee behaviour |
en_US |
| dc.subject |
Human-centric security |
en_US |
| dc.subject |
Human-related cyber risk |
en_US |
| dc.subject |
Telecommunications sector |
en_US |
| dc.subject |
Security awareness |
en_US |
| dc.subject |
Leadership commitment |
en_US |
| dc.subject.lcsh |
Cybersecurity -- Management -- Namibia |
en |
| dc.subject.lcsh |
Computer security -- Human factors -- Namibia |
en |
| dc.subject.lcsh |
Information technology -- Security measures -- Namibia |
en |
| dc.subject.lcsh |
Telecommunication -- Security measures -- Namibia |
en |
| dc.subject.lcsh |
Telecommunication industry -- Namibia -- Management |
en |
| dc.subject.lcsh |
Employees -- Training of -- Namibia |
en |
| dc.subject.lcsh |
Information resources management -- Security measures -- Namibia. |
en |
| dc.subject.lcsh |
Cyberinfrastructure -- Protection -- Namibia |
en |
| dc.title |
Developing a cybersecurity culture framework: a case study of Namibia’s telecommunications sector |
en_US |
| dc.description.department |
Computing |
en |
| dc.description.degree |
M. Sc. (Computing) |
en |