Monday, 14 September 2026
Nigeria Communications Week
E-Business

Survey Shows Gaps in Cybersecurity Policies and Employee Commitment Leave Organisations Vulnerable

Chike Onwuegbuchi23 Apr 20260 Comments
Survey Shows Gaps in Cybersecurity Policies and Employee Commitment Leave Organisations Vulnerable
Kindly share this post

A recent Kaspersky survey entitled “Cybersecurity in the workplace: Employee knowledge and behaviour”, showed that 39% of professionals in the Middle East, Turkiye and Africa (META) region, consider…

A recent Kaspersky survey entitled “Cybersecurity in the workplace: Employee knowledge and behaviour”, showed that 39% of professionals in the Middle East, Turkiye and Africa (META) region, consider cybersecurity rules in their company to be excessive or not fully appropriate.

While 7% noted that their organisations do not have cybersecurity rules or that they are not aware of them. These results show a disconnect between corporate cybersecurity policies and employee commitment to these rules, underscoring the risks associated with shadow IT and unmanaged device usage in the workplace.

Shadow IT is defined as the use of unauthorised software, devices, or services without IT oversight, and it has evolved into a critical business risk. While often driven by employee productivity needs, it creates blind spots for IT departments.

The rise of hybrid work environments, increased reliance on cloud-based tools and the spread of AI tools have accelerated this trend. Without robust cybersecurity management and oversight, organisations face heightened exposure to ransomware attacks, data leaks, and regulatory penalties.

19% of survey respondents in the META region said there are no policies regarding the use of non-corporate devices in their company. 35% of employees admitted that they can use their own devices to access business information, provided they have some type of cybersecurity protection, even consumer-grade software.

On the positive side, 21% said they can use their own device, but these must first pass more stringent corporate IT security checks; while 25% of respondents indicated that only devices provided by the IT function can be used for work purposes.

The situation is significantly better with permissions for employees to install software on corporate devices without IT department’s approval. 50% reported that only IT specialists in their company are allowed to install software, while in 31% of organisations only top management or designated users can do so. 11% of employees can install software that is approved by the IT team. However, 8% of respondents said that all users can install any software they need without IT agreement in their organisation.

At the same time 21% of professionals surveyed acknowledged that within the past year they installed software on their work devices without IT supervision. That highlights a persistent shadow IT challenge that continues to expose organisations to security vulnerabilities, compliance risks, and data breaches.

“Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap. Many organisations already have security policies in place, but employee perception must also be considered.

Organisations should move beyond restrictive controls and instead implement intelligent, user-centric cybersecurity strategies that combine strategies that integrate technology with employee awareness and responsible use,” said Toufic Derbass, Managing Director for the META region at Kaspersky.

C
Published by

Chike Onwuegbuchi

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business
E-Business

What Dollar Strength Cycle Mean for Traders

By Ugo Onwuaso21 Aug 2026

The USD still ranks among the major forces that drive financial markets all over the world. When the USD gains in value, it rarely affects currency pairs alone; it may have implications for commodities, stock market indices, capital movement, and risk appetite.