• Skip to main content
  • Skip to header right navigation
  • Skip to after header navigation
  • Skip to site footer
MyZA

MyZA

News, Directory, Events and Other Stuff

  • Social Media
  • Sport
  • World News
  • Home
  • Submit News
  • Directory
  • Events
  • Stratlec
  • TFSA
  • News
    • APO
    • Today’s Sport News
    • Todays Social Media and Tech Headlines
    • Today’s World News
    • Today’s SA Financial News
  • Contact
You are here: Home / News / Gaps in Cybersecurity Policies and Employee Commitment Leave Organisations Vulnerable, Kaspersky Survey Shows

Gaps in Cybersecurity Policies and Employee Commitment Leave Organisations Vulnerable, Kaspersky Survey Shows

23 April 2026 by Guest
Kaspersky

A recent Kaspersky (www.Kaspersky.co.za) survey undertaken in the Middle East, Turkiye and Africa (META) region entitled “Cybersecurity in the workplace: Employee knowledge and behaviour”, showed that 39% of professionals consider cybersecurity rules in their company to be excessive or not fully appropriate. In Kenya, this figure was 25% and in South Africa, 23%. Furthermore, the survey highlighted that 7% of respondents in the META region, 4% in Kenya and 10% in South Africa noted that their organisations do not have cybersecurity rules or that they are not aware of them. These results show a disconnect between corporate cybersecurity policies and employee commitment to these rules, underscoring the risks associated with shadow IT and unmanaged device usage in the workplace.

Shadow IT is defined as the use of unauthorised software, devices, or services without IT oversight, and it has evolved into a critical business risk. While often driven by employee productivity needs, it creates blind spots for IT departments. The rise of hybrid work environments, increased reliance on cloud-based tools and the spread of AI tools have accelerated this trend. Without robust cybersecurity management and oversight, organisations face heightened exposure to ransomware attacks, data leaks, and regulatory penalties.

19% of all survey respondents said there are no policies regarding the use of non-corporate devices in their company. 35% admitted that they can use their own devices to access business information, provided they have some type of cybersecurity protection, even consumer-grade software. On the positive side, 21% of all respondents said they can use their own device, but these must first pass more stringent corporate IT security checks; while 25% indicated that only devices provided by the IT function can be used for work purposes.

The situation is significantly better with permissions for employees to install software on corporate devices without IT department’s approval. 50% of all survey participants reported that only IT specialists in their company are allowed to install software, while in 31% of organisations only top management or designated users can do so. 11% of employees can install software that is approved by the IT team. However, 8% of respondents said that all users can install any software they need without IT agreement in their organisation.

At the same time 21% of professionals surveyed in the META region, 29% in Kenya and 17% in South Africa acknowledged that within the past year they installed software on their work devices without IT supervision. That highlights a persistent shadow IT challenge that continues to expose organisations to security vulnerabilities, compliance risks, and data breaches.  

“Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap. Many organisations already have security policies in place, but employee perception must also be considered. Organisations should move beyond restrictive controls and instead implement intelligent, user-centric cybersecurity strategies that combine strategies that integrate technology with employee awareness and responsible use,” said Toufic Derbass, Managing Director for the META region at Kaspersky.

To help organisations strengthen their defences, Kaspersky recommends the following:

  • Conduct a Shadow IT audit to identify all unauthorised software, cloud services, and personal devices accessing corporate data.
  • Implement robust monitoring and cybersecurity solutions, for example from the Kaspersky Next product line with EDR and XDR tiers, to gain visibility into unsanctioned app usage and device behaviour.
  • If employees are allowed to use personal devices, define clear minimum security requirements and enforce them through such solutions as mobile device management (MDM) or endpoint management tools.
  • Complement user-friendly cybersecurity policies for employees with trainings that demonstrates real-life risks and ways to avoid them. Solutions such as Kaspersky Automated Security Awareness Platform can help.

For employees Kaspersky experts advise:

  • Understand your company’s cybersecurity policies. If anything is unclear, ask for clarification.
  • Only use applications that have been approved by your IT department and request access to specific IT resources when needed.
  • Use only authorised devices for work. If personal devices are allowed, make sure they meet all required security standards and have appropriate cybersecurity solutions installed.
  • Store and share work files only through approved platforms.

*The survey was conducted by Toluna research agency at the request of Kaspersky in 2025. The study sample included 2800 online interviews with employees and business owners using computers for work in seven countries: Türkiye, South Africa, Kenya, Pakistan, Egypt, Saudi Arabia, and the UAE.

Distributed by APO Group on behalf of Kaspersky.

For further information please contact:
Nicole Allman
nicole@inkandco.co.za

Social Media:
Facebook: https://apo-opa.co/3OY4SYW
X: https://apo-opa.co/4eCWYyA
YouTube: https://apo-opa.co/3OBAIL2
Instagram: https://apo-opa.co/4cqYfHF
Blog: https://apo-opa.co/48CtddJ

About Kaspersky: 
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and over 200,000 corporate clients protect what matters most to them. Learn more at www.Kaspersky.co.za.   

Media files
Kaspersky
Download logo

A recent Kaspersky survey undertaken in the Center East, Turkiye and Africa (META) region entitled “Cybersecurity in the workplace: Employee knowledge and behaviour”, showed that 39% of professionals consider cybersecurity rules in their company to be excessive or not fully appropriate. In Kenya, this figure was 25% and in South Africa, 23%. Furthermore, the survey highlighted that 7% of respondents in the META region, 4% in Kenya and 10% in South Africa noted that their organisations do not have cybersecurity rules or that they are not aware of them. These results show a disconnect between corporate cybersecurity policies and employee commitment to these rules, underscoring the risks associated with shadow IT and unmanaged device usage in the workplace.

Shadow IT is defined as the use of unauthorised software, devices, or services without IT oversight, and it has evolved into a critical business risk. While often driven by employee productivity needs, it creates blind spots for IT departments. The rise of hybrid work environments, increased reliance on cloud-based tools and the spread of AI tools have accelerated this trend. Without robust cybersecurity management and oversight, organisations face heightened exposure to ransomware attacks, data leaks, and regulatory penalties.

19% of all survey respondents said there are no policies regarding the use of non-corporate devices in their company. 35% admitted that they can use their own devices to access business information, provided they have some type of cybersecurity protection, even consumer-grade software. On the positive side, 21% of all respondents said they can use their own device, but these must first pass more stringent corporate IT security checks; while 25% indicated that only devices provided by the IT function can be used for work purposes.

The situation is significantly better with permissions for employees to install software on corporate devices without IT department’s approval. 50% of all survey participants reported that only IT specialists in their company are allowed to install software, while in 31% of organisations only top management or designated users can do so. 11% of employees can install software that is approved by the IT team. However, 8% of respondents said that all users can install any software they need without IT agreement in their organisation.

At the same time 21% of professionals surveyed in the META region, 29% in Kenya and 17% in South Africa acknowledged that within the past year they installed software on their work devices without IT supervision. That highlights a persistent shadow IT challenge that continues to expose organisations to security vulnerabilities, compliance risks, and data breaches.

“Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap. Many organisations already have security policies in place, but employee perception must also be considered. Organisations should move beyond restrictive controls and instead implement intelligent, user-centric cybersecurity strategies that combine strategies that integrate technology with employee awareness and responsible use,” said Toufic Derbass, Managing Director for the META region at Kaspersky.

To help organisations strengthen their defences, Kaspersky recommends the following:

  • Conduct a Shadow IT audit to identify all unauthorised software, cloud services, and personal devices accessing corporate data.
  • Implement robust monitoring and cybersecurity solutions, for example from the Kaspersky Next product line with EDR and XDR tiers, to gain visibility into unsanctioned app usage and device behaviour.
  • If employees are allowed to use personal devices, define clear minimum security requirements and enforce them through such solutions as mobile device management (MDM) or endpoint management tools.
  • Complement user-friendly cybersecurity policies for employees with trainings that demonstrates real-life risks and ways to avoid them. Solutions such as Kaspersky Automated Security Awareness Platform can help.

For employees Kaspersky experts advise:

  • Understand your company’s cybersecurity policies. If anything is unclear, ask for clarification.
  • Only use applications that have been approved by your IT department and request access to specific IT resources when needed.
  • Use only authorised devices for work. If personal devices are allowed, make sure they meet all required security standards and have appropriate cybersecurity solutions installed.
  • Store and share work files only through approved platforms.

*The survey was conducted by Toluna research agency at the request of Kaspersky in 2025. The study sample included 2800 online interviews with employees and business owners using computers for work in seven countries: Türkiye, South Africa, Kenya, Pakistan, Egypt, Saudi Arabia, and the UAE.

Per Kind Favour of APO

Africa Fact: The palace in the Kenyan city of Gedi contains evidence of piped water controlled by taps. In addition it had bathrooms and indoor toilets.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Print (Opens in new window) Print
  • Email a link to a friend (Opens in new window) Email
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
Category: NewsTag: APO

If you feel strongly about this article then feel free to send MyZA a ‘Letter to the Editor’ using the submission form below:


Letter to the Editor

This field is for validation purposes and should be left unchanged.
If this is in response to an article please include that article title here or as the lead in for the first paragraph of your Letter below.

Separate tags with commas

Localise your letter by naming the city your words are about. Add relevant words describing your subject. Single comma separated words of no more than 5
Your Name(Required)
Your Name will be linked to the website below.
Your personal, business or social media web site
Choose NO to not set up a user account on MyZA. User Accounts will allow you to submit letters under your own Author Name

3 Latest Letters to the Editor:

  • Congratulations to the Lotto Winner

    Dear Editor Dear Editor, I was thrilled to hear about the R8.5 million Lotto win for the community of Gqeberha. Such life-changing news brings hope and excitement to everyone in the area. I congratulate the winner and wish them all the best with their prize. May this bring positive change to their life and the…

    1 October 2026
  • Opinion on Lotto Winner News

    Dear Editor Congratulations to the lucky winner! This is truly wonderful news for the community. Regards Marina Adams In Response to/From: Congratulations to the Lucky Winner

    1 October 2026
  • Regarding Lotto Winner Story

    Dear Editor Congratulations to the winner, this is wonderful news for the community. Wishing them the best for the future. Regards Willem Pieterse In Response to/From: Re: R8.5 Million Lotto Winner Claims Prize in Gqeberha

    27 September 2026

About Guest

Previous Post:The legal duty of care in commuter transport
Next Post:Strategic Consolidation: OG Ventures Welcomes The Marketing Mill Under Its Umbrella to Enhance Digital Resilience

Reader Interactions

Comments

  1. Shady Lady

    9 September 2026 at 2:42 am

    Fun South African Fact: South Africa is home to the highest commercial bungi jump in the world at 710 feet.

  2. Old Felix

    31 August 2026 at 2:08 pm

    Fun South African Fact: There are 11 official languages, each with equal status, in South Africa

Copyright © 2026 · MyZA · All Rights Reserved · Powered by Stratlec Online