About the Author(s)


Nicholas W. Omollo Email symbol
School of Agriculture and Science, College of Agriculture, Engineering & Science, University of KwaZulu-Natal, Durban, South Africa

Manoj Maharaj symbol
School of Agriculture and Science, College of Agriculture, Engineering & Science, University of KwaZulu-Natal, Durban, South Africa

Citation


Omollo, N.W. & Maharaj, M., 2026, ‘Adaptive governance awareness model for improving user security in mobile financial services’, South African Journal of Information Management 28(1), a2166. https://doi.org/10.4102/sajim.v28i1.2166

Original Research

Adaptive governance awareness model for improving user security in mobile financial services

Nicholas W. Omollo, Manoj Maharaj

Received: 11 Feb. 2026; Accepted: 23 Apr. 2026; Published: 13 Aug. 2026

Copyright: © 2026. The Authors. Licensee: AOSIS.
This work is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license (https://creativecommons.org/licenses/by/4.0/).

Abstract

Background: The rapid growth of mobile financial services (MFSs) has expanded financial inclusion but also increased users’ exposure to cybersecurity threats. Existing awareness programmes and governance frameworks had not adequately addressed the dynamic and behavioural dimensions of user security in mobile financial ecosystems, particularly in developing economies.

Objectives: This study addressed this gap by developing and validating the adaptive governance awareness model (AGAM) to improve cybersecurity awareness and governance among MFS users. The model aimed to provide a framework that linked governance processes, user awareness and behavioural practices to security outcomes.

Method: A quantitative research design was employed using a structured questionnaire administered to MFS users in Kenya. Statistical analyses were conducted to examine relationships between demographic factors, awareness levels and security behaviours. Adaptive governance awareness model was operationalised by integrating the National Institute of Standards and Technology and MediaPro Frameworks.

Results: The findings revealed significant gaps in user awareness and inconsistencies in cybersecurity behaviour. Demographic factors influenced both awareness and security practices. The results demonstrated that adaptive governance and awareness interventions aligned with AGAM improved the management of user-level cybersecurity risks in MFS environments.

Conclusion: Integrating behavioural awareness with structured governance processes enhanced users’ cybersecurity resilience and supported more effective information security management in mobile financial ecosystems.

Contribution: This study filled a theoretical and practical gap by introducing and empirically supporting AGAM as an awareness and governance model for cybersecurity in MFSs. The model extended existing frameworks by embedding adaptive, behaviour-oriented governance, offering actionable insights for managers, policymakers and information systems researchers.

Keywords: NIST Cybersecurity Framework; adaptive governance awareness model; mobile financial services; cybersecurity awareness; MediaPro Adaptive Awareness Framework; risk analysis; capacity building.

Introduction

The rapid expansion of mobile financial services (MFSs) in developing economies, particularly across Africa, has transformed access to financial systems and accelerated financial inclusion (Jack & Suri 2011). In Kenya, M-PESA – a leading mobile phone-based money transfer, payment and micro-financing service launched by Safaricom in partnership with Vodafone in 2007 – has become integral to everyday economic activity, supporting payments, savings and remittances. However, this expansion has also heightened users’ exposure to cybersecurity threats, often exacerbated by limited digital literacy, socio-economic inequality and uneven regulatory enforcement (Abrahams et al. 2024; Communications Authority of Kenya 2023; Musyoka & Mose 2024).

Compared with developed economies, many African MFS ecosystems operate within low-resource and heterogeneous environments, where feature phones, informal practices and basic authentication mechanisms shape distinctive patterns of security behaviour and vulnerability (GSMA 2021; Kshetri 2019). Empirical evidence indicates that weak user awareness and risky practices significantly increase exposure to fraud and social engineering attacks, underscoring the importance of cybersecurity awareness for sustaining trust in digital finance and protecting livelihoods (Bada, Sasse & Nurse 2019; GSMA 2024; Serianu 2023).

From a scientific perspective, cybersecurity is widely recognised as a multidimensional challenge encompassing technological, organisational and behavioural dimensions (Trim & Lee 2019). Prior research highlights the role of cybersecurity education and training (Al-Shanfari, Yassin & Abdullah 2020; Schneider et al. 2020), alongside governance structures and risk management practices, in shaping security outcomes. Established frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) provide structured guidance for cybersecurity governance and risk management (NIST 2018), while awareness-oriented models such as the MediaPro Adaptive Awareness Framework emphasise behavioural reinforcement and continuous learning (MediaPro 2018). However, these frameworks were largely developed for organisational or high-resource contexts and offer limited guidance for individual MFS users in developing economies, where digital literacy, regulatory maturity and socio-economic conditions vary considerably (International Telecommunication Union 2024; Kshetri 2019; World Bank 2023).

This study addresses this gap by proposing the adaptive governance awareness model (AGAM), a context-sensitive framework tailored to MFS users in Kenya and comparable developing economies. Adaptive governance awareness model integrates governance-oriented cybersecurity controls from the NIST CSF (NIST 2018) with the adaptive, behaviour-focused principles of the MediaPro framework (MediaPro 2019), enabling flexible application across diverse MFS ecosystems. By systematically linking governance structures with adaptive awareness strategies, AGAM offers an empirically supported approach for addressing user behaviour, regulatory diversity and persistent cybersecurity threats in MFSs (Adongo 2025; Osabutey & Jackson 2024).

Research problem

The widespread adoption of MFSs in Kenya has transformed financial transactions but has also introduced significant cybersecurity risks (Musyoka & Mose 2024; Ngugi, Mwangi & Kamau 2020). While existing frameworks, such as the NIST CSF and the MediaPro Adaptive Awareness Framework, offer structured approaches to cybersecurity, they were primarily developed in contexts with higher digital literacy and more robust security infrastructures (Kshetri 2019). These frameworks do not fully account for the socio-economic, technological and behavioural factors that shape cybersecurity awareness among MFS users in Kenya. Given the increasing sophistication of cyber threats and the reliance on mobile transactions in Kenya, there is a critical need for an integrated model that aligns with local realities. This study, therefore, seeks to bridge this gap by developing the AGAM, a context-specific framework that enhances cybersecurity awareness and user behaviour in mobile financial ecosystems. Unlike a direct application of these frameworks, AGAM synthesises structured security controls with adaptive learning, ensuring that cybersecurity awareness is both regulatory-aligned and behaviourally reinforced.

Research objectives

Kenya, with its widespread adoption of mobile money platforms such as M-PESA, exemplifies both the opportunities and challenges of MFSs in developing economies. While MFSs have enhanced financial inclusion, it has also introduced significant cybersecurity vulnerabilities because of diverse user demographics, varying levels of digital literacy and evolving cyber threats (Musyoka & Mose 2024). This study seeks to develop a cybersecurity awareness model that aligns with these contextual realities, offering insights applicable to Kenya and other developing economies where MFSs play a crucial role.

To achieve this, the study introduces the AGAM, an integrated cybersecurity awareness framework specifically designed for MFS users in Kenya. Adaptive governance awareness model is formulated by synthesising two well-established frameworks: The NIST CSF, which provides a structured approach to cybersecurity risk management (NIST 2018), and the MediaPro Adaptive Awareness Framework, which emphasises continuous learning and reinforcement to strengthen user security behaviour (MediaPro 2019). The integration of these frameworks is guided by the need to balance structured governance with user-centric learning strategies, ensuring that cybersecurity awareness aligns with the socio-technical landscape in Kenya. This is essential as cybersecurity challenges in MFSs are significantly influenced by user behaviour, awareness levels and evolving threat vectors such as phishing and social engineering (Wainaina, Kiyeng & Masese 2023; Wakoli 2024). Furthermore, empirical studies demonstrate that cybersecurity awareness and digital literacy play a critical role in shaping secure user behaviour and the adoption of digital financial services (Al Doghan & Mirzaliev 2024). By integrating these frameworks, AGAM is expected not only to enhance user security knowledge but also to cultivate proactive security habits among MFS users.

The study theorises that the structured security controls from the NIST framework, when complemented by the adaptive and behaviour-focused principles of the MediaPro framework, will create a comprehensive approach to improving cybersecurity awareness among MFS users. By contextualising these models within the Kenyan and broader African experience, the study aims to assess how various cybersecurity awareness components influence user behaviour and resilience against threats. Therefore, the research seeks to answer the following question: How can the components of the NIST CSF and the MediaPro Adaptive Awareness Framework be integrated to enhance cybersecurity awareness among users of MFSs in Kenya?

Theoretical framework and literature review

Mobile financial services

Mobile financial services refer to financial transactions conducted through mobile devices, enabling users to store, transfer and manage money electronically, particularly in regions with limited access to traditional banking infrastructure (Mater et al. 2021; Van Zanden 2023). Common MFS transactions include person-to-person money transfers, bill payments, savings and mobile banking services such as account management and international remittances (Ndung’u & Oguso 2021). By lowering transaction costs and reducing geographical barriers, MFSs have played a significant role in extending financial services to unbanked and underbanked populations in developing economies (Mwangi & Kasamani 2017).

An MFS ecosystem typically comprises mobile network operators, financial institutions, agents, merchants and regulatory authorities, whose interactions enable the delivery and sustainability of mobile-based financial services (Tobin 2011). Platforms such as M-PESA in Kenya and MTN Mobile Money in Uganda illustrate how telecommunications and financial infrastructures are integrated to support domestic and cross-border transactions (Van Zanden 2023). While initially designed for basic money transfers, MFS platforms have evolved to include microloans, insurance products and merchant payments, further deepening financial inclusion and economic participation (Ahirrao & Jethani 2014).

Cybersecurity awareness

Cybersecurity awareness refers to users’ understanding of cyber risks and their ability to recognise, avoid and respond to security threats when interacting with digital systems. In developing economies, limited digital literacy and uneven access to cybersecurity education increase users’ susceptibility to fraud, particularly within MFS environments (Iyelolu et al. 2024; Vitus 2023). Recent evidence indicates high exposure to digital fraud among Mobile financial services users in Kenya, highlighting the urgent need for awareness initiatives tailored to diverse literacy levels and socio-economic conditions (TransUnion Africa 2025).

Effective cybersecurity awareness programmes must therefore be adaptive, inclusive and responsive to evolving threat landscapes. Prior studies emphasise the importance of multifaceted awareness strategies that combine training, communication and behavioural reinforcement to address heterogeneous user capabilities (Brecht 2019; Nagyfejeo & Von Solms 2020). Well-designed awareness initiatives enhance users’ capacity to recognise cyber threats, adopt secure behaviours and reduce systemic exposure to cybercrime within financial ecosystems (Naik & Sneha 2023; NIST 2021; Odo 2024; Popoola et al. 2024).

National institute of standards and technology cybersecurity framework

The NIST CSF provides a structured approach to managing cybersecurity risks through a set of core functions – Identify, Protect, Detect, Respond and Recover – designed to guide organisations in developing and implementing effective security practices (NIST 2018). The introduction of the Govern function further underscores the importance of cybersecurity governance, emphasising alignment between organisational objectives, risk management and awareness initiatives (NIST 2023). While widely adopted, the framework is primarily organisational in focus and offers limited guidance on individual user awareness in low-resource MFS contexts.

MediaPro adaptive awareness framework

The MediaPro Adaptive Awareness Framework adopts a user-centric approach to cybersecurity awareness through four core components: Analyse, Plan, Train and Reinforce (MediaPro 2018). The framework emphasises continuous assessment of user awareness levels, strategic planning of awareness initiatives, engaging training methods and ongoing reinforcement of secure behaviours (8Pillars 2018). Its adaptive design allows awareness content to be personalised based on user behaviour and risk profiles, making it particularly suitable for dynamic environments such as MFSs. However, the framework lacks explicit governance and regulatory integration, limiting its effectiveness when applied independently in regulated financial ecosystems.

Conceptual framework

This study is underpinned by an integrated conceptual framework that combines risk-based cybersecurity governance theory with adaptive cybersecurity awareness and behavioural learning theory to explain cybersecurity awareness within MFS environments. The framework is developed through the integration of constructs from the NIST CSF and the MediaPro Adaptive Awareness Framework, which together provide a socio-technical perspective on cybersecurity awareness.

The NIST CSF conceptualises cybersecurity as a structured, lifecycle-oriented process encompassing governance, risk identification, protection, detection, response and recovery (NIST 2023). The framework offers a strong theoretical foundation for understanding how cybersecurity is governed and operationalised through formal policies, risk management processes and technical controls. However, prior studies have observed that governance-centric frameworks such as NIST give limited attention to behavioural, cognitive and socio-cultural factors that influence how users perceive and respond to cybersecurity risks, particularly in developing economies (Popoola et al. 2024).

To address this limitation, the conceptual framework also draws on the MediaPro Adaptive Awareness Framework, which conceptualises cybersecurity awareness as an iterative process of analysis, training and reinforcement (MediaPro 2019). MediaPro is grounded in behavioural and educational theory and emphasises sustained learning, user engagement and reinforcement as mechanisms for influencing cybersecurity behaviour over time. The integration of NIST and MediaPro therefore enables the conceptualisation of cybersecurity awareness as a socio-technical system, in which governance structures, technical safeguards and user behaviour are mutually reinforcing.

The resulting AGAM has been contextualised for MFS environments in developing economies, where rapid digital financial inclusion has expanded the cyber threat landscape amid uneven digital literacy and limited institutional capacity (Iyelolu et al. 2024; Lamia 2024). In such contexts, cybersecurity awareness cannot be adequately explained through technical controls or training initiatives alone. Instead, it emerges from the interaction between governance mechanisms, risk perception, threat management practices and continuous capacity building.

Adaptive governance awareness model consolidates overlapping constructs from established cybersecurity governance and awareness frameworks into five information management-oriented dimensions: Governance Planning (GP), Risk Analysis (RA), Threat Management (TM), Incident Response and Recovery (IRR) and Capacity Building (CB). Governance Planning reflects strategic information governance through policy alignment, regulatory compliance and organisational oversight that shape cybersecurity decision-making processes (NIST 2018). Risk analysis is positioned as a forward-looking information management function that supports the systematic identification, evaluation and prioritisation of cybersecurity risks (Whitman & Mattord 2004), while TM represents the operational use of security information through continuous monitoring and the application of protective controls in response to identified risks, thereby maintaining a clear distinction between strategic planning and operational execution (Von Solms & Van Niekerk 2013). Incident response and recovery emphasises organisational resilience by integrating information flows for response coordination, service restoration and post-incident learning (ISO/IEC 2023). Capacity building frames cybersecurity awareness as an ongoing knowledge management and learning process that enhances adaptive user behaviour and institutional capability, which is particularly critical in MFS environments characterised by diverse user competencies (Dhillon & Backhouse 2000; Musyoka & Mose 2024).

The conceptual framework further posits that these constructs are interrelated rather than sequential. Governance planning shapes the deployment of TM and incident response mechanisms, while RA continuously informs governance adaptation and operational priorities. Capacity building functions as a cross-cutting enabler, influencing governance effectiveness, threat recognition and response capability. These relationships reflect established insights from cybersecurity governance and behavioural security literature, which emphasise the reciprocal interaction between policy, risk perception, technical controls and user behaviour (Dhillon & Backhouse 2000; NIST 2018).

By integrating governance and adaptive awareness perspectives, AGAM responds to calls for CSFs that are contextually grounded and behaviourally informed, particularly within developing economies (Al Doghan & Mirzaliev 2024; Kshetri 2019). The conceptual relationships among the constructs are illustrated in Figure 1, which presents AGAM as a holistic framework for understanding and strengthening cybersecurity awareness in MFSs.

FIGURE 1: Proposed adaptive governance awareness model. Conceptual integration of National Institute of Standards and Technology governance functions and MediaPro adaptive awareness processes, illustrating hypothesised relationships among governance planning, risk analysis, threat management, incident response and recovery and capacity building.

Research methods and design

The study employed a quantitative research design, surveying 1159 respondents in Kenya to examine their interaction with MFS platforms and their cybersecurity awareness. The questionnaire was structured to assess user engagement with MFSs and their understanding of security vulnerabilities, aligning with best practices in cybersecurity research (Abrardi, Comino & Grassini 2025; Ebel & Mitra 2024). The research model incorporated five interrelated constructs: GP, RA, TM, IRR and CB, reflecting established CSFs such as the NIST CSF (NIST 2018).

The target population consisted of MFS users. Because of the wide geographic distribution of users, cluster sampling was employed. The population was divided into clusters based on major cities, and five cities (Nairobi, Nakuru, Mombasa, Kisumu and Eldoret) were randomly selected to represent the population’s demographic diversity, including age, gender, education and income.

A total of 1170 questionnaires were distributed to the selected cities, with 1159 returned, representing a 99.06% response rate. The sample size was determined using Cochran’s formula (Cochran 1977) for finite populations with a 95% confidence level, a 3% margin of error and a conservative population proportion of 50%, yielding an initial sample of 1067. To account for potential non-responses, the sample was increased by 10%.

Within the selected clusters, random sampling ensured that each individual had an equal probability of being selected. Questionnaires were distributed with follow-ups by research assistants to maximise response rates.

Inclusion criteria were individuals aged 18 years and above who actively use MFSs. Individuals under 18 years or those without experience using MFSs were excluded from the study.

To analyse the relationships among the constructs, the study utilised both variance-based and covariance-based structural equation modelling (SEM), consistent with methodological recommendations for validating measurement models before testing structural relationships (Hair 2014). Variance-based SEM, specifically partial least squares SEM (PLS-SEM), was selected because of its strengths in exploratory research and its capacity to manage complex models with relatively small sample sizes (Chin 2009). Conversely, covariance-based SEM (CB-SEM) was employed to evaluate the model’s overall goodness-of-fit, ensuring construct validity and reliability (Kline 2023). This dual approach allowed for a comprehensive assessment of the model’s predictive power in explaining cybersecurity awareness among MFS users.

Ethical considerations

Ethical approval for this study was obtained from the University of KwaZulu-Natal Humanities and Social Sciences Research Ethics Committee (No. HSS/1508/015D), as well as from the Communications Authority of Kenya (Ref. No. CCK/CTMA/Research/Vol 13/10/05), in line with both national and institutional ethical requirements. Authorisation was also obtained from the appropriate organisational gatekeeper representing MFSs users. All participants received a consent letter outlining the purpose of the research, its objectives and the procedures implemented to ensure confidentiality and anonymity. Respondents were assured that their identities would be protected and that their personal information would remain anonymous. Participation was entirely voluntary, and participants were informed of their right to withdraw from the study at any stage without any adverse consequences.

Results

The results demonstrate that user cybersecurity awareness and behaviour in MFSs are systematically shaped by demographic characteristics and the interrelationships specified in the AGAM. Descriptive analysis indicates notable variation in device protection practices, threat detection capability and general security awareness across age groups and educational levels. Younger users (18–40) generally showed stronger cybersecurity practices, with 84.9% (18–25) using phone security locks compared to 44.8% (61+), while older users (51+) demonstrated lower adoption. Formal education, defined from Kenya Certificate of Primary Education (KCPE) to postgraduate level, also influenced behaviour, as higher education (e.g. 89.6% bachelor’s, 78.5% master’s) correlated with stronger security use and reduced reliance on assistance. These patterns highlight the importance of tailoring cybersecurity awareness initiatives to the diverse socio-demographic composition of MFS users.

Beyond these descriptive trends, the structural analysis provides deeper insight into how governance, RA, CB and operational security practices interact to shape cybersecurity behaviour.

Measurement reliability and validity tests confirmed the strength of the constructs, allowing for meaningful interpretation of the structural relationships. The results of the path analysis and hypothesis testing, presented in Figure 2 and Table 4, respectively, demonstrate that RA and CB play central roles in strengthening TM and IRR. These findings empirically support AGAM as an integrated governance–awareness framework capable of explaining user-level cybersecurity behaviour in mobile financial ecosystems.

FIGURE 2: Structural path analysis of adaptive governance awareness model. Standardised path coefficients obtained from partial least squares structural equation modelling showing the magnitude and significance of relationships among adaptive governance awareness model constructs (p < 0.05). All path coefficients were estimated using bootstrapping with 5000 resamples, and significance was assessed at p < 0.05.

Research model testing and validation

The study integrated constructs from the NIST CSF (NIST 2018) and the MediaPro Adaptive Awareness Framework (MediaPro 2019) to identify the most significant factors influencing the security posture of MFS users. To assess the model’s strength, a series of statistical tests were conducted to evaluate both the measurement and structural models systematically (Hair 2014). These evaluations ensured that the constructs demonstrated adequate reliability, validity and predictive relevance, which are essential prerequisites for hypothesis testing (Fornell & Larcker 1981). Additionally, these assessments provided empirical support for the theoretical framework, strengthening the interpretability of the study’s findings.

Reliability coefficients

Reliability coefficients assess the consistency and dependability of a set of measurements or test scores, reflecting the degree to which the data is free from measurement errors and yields consistent results over time or under different conditions.

Reliability and validity assessment

The internal consistency and construct validity of the measurement model were rigorously evaluated prior to structural analysis. Reliability analysis confirmed acceptable levels of internal consistency across all scales, exceeding established thresholds as highlighted by Fornell and Larcker (1981). Convergent validity was assessed using average variance extracted (AVE), with all constructs exceeding the recommended minimum value of 0.50 (Fornell & Larcker 1981), indicating that the indicators adequately represent their respective latent variables (Table 1).

TABLE 1: Convergent validity of adaptive governance awareness model constructs (average variance extracted).
Discriminant validity

Discriminant validity was evaluated using the Fornell–Larcker criterion, which confirmed that each construct was empirically distinct from the others, as the square root of each construct’s AVE exceeded its correlations with other constructs as shown in Table 2.

TABLE 2: Discriminant validity of adaptive governance awareness model constructs (Fornell–Larcker criterion).

An AVE threshold of 0.50 or higher is commonly used to affirm construct reliability and validity (Hair et al. 2019), thus supporting the strength of this measurement model. Collectively, these results establish the adequacy of the measurement model and provide a sound basis for subsequent confirmatory factor analysis (CFA) and structural modelling.

Model validation

Confirmatory factor analysis was performed to assess how well the AGAM measurement model fits the observed data. The overall model fit statistics are summarised in Table 3.

TABLE 3: Overall model fit indices for the adaptive governance awareness model measurement model.

Although the Chi-square minimum discrepancy divided by its degrees of freedom (CMIN/df) ratio exceeded commonly recommended thresholds, alternative and more robust indices indicated excellent model fit. The goodness of fit index (GFI = 0.983) and adjusted GFI (AGFI = 0.922) surpassed the recommended benchmark of 0.90, demonstrating strong absolute model fit. Incremental fit indices, including NFI (0.921), IFI (0.924), TLI (0.914) and CFI (0.923), also exceeded the 0.90 threshold, indicating that the proposed model substantially improves upon the null model.

Furthermore, error-based indices confirmed high model adequacy, with a root mean square residual (RMR) of 0.004 and a root mean square error of approximation (RMSEA) of 0.006, both well within acceptable limits. Taken together, these indicators provide strong evidence that the AGAM measurement model fits the observed data well and is appropriate for testing the hypothesised structural relationships.

Path analysis

After confirming that the measurement constructs achieved an acceptable level of model fit, the next step involved conducting a path analysis using PLS-SEM to examine the relationships within the proposed model. The results, illustrated in Figure 2, show the strength and significance of each path coefficient, with significant relationships marked by green arrows (p < 0.05).

The path analysis confirms that RA and CB play vital roles in cybersecurity management. Risk analysis enhances GP and TM, aligning with frameworks like NIST that highlight risk assessment as central to TM (Freund 2024; NIST 2018; Rahman et al. 2024). Conversely, CB positively affects TM but negatively impacts GP, suggesting targeted approaches are required to integrate capacity-building efforts into strategic governance (Savaş & Karataş 2022). These relationships support the literature emphasising adaptive cybersecurity strategies (ENISA 2020).

Hypothesis testing

Table 4 summarises the outcomes of the hypothesis tests obtained through path analysis. The path coefficients indicate both the magnitude and direction of the relationships between the constructs, whereas the p-values show their level of statistical significance, with values less than 0.05 considered statistically significant.

TABLE 4: Structural path estimates and hypothesis testing results.

The results of the hypothesis testing, derived from path analysis, are presented in Table 4 and highlight the relationships between the constructs in the AGAM. Significant relationships were found across all paths, with estimates ranging from 0.075 to 0.498, all yielding p-values of < 0.001, signifying strong evidence for the acceptance of the hypotheses. These significant relationships confirm the interconnections between the constructs of governance, risk management and incident recovery within the awareness model. The thresholds used for assessing these relationships – such as standardised regression weights (CR values), with critical ratios (CR) exceeding 1.96 (Kline 2023) and p-values lower than 0.05 – demonstrate the reliability and validity of the model constructs in predicting key cybersecurity outcomes (Hair et al. 2019). This solid empirical foundation supports the proposed model’s capability to effectively guide cybersecurity training and awareness strategies.

Final model

Figure 3 depicts the final representation of the AGAM.

FIGURE 3: Final empirically supported adaptive governance awareness model. Final structural representation of adaptive governance awareness model following model testing and validation, highlighting significant interrelationships among governance, risk, capacity building, threat management and incident response.

Discussion

This study developed and validated the AGAM by integrating constructs from the NIST CSF and the MediaPro adaptive awareness framework to explain cybersecurity awareness among MFSs users. The findings demonstrate that cybersecurity behaviour is shaped by the interdependence of governance, RA, CB and TM, extending prior research that often examines these elements in isolation (Bada et al. 2019; ENISA 2020).

Demographic factors significantly influenced user awareness. Younger users (18–40 years) and those with higher educational attainment (Bachelor’s or Master’s degrees) reported higher competence in device protection and threat detection, while older users and those with minimal education exhibited lower confidence (Branley-Bell et al. 2022; Van Deursen & Van Dijk 2014). These findings align with prior work linking digital literacy to age and education, highlighting the need for tailored awareness programmes that account for user characteristics in MFS contexts (GSMA 2022).

Path analysis confirms that RA positively influences GP, TM and IRR, corroborating the NIST emphasis on risk assessment as foundational to cybersecurity (NIST 2018). Conversely, CB positively affects TM but negatively impacts GP, suggesting that while training enhances user-level TM, it must be aligned with governance structures to optimise overall security (Puhakainen & Siponen 2010; Savaş & Karataş 2022). Governance planning also positively supports IRR but showed a negative effect on TM, indicating that rigid policies may limit adaptive user practices, a tension noted in cybersecurity governance research (Weber 2019).

The negative relationships observed between GP and TM and between CB and GP suggest potential tensions between formal governance structures and adaptive user practices. In highly dynamic MFS environments, rigid governance mechanisms may constrain flexible TM behaviours at the user level. Similarly, capacity-building initiatives that focus predominantly on individual skills may operate independently of formal governance processes, reducing their integration into strategic planning. This finding aligns with prior cybersecurity governance research, which highlights the risk of misalignment between policy-driven controls and adaptive security behaviour (Melaku 2023; Modi, Kuzminykh & Ghita 2023; Puhakainen & Siponen 2010; Vrhovec & Markelj 2024; Weber 2019).

These findings underscore AGAM’s theoretical contribution by bridging technical cybersecurity strategies with user-centric behavioural approaches, empirically demonstrating the interconnections between governance, risk and adaptive awareness. Unlike prior models focusing solely on either organisational controls or individual behaviour, AGAM captures their dynamic interplay, offering a holistic explanation of user cybersecurity behaviour in digital financial ecosystems (Bada et al. 2019; Hadlington 2017).

Practically, AGAM provides MFS providers with a framework to design targeted awareness and capacity-building initiatives, particularly for vulnerable demographics, while integrating these programmes within governance structures. Policymakers can adopt AGAM to inform regulations mandating adaptive cybersecurity training and digital literacy initiatives, supporting safe financial inclusion (ENISA 2020; World Bank 2021). Although tested in Kenya, the model’s principles are replicable across diverse socio-economic contexts, providing a flexible foundation for global application.

In conclusion, AGAM advances both theory and practice by demonstrating that effective cybersecurity awareness emerges from the coordinated interaction of governance, RA, CB and adaptive user behaviour, rather than isolated interventions. This integrated perspective addresses critical gaps in existing frameworks and offers actionable guidance for MFS providers, policymakers and educational programmes worldwide.

Strength and limitations

This study’s strengths include the integration of technical (NIST) and behavioural (MediaPro) constructs, combined with robust survey data from 1159 MFS users across diverse demographics and rigorous validation through reliability (Cronbach’s alpha 0.711–0.802), convergent and discriminant validity and CFA. Path analysis further demonstrated the interdependence of governance, RA, CB and TM. Limitations include the cross-sectional design, which limits causal inference, geographic focus on Kenya affecting generalisability, and reliance on self-reported measures, potentially introducing bias. Results should be interpreted considering these constraints, and longitudinal studies are recommended to strengthen causal and external validity.

Recommendation for further research

Based on the study’s findings, several recommendations emerge for future research, policy and practice. The significant effects of age and education on device protection and threat detection suggest that additional socio-economic variables – such as income, employment type and digital access – should be explored to understand their influence on cybersecurity awareness. Such insights would enable more targeted and inclusive interventions, ensuring that awareness programmes reach vulnerable users effectively. The observed lower confidence among older users highlights the need for age-specific training initiatives; future research should design and evaluate adaptive cybersecurity programmes that consider cognitive and behavioural differences, enhancing learning outcomes and threat response across age groups. Cultural factors also merit investigation, as societal norms, trust dynamics and local perceptions of security may shape behaviour; cross-cultural studies could refine AGAM’s adaptability and inform globally relevant awareness strategies. Moreover, validating AGAM in diverse geographic and regulatory contexts would strengthen its generalisability, enabling policymakers and MFS providers to implement evidence-based, context-sensitive interventions that integrate governance, risk assessment and capacity-building efforts.

By linking interventions to demographic, cultural and contextual variables, future studies can ensure that cybersecurity awareness programmes are both effective and equitable, fostering sustained behavioural change.

Collectively, these research avenues will support the development of AGAM as a comprehensive, globally applicable tool for improving cybersecurity awareness and resilience among MFS users, guiding policy, and informing best practices in diverse socio-economic and technological environments.

Conclusion

This study developed the AGAM to enhance cybersecurity awareness among MFS users in Kenya, directly addressing the research question: How can NIST and MediaPro framework components be integrated to improve user cybersecurity awareness? The findings show that demographics, particularly age and education, influence cybersecurity behaviours, with younger and more educated users demonstrating higher competence in device protection and threat detection. This highlights the need for tailored, user-centric interventions, fulfilling the first objective.

Adaptive governance awareness model successfully integrates NIST’s structured governance and risk management elements with MediaPro’s adaptive awareness and capacity-building principles, achieving the second objective. Path analysis (Table 4) confirmed that RA positively affects GP (β = 0.075), TM (β = 0.412) and IRR (β = 0.498), while CB enhances TM (β = 0.174) but negatively impacts GP (β = −0.028). These results demonstrate that coordinated integration of structured controls with adaptive learning strengthens cybersecurity resilience, directly answering the research question.

Contextualised within Kenya, AGAM provides a holistic, empirically supported framework for guiding MFS providers, policymakers and educators. The model shows that aligning governance, RA, CB and adaptive user behaviour fosters proactive security practices, enhancing the safety and resilience of mobile financial ecosystems in Kenya and other developing economies.

Acknowledgements

This article is based on research originally conducted as part of Nicholas W. Omollo’s doctoral thesis titled ‘Information Security Education, Training, and Awareness within the Mobile Financial Services Sector’, submitted to the Department of Mathematics, Statistics and Computer Science, College of Agriculture, Engineering and Science, University of KwaZulu-Natal in 2025. The thesis was supervised by Manoj Maharaj. The thesis was reworked, revised and adapted into a journal article for publication. The original thesis is available at: https://hdl.handle.net/10413/23992.

This article is based on data from a larger study. Two other articles were published from the same thesis. The first article focusing on ‘Exploring Protective Behaviours Among Users of Mobile Financial Services’ has been published in the African Journal of Information Systems Vol 18. The second related article, focusing on Assessing Cybersecurity Threat Avoidance Factors Influencing User Attitudes in Mobile Financial Services in the Context of Kenya, has been published in IST-Africa 2025 Conference Proceedings and by IEEE.

Competing interests

The authors declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.

CRediT authorship contribution

Nicholas W. Omollo: Writing – original draft. Manoj Maharaj: Supervision, Writing – review & editing. All authors reviewed the article, contributed to the discussion of results, approved the final version for submission and publication and take responsibility for the integrity of its findings.

Funding information

This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.

Data availability

The data that support the findings of this study are not openly available because of (ethical restrictions and privacy concerns related to participant confidentiality) and are available from the corresponding author, Nicholas W. Omollo, upon reasonable request. The data is securely kept at the University of KwaZulu-Natal Research office.

Disclaimer

The views and opinions expressed in this article are those of the authors and are the product of professional research. They do not necessarily reflect the official policy or position of any affiliated institution, funder, agency or that of the publisher. The authors are responsible for this article’s results, findings and content.

Reference

8Pillars, 2018, Helping customers solve the human side of security awareness, viewed 03 July 2025, from https://www.8pillars.com.au/products/mediapro/.

Abrahams, T.O., Farayola, O.A., Kaggwa, S., Uwaoma, P.U., Hassan, A.O. & Dawodu, S.O., 2024, ‘Cybersecurity awareness and education programs: A review of employee engagement and accountability’, Computer Science and IT Research Journal 5(1), 100–119. https://doi.org/10.51594/csitrj.v5i1.708

Abrardi, L., Comino, S. & Grassini, S., 2025, ‘The economics of cyber risk: A survey of the literature’, Journal of Industrial and Business Economics 53, 1–35. https://doi.org/10.1007/s40812-025-00370-3

Adongo, M., 2025, Mobile money social engineering attacks in African countries: A survey, SSRN Working Paper No. 5257020, SSRN, Rochester, NY.

Ahirrao, K.B. & Jethani, V., 2014, ‘A security framework on SIM based authentication technique for mobile financial services’, International Journal of Engineering Research and Technology 3(8), viewed 03 July 2025, from https://www.ijert.org/a-security-framework-on-sim-based-authentication-technique-for-mobile-financial-services.

Al Doghan, M.A. & Mirzaliev, S., 2024, ‘Cybersecurity awareness and digital banking adoption: Exploring the moderating impact of digital literacy’, International Journal of Economics and Finance Studies 16(3), 34–58. https://doi.org/10.34109/ijefs.202416303

Al-Shanfari, I., Yassin, W. & Abdullah, R., 2020, ‘Identify of factors affecting information security awareness and weight analysis process’, International Journal of Engineering and Advanced Technology 9(3), 534–542. https://doi.org/10.35940/ijeat.C4775.029320

Bada, M., Sasse, A.M. & Nurse, J.R.C., 2019, ‘Cyber security awareness campaigns: Why do they fail to change behaviour?’, arXiv preprint, arXiv:1901.02672. https://doi.org/10.48550/arXiv.1901.02672

Branley-Bell, D., Coventry, L., Dixon, M., Joinson, A. & Briggs, P., 2022, ‘Exploring age and gender differences in ICT cybersecurity behaviour’, Human Behaviour and Emerging Technologies 2022(1), 2693080. https://doi.org/10.1155/2022/2693080

Brecht, D., 2019, The components of top security awareness programs, p. 15, InfoSec Institute, viewed 24 October 2025, from https://www.infosecinstitute.com/resources/security-awareness/components-top-security-awareness-programs/.

Chin, W.W., 2009, ‘How to write up and report PLS analyses’, in V.E. Vinzi, W.W. Chin, J. Henseler, H. Wang, H. Abdi & G. Russolillo (eds.), Handbook of partial least squares, pp. 655–690, Springer, Berlin.

Communications Authority of Kenya, 2023, ‘Cybersecurity report Q1 2023–2024’, viewed 04 July 2025, from https://www.ca.go.ke/sites/default/files/2023-10/Cybersecurity%20Report%20Q1%202023-2024.pdf.

Cochran, W.G., 1977, Sampling techniques, 3rd edn., John Wiley & Sons, New York.

Dhillon, G. & Backhouse, J., 2000, ‘Information system security management in the new millennium’, Communications of the ACM 43(7), 125–128. https://doi.org/10.1145/341852.341877

Ebel, A. & Mitra, D., 2024, ‘Economics and optimal investment policies of attackers and defenders in cybersecurity’, Journal of Cybersecurity 10(1), tyae019. https://doi.org/10.1093/cybsec/tyae019

European Union Agency for Cybersecurity (ENISA), 2020, Threat landscape report, viewed 25 October 2025, from https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape.

Fornell, C. & Larcker, D.F., 1981, ‘Evaluating structural equation models with unobservable variables and measurement error’, Journal of Marketing Research 18(1), 39–50. https://doi.org/10.1177/002224378101800104

Freund, J., 2024, ‘From measurement to management: Integrating cyberrisk quantification into risk governance’, ISACA Journal 5, 28–36, viewed 20 April 2026, from https://www.researchgate.net/profile/Jack-Freund/publication/387540955_From_Measurement_to_Management_Integrating_Cyberrisk_Quantification_into_Risk_Governance/links/677360a3117f340ec3e89b97/From-Measurement-to-Management-Integrating-Cyberrisk-Quantification-into-Risk-Governance.pdf.

GSMA, 2021, Cybersecurity and mobile money: Prioritising consumer trust and awareness, viewed 20 October 2025, from https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/topic/financial-inclusion/mobile-money-financial-inclusion/cybersecurity-and-mobile-money-prioritising-consumer-trust-and-awareness.

GSMA, 2022, State of the industry report on mobile money 2022, viewed 21 October 2025, from https://media.gsma.com/assets/2022/annual_report.pdf.

GSMA, 2024, Mobile money fraud typologies and mitigation strategies, viewed 21 October 2025, from https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/gsma_resources/mobile-money-fraud-typologies-and-mitigation-strategies/.

Hadlington, L., 2017, ‘Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours’, Heliyon 3(7), e00346. https://doi.org/10.1016/j.heliyon.2017.e00346

Hair, J.F., 2014, A primer on partial least squares structural equation modelling (PLS-SEM), Sage, Thousand Oaks, CA.

Hair, J.F., Black, W.C., Babin, B.J., Anderson, R.E. & Tatham, R.L., 2019, Multivariate data analysis, 8th edn., Pearson, Harlow.

International Telecommunication Union, 2024, Global cybersecurity index, viewed 20 April 2026, from https://www.itu.int/en/ITU-D/Cybersecurity/pages/global-cybersecurity-index.aspx.

ISO/IEC, 2023, ISO/IEC 27035-1:2023 Information security incident management, viewed 21 October 2025, from https://www.iso.org/standard/78973.html#lifecycle.

Iyelolu, T.V., Agu, E.E., Idemudia, C. & Ijomah, T.I., 2024, ‘Conceptualizing mobile banking and payment systems: Adoption trends and security considerations in Africa and the U.S’, International Journal of Science and Technology Research Archive 7(1), 1–9. https://doi.org/10.53771/ijstra.2024.7.1.0052

Jack, W. & Suri, T., 2011, Mobile money: The economics of M-PESA, NBER Working Paper No. 16721, National Bureau of Economic Research, Cambridge, MA. https://doi.org/10.3386/w16721

Kline, R.B., 2023, Principles and practice of structural equation modeling, 5th edn., Guilford Press, New York, NY.

Kshetri, N., 2019, ‘Cybercrime and cybersecurity in Africa’, Journal of Global Information Technology Management 22(2), 77–81. https://doi.org/10.1080/1097198X.2019.1603527

Lamia, I., 2024, ‘Digital illiteracy and the myth of digital natives: Unveiling realities and challenges’, JETT 15(3), 263–276, viewed 05 July 2025, from https://dialnet.unirioja.es/descarga/articulo/9896011.pdf.

Mater, W., Matar, N., Alismaiel, O.A., Al Moteri, M.A., Al Youssef, I.Y. & Al-Rahmi, W.M., 2021, ‘Factors influencing the intention behind mobile wallet adoption: Perceptions of university students’, Entrepreneurship and Sustainability Issues 9(1), 447–460. http://doi.org/10.9770/jesi.2021.9.1(28)

MediaPro, 2018, Adaptive awareness framework, viewed 25 October 2025, from https://www.knowbe4.com/products/security-awareness-training.

MediaPro, 2019, The MediaPro adaptive awareness framework: A model for cybersecurity training, viewed 25 October 2025, from https://www.8pillars.com.au/products/mediapro/.

Melaku, H.M., 2023, ‘A dynamic and adaptive cybersecurity governance framework’, Journal of Cybersecurity and Privacy 3(3), 327–350. https://doi.org/10.3390/jcp3030017

Modi, A., Kuzminykh, I. & Ghita, B., 2023, ‘Data driven approaches to cybersecurity governance for board decision-making – A systematic review’, arXiv preprint arXiv:2311.17578. https://doi.org/10.48550/arXiv.2311.17578

Musyoka, S.M. & Mose, T., 2024, ‘Zero trust maturity model and cyber resilience in mobile money providers in Nairobi City County, Kenya’, International Journal of Social Sciences Management and Entrepreneurship 8(3), 1037–1051, viewed 20 October 2025, from https://www.sagepublishers.com/index.php/ijssme/article/download/700/638.

Mwangi, K.K. & Kasamani, B.S., 2017, ‘A universal mobile money transfer platform’, International Journal of Computer Applications 175(6), 40–47, viewed 05 July 2025, from https://www.ijcaonline.org/archives/volume175/number6/mwangi-2017-ijca-915595.pdf.

Nagyfejeo, E. & Von Solms, B., 2020, ‘Why do national cybersecurity awareness programmes often fail’, International Journal of Information Security and Cybercrime 9(2), 18–27, https://doi.org/10.19107/IJISC.2020.02.03

Naik, N. & Sneha, N., 2023, ‘Implementation of techniques to avoid cyber attacks’, The Online Journal of Distance Education and e-Learning 11(2), 1488–1499, viewed 20 October 2026, from https://tojdel.net/journals/tojdel/articles/v11i02/v11i02-62.pdf.

National Institute of Standards and Technology (NIST), 2018, Framework for improving critical infrastructure cybersecurity, version 1.1, viewed 05 July 2025, from https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf.

Ndung’u, N. & Oguso, A., 2021, ‘Financial sector development and financial inclusion in Africa’, in A.H. Ahmad, D.T. Llewellyn & V. Murinde (eds.), Inclusive financial development, pp. 28–51, Edward Elgar, Cheltenham. https://doi.org/10.4337/9781800376380.00008

Ngugi, J., Mwangi, S. & Kamau, P., 2020, ‘Mobile financial services and cybersecurity threats in Kenya’, International Journal of Cyber Studies 5(2), 34–50.

NIST, 2021, Building a cybersecurity and privacy awareness and training program, viewed 24 October 2025, from https://csrc.nist.gov/publications/detail/sp/800-50/rev-1/draft.

NIST, 2023, NIST cybersecurity framework, viewed 13 October 2025, from https://www.nist.gov/cyberframework.

Odo, C., 2024, Strengthening cybersecurity resilience, SSRN Working Paper, Social Science Research Network (SSRN), Rochester, NY, viewed 20 October 2025, from https://dx.doi.org/10.2139/ssrn.4779289.

Osabutey, E.L.C. & Jackson, T., 2024, ‘Mobile money and financial inclusion in Africa: Emerging themes, challenges and policy implications’, Technological Forecasting and Social Change 202, 123339. https://doi.org/10.1016/j.techfore.2024.123339

Popoola, O.A., Akinsanya, M.O., Nzeako, G., Chukwurah, E.G. & Okeke, C.D., 2024, ‘Exploring theoretical constructs of cybersecurity awareness and training programs: Comparative analysis of African and U.S. Initiatives’, International Journal of Applied Research in Social Sciences 6(5), 819–827. https://doi.org/10.51594/ijarss.v6i5.1104

Puhakainen, P. & Siponen, M., 2010, ‘Improving employees’ compliance through information systems security training: An action research study’, MIS Quarterly 34(4), 757–778. https://doi.org/10.2307/25750704

Rahman, M.M., Kshetri, N., Sayeed, S.A. & Rana, M.M., 2024, ‘AssessITS: Integrating procedural guidelines and practical evaluation metrics for organizational IT and cybersecurity risk assessment’, Journal of Information Security 15, 564–588.

Savaş, S. & Karataş, S., 2022, ‘Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance’, International Cybersecurity Law Review 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4

Schneider, B., Asprion, P.M., Androvicsova, S. & Azan, W., 2020, A practical guideline for developing a managerial information security awareness program, viewed 05 July 2025, from https://scholar.archive.org/work/kctmudhaubdrfmrvcbmmybpp5m/access/wayback/https://aisel.aisnet.org/cgi/viewcontent.cgi?article=1256&context=amcis2020.

Serianu, 2023, Africa cybersecurity report 2023, viewed 30 October 2025, from https://www.serianu.com/downloads/KenyaCyberSecurityReport2023.pdf.

Tobbin, P., 2011, ‘Understanding Mobile Money Ecosystem: Roles, Structure and Strategies’, 2011 10th International Conference on Mobile Business, Como, Italy, pp. 185–194. https://doi.org/10.1109/ICMB.2011.19

TransUnion Africa, 2025, ‘More than four-fifths of Kenyans said they were recently targeted with fraud’, 17 June, viewed 25 October 2025, from https://www.transunionafrica.com/fraud-trends/reports/kenya-2024-h2-omnichannel-fraud-report.

Trim, P.R. & Lee, Y.-I., 2019, ‘The role of B2B marketers in increasing cyber security awareness and influencing behavioural change’, Industrial Marketing Management 83, 224–238. https://doi.org/10.1016/j.indmarman.2019.04.003

Van Deursen, A.J. & Van Dijk, J.A., 2014, ‘The digital divide shifts to differences in usage’, New Media and Society 16(3), 507–526. https://doi.org/10.1177/1461444813487959

Van Zanden, J.L., 2023, ‘Examining the relationship of information and communication technology and financial access in Africa’, Journal of Business and Economic Options 6(3), 26–36, viewed 20 July 2025, from https://resdojournals.com/index.php/jbeo/article/view/242.

Vitus, E.N., 2023, Cybercrime and online safety: Addressing the challenges and solutions related to cybercrime, online fraud, and ensuring a safe digital environment for all users – A case of African States, viewed 20 October 2025, from https://philpapers.org/go.pl?id=VITCAO&proxyId=none&u=http%3A%2F%2Fdx.doi.org%2F10.6084%2Fm9.figshare.24155610.v1.

Von Solms, R. & Van Niekerk, J., 2013, ‘From information security to cyber security’, Computers & Security 38, 97–102. https://doi.org/10.1016/j.cose.2013.04.004

Vrhovec, S. & Markelj, B., 2024, ‘We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers’, PLoS One 19(10), e0312266. https://doi.org/10.1371/journal.pone.0312266

Wainaina, G.N., Kiyeng, D. & Masese, N., 2023, ‘Enhancing security measures for mobile banking applications: A comprehensive analysis of threats, vulnerabilities, and countermeasures in Kenya banking industry’, International Journal of Computer Applications Technology and Research 12(8), 99–112. https://doi.org/10.7753/IJCATR1208.1014

Wakoli, L.W., 2024, ‘Factors That influence cybersecurity compliance behaviours by bank employees: A case of banks operating in Kenya’, International Journal of Scientific Research and Management 12(12), 8037–8046. https://doi.org/10.18535/ijsrm/v12i12.em02

Weber, R.H., 2019, A new trade regime for digital assets, WTO Workshop, London.

Whitman, M.E. & Mattord, H.J., 2004, Principles of information security, Thomson Course Technology, Boston, MA.

World Bank, 2021, Consumer risks in fintech, World Bank, Washington, DC, viewed 20 October 2025, from https://hdl.handle.net/10986/35699.

World Bank, 2023, Annual progress report FY23-24, World Bank, Washington, DC, viewed 20 April 2026, from https://thedocs.worldbank.org/en/doc/ae07a1384f3e2b5242cbdd9f2d12bd4b-0060052024/original/CWPF-FY23-24-Annual-Report-11-4-2024.pdf.



Crossref Citations

No related citations found.