<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d1 20130915//EN" "http://jats.nlm.nih.gov/publishing/1.1d1/JATS-journalpublishing1.dtd">
<article article-type="research-article" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">SAJIM</journal-id>
<journal-title-group>
<journal-title>South African Journal of Information Management</journal-title>
</journal-title-group>
<issn pub-type="ppub">2078-1865</issn>
<issn pub-type="epub">1560-683X</issn>
<publisher>
<publisher-name>AOSIS</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">SAJIM-28-2166</article-id>
<article-id pub-id-type="doi">10.4102/sajim.v28i1.2166</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Original Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Adaptive governance awareness model for improving user security in mobile financial services</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<contrib-id contrib-id-type="orcid">https://orcid.org/0009-0002-3387-7151</contrib-id>
<name>
<surname>Omollo</surname>
<given-names>Nicholas W.</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<contrib contrib-type="author">
<contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-5340-1794</contrib-id>
<name>
<surname>Maharaj</surname>
<given-names>Manoj</given-names>
</name>
<xref ref-type="aff" rid="AF0001">1</xref>
</contrib>
<aff id="AF0001"><label>1</label>School of Agriculture and Science, College of Agriculture, Engineering &#x0026; Science, University of KwaZulu-Natal, Durban, South Africa</aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><bold>Corresponding author:</bold> Nicholas Omollo, <email xlink:href="nickywash@gmail.com">nickywash@gmail.com</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>13</day><month>08</month><year>2026</year></pub-date>
<pub-date pub-type="collection"><year>2026</year></pub-date>
<volume>28</volume>
<issue>1</issue>
<elocation-id>2166</elocation-id>
<history>
<date date-type="received"><day>11</day><month>02</month><year>2026</year></date>
<date date-type="accepted"><day>23</day><month>04</month><year>2026</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026. The Authors</copyright-statement>
<copyright-year>2026</copyright-year>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>Licensee: AOSIS. This work is licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.</license-p>
</license>
</permissions>
<abstract>
<sec id="st1">
<title>Background</title>
<p>The rapid growth of mobile financial services (MFSs) has expanded financial inclusion but also increased users&#x2019; exposure to cybersecurity threats. Existing awareness programmes and governance frameworks had not adequately addressed the dynamic and behavioural dimensions of user security in mobile financial ecosystems, particularly in developing economies.</p>
</sec>
<sec id="st2">
<title>Objectives</title>
<p>This study addressed this gap by developing and validating the adaptive governance awareness model (AGAM) to improve cybersecurity awareness and governance among MFS users. The model aimed to provide a framework that linked governance processes, user awareness and behavioural practices to security outcomes.</p>
</sec>
<sec id="st3">
<title>Method</title>
<p>A quantitative research design was employed using a structured questionnaire administered to MFS users in Kenya. Statistical analyses were conducted to examine relationships between demographic factors, awareness levels and security behaviours. Adaptive governance awareness model was operationalised by integrating the National Institute of Standards and Technology and MediaPro Frameworks.</p>
</sec>
<sec id="st4">
<title>Results</title>
<p>The findings revealed significant gaps in user awareness and inconsistencies in cybersecurity behaviour. Demographic factors influenced both awareness and security practices. The results demonstrated that adaptive governance and awareness interventions aligned with AGAM improved the management of user-level cybersecurity risks in MFS environments.</p>
</sec>
<sec id="st5">
<title>Conclusion</title>
<p>Integrating behavioural awareness with structured governance processes enhanced users&#x2019; cybersecurity resilience and supported more effective information security management in mobile financial ecosystems.</p>
</sec>
<sec id="st6">
<title>Contribution</title>
<p>This study filled a theoretical and practical gap by introducing and empirically supporting AGAM as an awareness and governance model for cybersecurity in MFSs. The model extended existing frameworks by embedding adaptive, behaviour-oriented governance, offering actionable insights for managers, policymakers and information systems researchers.</p>
</sec>
</abstract>
<kwd-group>
<kwd>NIST Cybersecurity Framework</kwd>
<kwd>adaptive governance awareness model</kwd>
<kwd>mobile financial services</kwd>
<kwd>cybersecurity awareness</kwd>
<kwd>MediaPro Adaptive Awareness Framework</kwd>
<kwd>risk analysis</kwd>
<kwd>capacity building</kwd>
</kwd-group>
<funding-group>
<funding-statement><bold>Funding information</bold> This research received no specific grant from any funding agency in the public, commercial or not-for-profit sectors.</funding-statement>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s0001">
<title>Introduction</title>
<p>The rapid expansion of mobile financial services (MFSs) in developing economies, particularly across Africa, has transformed access to financial systems and accelerated financial inclusion (Jack &#x0026; Suri <xref ref-type="bibr" rid="CIT0028">2011</xref>). In Kenya, M-PESA &#x2013; a leading mobile phone-based money transfer, payment and micro-financing service launched by Safaricom in partnership with Vodafone in 2007 &#x2013; has become integral to everyday economic activity, supporting payments, savings and remittances. However, this expansion has also heightened users&#x2019; exposure to cybersecurity threats, often exacerbated by limited digital literacy, socio-economic inequality and uneven regulatory enforcement (Abrahams et al. <xref ref-type="bibr" rid="CIT0002">2024</xref>; Communications Authority of Kenya <xref ref-type="bibr" rid="CIT0012">2023</xref>; Musyoka &#x0026; Mose <xref ref-type="bibr" rid="CIT0037">2024</xref>).</p>
<p>Compared with developed economies, many African MFS ecosystems operate within low-resource and heterogeneous environments, where feature phones, informal practices and basic authentication mechanisms shape distinctive patterns of security behaviour and vulnerability (GSMA <xref ref-type="bibr" rid="CIT0019">2021</xref>; Kshetri <xref ref-type="bibr" rid="CIT0030">2019</xref>). Empirical evidence indicates that weak user awareness and risky practices significantly increase exposure to fraud and social engineering attacks, underscoring the importance of cybersecurity awareness for sustaining trust in digital finance and protecting livelihoods (Bada, Sasse &#x0026; Nurse <xref ref-type="bibr" rid="CIT0008">2019</xref>; GSMA <xref ref-type="bibr" rid="CIT0021">2024</xref>; Serianu <xref ref-type="bibr" rid="CIT0053">2023</xref>).</p>
<p>From a scientific perspective, cybersecurity is widely recognised as a multidimensional challenge encompassing technological, organisational and behavioural dimensions (Trim &#x0026; Lee <xref ref-type="bibr" rid="CIT0056">2019</xref>). Prior research highlights the role of cybersecurity education and training (Al-Shanfari, Yassin &#x0026; Abdullah <xref ref-type="bibr" rid="CIT0007">2020</xref>; Schneider et al. <xref ref-type="bibr" rid="CIT0052">2020</xref>), alongside governance structures and risk management practices, in shaping security outcomes. Established frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) provide structured guidance for cybersecurity governance and risk management (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>), while awareness-oriented models such as the MediaPro Adaptive Awareness Framework emphasise behavioural reinforcement and continuous learning (MediaPro <xref ref-type="bibr" rid="CIT0033">2018</xref>). However, these frameworks were largely developed for organisational or high-resource contexts and offer limited guidance for individual MFS users in developing economies, where digital literacy, regulatory maturity and socio-economic conditions vary considerably (International Telecommunication Union <xref ref-type="bibr" rid="CIT0025">2024</xref>; Kshetri <xref ref-type="bibr" rid="CIT0030">2019</xref>; World Bank <xref ref-type="bibr" rid="CIT0067">2023</xref>).</p>
<p>This study addresses this gap by proposing the adaptive governance awareness model (AGAM), a context-sensitive framework tailored to MFS users in Kenya and comparable developing economies. Adaptive governance awareness model integrates governance-oriented cybersecurity controls from the NIST CSF (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>) with the adaptive, behaviour-focused principles of the MediaPro framework (MediaPro <xref ref-type="bibr" rid="CIT0034">2019</xref>), enabling flexible application across diverse MFS ecosystems. By systematically linking governance structures with adaptive awareness strategies, AGAM offers an empirically supported approach for addressing user behaviour, regulatory diversity and persistent cybersecurity threats in MFSs (Adongo <xref ref-type="bibr" rid="CIT0004">2025</xref>; Osabutey &#x0026; Jackson <xref ref-type="bibr" rid="CIT0047">2024</xref>).</p>
<sec id="s20002">
<title>Research problem</title>
<p>The widespread adoption of MFSs in Kenya has transformed financial transactions but has also introduced significant cybersecurity risks (Musyoka &#x0026; Mose <xref ref-type="bibr" rid="CIT0037">2024</xref>; Ngugi, Mwangi &#x0026; Kamau <xref ref-type="bibr" rid="CIT0043">2020</xref>). While existing frameworks, such as the NIST CSF and the MediaPro Adaptive Awareness Framework, offer structured approaches to cybersecurity, they were primarily developed in contexts with higher digital literacy and more robust security infrastructures (Kshetri <xref ref-type="bibr" rid="CIT0030">2019</xref>). These frameworks do not fully account for the socio-economic, technological and behavioural factors that shape cybersecurity awareness among MFS users in Kenya. Given the increasing sophistication of cyber threats and the reliance on mobile transactions in Kenya, there is a critical need for an integrated model that aligns with local realities. This study, therefore, seeks to bridge this gap by developing the AGAM, a context-specific framework that enhances cybersecurity awareness and user behaviour in mobile financial ecosystems. Unlike a direct application of these frameworks, AGAM synthesises structured security controls with adaptive learning, ensuring that cybersecurity awareness is both regulatory-aligned and behaviourally reinforced.</p>
</sec>
<sec id="s20003">
<title>Research objectives</title>
<p>Kenya, with its widespread adoption of mobile money platforms such as M-PESA, exemplifies both the opportunities and challenges of MFSs in developing economies. While MFSs have enhanced financial inclusion, it has also introduced significant cybersecurity vulnerabilities because of diverse user demographics, varying levels of digital literacy and evolving cyber threats (Musyoka &#x0026; Mose <xref ref-type="bibr" rid="CIT0037">2024</xref>). This study seeks to develop a cybersecurity awareness model that aligns with these contextual realities, offering insights applicable to Kenya and other developing economies where MFSs play a crucial role.</p>
<p>To achieve this, the study introduces the AGAM, an integrated cybersecurity awareness framework specifically designed for MFS users in Kenya. Adaptive governance awareness model is formulated by synthesising two well-established frameworks: The NIST CSF, which provides a structured approach to cybersecurity risk management (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>), and the MediaPro Adaptive Awareness Framework, which emphasises continuous learning and reinforcement to strengthen user security behaviour (MediaPro <xref ref-type="bibr" rid="CIT0034">2019</xref>). The integration of these frameworks is guided by the need to balance structured governance with user-centric learning strategies, ensuring that cybersecurity awareness aligns with the socio-technical landscape in Kenya. This is essential as cybersecurity challenges in MFSs are significantly influenced by user behaviour, awareness levels and evolving threat vectors such as phishing and social engineering (Wainaina, Kiyeng &#x0026; Masese <xref ref-type="bibr" rid="CIT0062">2023</xref>; Wakoli <xref ref-type="bibr" rid="CIT0063">2024</xref>). Furthermore, empirical studies demonstrate that cybersecurity awareness and digital literacy play a critical role in shaping secure user behaviour and the adoption of digital financial services (Al Doghan &#x0026; Mirzaliev <xref ref-type="bibr" rid="CIT0006">2024</xref>). By integrating these frameworks, AGAM is expected not only to enhance user security knowledge but also to cultivate proactive security habits among MFS users.</p>
<p>The study theorises that the structured security controls from the NIST framework, when complemented by the adaptive and behaviour-focused principles of the MediaPro framework, will create a comprehensive approach to improving cybersecurity awareness among MFS users. By contextualising these models within the Kenyan and broader African experience, the study aims to assess how various cybersecurity awareness components influence user behaviour and resilience against threats. Therefore, the research seeks to answer the following question: How can the components of the NIST CSF and the MediaPro Adaptive Awareness Framework be integrated to enhance cybersecurity awareness among users of MFSs in Kenya?</p>
</sec>
</sec>
<sec id="s0004">
<title>Theoretical framework and literature review</title>
<sec id="s20005">
<title>Mobile financial services</title>
<p>Mobile financial services refer to financial transactions conducted through mobile devices, enabling users to store, transfer and manage money electronically, particularly in regions with limited access to traditional banking infrastructure (Mater et al. <xref ref-type="bibr" rid="CIT0032">2021</xref>; Van Zanden <xref ref-type="bibr" rid="CIT0058">2023</xref>). Common MFS transactions include person-to-person money transfers, bill payments, savings and mobile banking services such as account management and international remittances (Ndung&#x2019;u &#x0026; Oguso <xref ref-type="bibr" rid="CIT0042">2021</xref>). By lowering transaction costs and reducing geographical barriers, MFSs have played a significant role in extending financial services to unbanked and underbanked populations in developing economies (Mwangi &#x0026; Kasamani <xref ref-type="bibr" rid="CIT0038">2017</xref>).</p>
<p>An MFS ecosystem typically comprises mobile network operators, financial institutions, agents, merchants and regulatory authorities, whose interactions enable the delivery and sustainability of mobile-based financial services (Tobin <xref ref-type="bibr" rid="CIT0054">2011</xref>). Platforms such as M-PESA in Kenya and MTN Mobile Money in Uganda illustrate how telecommunications and financial infrastructures are integrated to support domestic and cross-border transactions (Van Zanden <xref ref-type="bibr" rid="CIT0058">2023</xref>). While initially designed for basic money transfers, MFS platforms have evolved to include microloans, insurance products and merchant payments, further deepening financial inclusion and economic participation (Ahirrao &#x0026; Jethani <xref ref-type="bibr" rid="CIT0005">2014</xref>).</p>
</sec>
<sec id="s20006">
<title>Cybersecurity awareness</title>
<p>Cybersecurity awareness refers to users&#x2019; understanding of cyber risks and their ability to recognise, avoid and respond to security threats when interacting with digital systems. In developing economies, limited digital literacy and uneven access to cybersecurity education increase users&#x2019; susceptibility to fraud, particularly within MFS environments (Iyelolu et al. <xref ref-type="bibr" rid="CIT0027">2024</xref>; Vitus <xref ref-type="bibr" rid="CIT0059">2023</xref>). Recent evidence indicates high exposure to digital fraud among Mobile financial services users in Kenya, highlighting the urgent need for awareness initiatives tailored to diverse literacy levels and socio-economic conditions (TransUnion Africa <xref ref-type="bibr" rid="CIT0055">2025</xref>).</p>
<p>Effective cybersecurity awareness programmes must therefore be adaptive, inclusive and responsive to evolving threat landscapes. Prior studies emphasise the importance of multifaceted awareness strategies that combine training, communication and behavioural reinforcement to address heterogeneous user capabilities (Brecht <xref ref-type="bibr" rid="CIT0010">2019</xref>; Nagyfejeo &#x0026; Von Solms <xref ref-type="bibr" rid="CIT0039">2020</xref>). Well-designed awareness initiatives enhance users&#x2019; capacity to recognise cyber threats, adopt secure behaviours and reduce systemic exposure to cybercrime within financial ecosystems (Naik &#x0026; Sneha <xref ref-type="bibr" rid="CIT0040">2023</xref>; NIST <xref ref-type="bibr" rid="CIT0044">2021</xref>; Odo <xref ref-type="bibr" rid="CIT0046">2024</xref>; Popoola et al. <xref ref-type="bibr" rid="CIT0048">2024</xref>).</p>
</sec>
<sec id="s20007">
<title>National institute of standards and technology cybersecurity framework</title>
<p>The NIST CSF provides a structured approach to managing cybersecurity risks through a set of core functions &#x2013; Identify, Protect, Detect, Respond and Recover &#x2013; designed to guide organisations in developing and implementing effective security practices (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>). The introduction of the Govern function further underscores the importance of cybersecurity governance, emphasising alignment between organisational objectives, risk management and awareness initiatives (NIST <xref ref-type="bibr" rid="CIT0045">2023</xref>). While widely adopted, the framework is primarily organisational in focus and offers limited guidance on individual user awareness in low-resource MFS contexts.</p>
</sec>
<sec id="s20008">
<title>MediaPro adaptive awareness framework</title>
<p>The MediaPro Adaptive Awareness Framework adopts a user-centric approach to cybersecurity awareness through four core components: Analyse, Plan, Train and Reinforce (MediaPro <xref ref-type="bibr" rid="CIT0033">2018</xref>). The framework emphasises continuous assessment of user awareness levels, strategic planning of awareness initiatives, engaging training methods and ongoing reinforcement of secure behaviours (8Pillars <xref ref-type="bibr" rid="CIT0001">2018</xref>). Its adaptive design allows awareness content to be personalised based on user behaviour and risk profiles, making it particularly suitable for dynamic environments such as MFSs. However, the framework lacks explicit governance and regulatory integration, limiting its effectiveness when applied independently in regulated financial ecosystems.</p>
</sec>
<sec id="s20009">
<title>Conceptual framework</title>
<p>This study is underpinned by an integrated conceptual framework that combines risk-based cybersecurity governance theory with adaptive cybersecurity awareness and behavioural learning theory to explain cybersecurity awareness within MFS environments. The framework is developed through the integration of constructs from the NIST CSF and the MediaPro Adaptive Awareness Framework, which together provide a socio-technical perspective on cybersecurity awareness.</p>
<p>The NIST CSF conceptualises cybersecurity as a structured, lifecycle-oriented process encompassing governance, risk identification, protection, detection, response and recovery (NIST <xref ref-type="bibr" rid="CIT0045">2023</xref>). The framework offers a strong theoretical foundation for understanding how cybersecurity is governed and operationalised through formal policies, risk management processes and technical controls. However, prior studies have observed that governance-centric frameworks such as NIST give limited attention to behavioural, cognitive and socio-cultural factors that influence how users perceive and respond to cybersecurity risks, particularly in developing economies (Popoola et al. <xref ref-type="bibr" rid="CIT0048">2024</xref>).</p>
<p>To address this limitation, the conceptual framework also draws on the MediaPro Adaptive Awareness Framework, which conceptualises cybersecurity awareness as an iterative process of analysis, training and reinforcement (MediaPro <xref ref-type="bibr" rid="CIT0034">2019</xref>). MediaPro is grounded in behavioural and educational theory and emphasises sustained learning, user engagement and reinforcement as mechanisms for influencing cybersecurity behaviour over time. The integration of NIST and MediaPro therefore enables the conceptualisation of cybersecurity awareness as a socio-technical system, in which governance structures, technical safeguards and user behaviour are mutually reinforcing.</p>
<p>The resulting AGAM has been contextualised for MFS environments in developing economies, where rapid digital financial inclusion has expanded the cyber threat landscape amid uneven digital literacy and limited institutional capacity (Iyelolu et al. <xref ref-type="bibr" rid="CIT0027">2024</xref>; Lamia <xref ref-type="bibr" rid="CIT0031">2024</xref>). In such contexts, cybersecurity awareness cannot be adequately explained through technical controls or training initiatives alone. Instead, it emerges from the interaction between governance mechanisms, risk perception, threat management practices and continuous capacity building.</p>
<p>Adaptive governance awareness model consolidates overlapping constructs from established cybersecurity governance and awareness frameworks into five information management-oriented dimensions: Governance Planning (GP), Risk Analysis (RA), Threat Management (TM), Incident Response and Recovery (IRR) and Capacity Building (CB). Governance Planning reflects strategic information governance through policy alignment, regulatory compliance and organisational oversight that shape cybersecurity decision-making processes (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>). Risk analysis is positioned as a forward-looking information management function that supports the systematic identification, evaluation and prioritisation of cybersecurity risks (Whitman &#x0026; Mattord <xref ref-type="bibr" rid="CIT0065">2004</xref>), while TM represents the operational use of security information through continuous monitoring and the application of protective controls in response to identified risks, thereby maintaining a clear distinction between strategic planning and operational execution (Von Solms &#x0026; Van Niekerk <xref ref-type="bibr" rid="CIT0060">2013</xref>). Incident response and recovery emphasises organisational resilience by integrating information flows for response coordination, service restoration and post-incident learning (ISO/IEC <xref ref-type="bibr" rid="CIT0026">2023</xref>). Capacity building frames cybersecurity awareness as an ongoing knowledge management and learning process that enhances adaptive user behaviour and institutional capability, which is particularly critical in MFS environments characterised by diverse user competencies (Dhillon &#x0026; Backhouse <xref ref-type="bibr" rid="CIT0014">2000</xref>; Musyoka &#x0026; Mose <xref ref-type="bibr" rid="CIT0037">2024</xref>).</p>
<p>The conceptual framework further posits that these constructs are interrelated rather than sequential. Governance planning shapes the deployment of TM and incident response mechanisms, while RA continuously informs governance adaptation and operational priorities. Capacity building functions as a cross-cutting enabler, influencing governance effectiveness, threat recognition and response capability. These relationships reflect established insights from cybersecurity governance and behavioural security literature, which emphasise the reciprocal interaction between policy, risk perception, technical controls and user behaviour (Dhillon &#x0026; Backhouse <xref ref-type="bibr" rid="CIT0014">2000</xref>; NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>).</p>
<p>By integrating governance and adaptive awareness perspectives, AGAM responds to calls for CSFs that are contextually grounded and behaviourally informed, particularly within developing economies (Al Doghan &#x0026; Mirzaliev <xref ref-type="bibr" rid="CIT0006">2024</xref>; Kshetri <xref ref-type="bibr" rid="CIT0030">2019</xref>). The conceptual relationships among the constructs are illustrated in <xref ref-type="fig" rid="F0001">Figure 1</xref>, which presents AGAM as a holistic framework for understanding and strengthening cybersecurity awareness in MFSs.</p>
<fig id="F0001">
<label>FIGURE 1</label>
<caption><p>Proposed adaptive governance awareness model. Conceptual integration of National Institute of Standards and Technology governance functions and MediaPro adaptive awareness processes, illustrating hypothesised relationships among governance planning, risk analysis, threat management, incident response and recovery and capacity building.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2166-g001.tif"/>
</fig>
</sec>
</sec>
<sec id="s0010">
<title>Research methods and design</title>
<p>The study employed a quantitative research design, surveying 1159 respondents in Kenya to examine their interaction with MFS platforms and their cybersecurity awareness. The questionnaire was structured to assess user engagement with MFSs and their understanding of security vulnerabilities, aligning with best practices in cybersecurity research (Abrardi, Comino &#x0026; Grassini <xref ref-type="bibr" rid="CIT0003">2025</xref>; Ebel &#x0026; Mitra <xref ref-type="bibr" rid="CIT0015">2024</xref>). The research model incorporated five interrelated constructs: GP, RA, TM, IRR and CB, reflecting established CSFs such as the NIST CSF (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>).</p>
<p>The target population consisted of MFS users. Because of the wide geographic distribution of users, cluster sampling was employed. The population was divided into clusters based on major cities, and five cities (Nairobi, Nakuru, Mombasa, Kisumu and Eldoret) were randomly selected to represent the population&#x2019;s demographic diversity, including age, gender, education and income.</p>
<p>A total of 1170 questionnaires were distributed to the selected cities, with 1159 returned, representing a 99.06&#x0025; response rate. The sample size was determined using Cochran&#x2019;s formula (Cochran <xref ref-type="bibr" rid="CIT0013">1977</xref>) for finite populations with a 95&#x0025; confidence level, a 3&#x0025; margin of error and a conservative population proportion of 50&#x0025;, yielding an initial sample of 1067. To account for potential non-responses, the sample was increased by 10&#x0025;.</p>
<p>Within the selected clusters, random sampling ensured that each individual had an equal probability of being selected. Questionnaires were distributed with follow-ups by research assistants to maximise response rates.</p>
<p>Inclusion criteria were individuals aged 18 years and above who actively use MFSs. Individuals under 18 years or those without experience using MFSs were excluded from the study.</p>
<p>To analyse the relationships among the constructs, the study utilised both variance-based and covariance-based structural equation modelling (SEM), consistent with methodological recommendations for validating measurement models before testing structural relationships (Hair <xref ref-type="bibr" rid="CIT0023">2014</xref>). Variance-based SEM, specifically partial least squares SEM (PLS-SEM), was selected because of its strengths in exploratory research and its capacity to manage complex models with relatively small sample sizes (Chin <xref ref-type="bibr" rid="CIT0011">2009</xref>). Conversely, covariance-based SEM (CB-SEM) was employed to evaluate the model&#x2019;s overall goodness-of-fit, ensuring construct validity and reliability (Kline <xref ref-type="bibr" rid="CIT0029">2023</xref>). This dual approach allowed for a comprehensive assessment of the model&#x2019;s predictive power in explaining cybersecurity awareness among MFS users.</p>
<sec id="s20011">
<title>Ethical considerations</title>
<p>Ethical approval for this study was obtained from the University of KwaZulu-Natal Humanities and Social Sciences Research Ethics Committee (No. HSS/1508/015D), as well as from the Communications Authority of Kenya (Ref. No. CCK/CTMA/Research/Vol 13/10/05), in line with both national and institutional ethical requirements. Authorisation was also obtained from the appropriate organisational gatekeeper representing MFSs users. All participants received a consent letter outlining the purpose of the research, its objectives and the procedures implemented to ensure confidentiality and anonymity. Respondents were assured that their identities would be protected and that their personal information would remain anonymous. Participation was entirely voluntary, and participants were informed of their right to withdraw from the study at any stage without any adverse consequences.</p>
</sec>
</sec>
<sec id="s0012">
<title>Results</title>
<p>The results demonstrate that user cybersecurity awareness and behaviour in MFSs are systematically shaped by demographic characteristics and the interrelationships specified in the AGAM. Descriptive analysis indicates notable variation in device protection practices, threat detection capability and general security awareness across age groups and educational levels. Younger users (18&#x2013;40) generally showed stronger cybersecurity practices, with 84.9&#x0025; (18&#x2013;25) using phone security locks compared to 44.8&#x0025; (61+), while older users (51+) demonstrated lower adoption. Formal education, defined from Kenya Certificate of Primary Education (KCPE) to postgraduate level, also influenced behaviour, as higher education (e.g. 89.6&#x0025; bachelor&#x2019;s, 78.5&#x0025; master&#x2019;s) correlated with stronger security use and reduced reliance on assistance. These patterns highlight the importance of tailoring cybersecurity awareness initiatives to the diverse socio-demographic composition of MFS users.</p>
<p>Beyond these descriptive trends, the structural analysis provides deeper insight into how governance, RA, CB and operational security practices interact to shape cybersecurity behaviour.</p>
<p>Measurement reliability and validity tests confirmed the strength of the constructs, allowing for meaningful interpretation of the structural relationships. The results of the path analysis and hypothesis testing, presented in <xref ref-type="fig" rid="F0002">Figure 2</xref> and <xref ref-type="table" rid="T0004">Table 4</xref>, respectively, demonstrate that RA and CB play central roles in strengthening TM and IRR. These findings empirically support AGAM as an integrated governance&#x2013;awareness framework capable of explaining user-level cybersecurity behaviour in mobile financial ecosystems.</p>
<fig id="F0002">
<label>FIGURE 2</label>
<caption><p>Structural path analysis of adaptive governance awareness model. Standardised path coefficients obtained from partial least squares structural equation modelling showing the magnitude and significance of relationships among adaptive governance awareness model constructs (<italic>p</italic> &#x003C; 0.05). All path coefficients were estimated using bootstrapping with 5000 resamples, and significance was assessed at <italic>p</italic> &#x003C; 0.05.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2166-g002.tif"/>
</fig>
</sec>
<sec id="s0013">
<title>Research model testing and validation</title>
<p>The study integrated constructs from the NIST CSF (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>) and the MediaPro Adaptive Awareness Framework (MediaPro <xref ref-type="bibr" rid="CIT0034">2019</xref>) to identify the most significant factors influencing the security posture of MFS users. To assess the model&#x2019;s strength, a series of statistical tests were conducted to evaluate both the measurement and structural models systematically (Hair <xref ref-type="bibr" rid="CIT0023">2014</xref>). These evaluations ensured that the constructs demonstrated adequate reliability, validity and predictive relevance, which are essential prerequisites for hypothesis testing (Fornell &#x0026; Larcker <xref ref-type="bibr" rid="CIT0017">1981</xref>). Additionally, these assessments provided empirical support for the theoretical framework, strengthening the interpretability of the study&#x2019;s findings.</p>
<sec id="s20014">
<title>Reliability coefficients</title>
<p>Reliability coefficients assess the consistency and dependability of a set of measurements or test scores, reflecting the degree to which the data is free from measurement errors and yields consistent results over time or under different conditions.</p>
<sec id="s30015">
<title>Reliability and validity assessment</title>
<p>The internal consistency and construct validity of the measurement model were rigorously evaluated prior to structural analysis. Reliability analysis confirmed acceptable levels of internal consistency across all scales, exceeding established thresholds as highlighted by Fornell and Larcker (<xref ref-type="bibr" rid="CIT0017">1981</xref>). Convergent validity was assessed using average variance extracted (AVE), with all constructs exceeding the recommended minimum value of 0.50 (Fornell &#x0026; Larcker <xref ref-type="bibr" rid="CIT0017">1981</xref>), indicating that the indicators adequately represent their respective latent variables (<xref ref-type="table" rid="T0001">Table 1</xref>).</p>
<table-wrap id="T0001">
<label>TABLE 1</label>
<caption><p>Convergent validity of adaptive governance awareness model constructs (average variance extracted).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Construct</th>
<th valign="top" align="center">AVE value</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Governance planning</td>
<td align="center">0.527</td>
</tr>
<tr>
<td align="left">Risk analysis</td>
<td align="center">0.569</td>
</tr>
<tr>
<td align="left">Threat management</td>
<td align="center">0.572</td>
</tr>
<tr>
<td align="left">Incident response and recovery</td>
<td align="center">0.642</td>
</tr>
<tr>
<td align="left">Capacity building</td>
<td align="center">0.630</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Average variance extracted values for all constructs exceed the 0.50 threshold, indicating satisfactory convergent validity.</p></fn>
<fn><p>AVE, Average variance extracted.</p></fn>
</table-wrap-foot>
</table-wrap>
</sec>
<sec id="s30016">
<title>Discriminant validity</title>
<p>Discriminant validity was evaluated using the Fornell&#x2013;Larcker criterion, which confirmed that each construct was empirically distinct from the others, as the square root of each construct&#x2019;s AVE exceeded its correlations with other constructs as shown in <xref ref-type="table" rid="T0002">Table 2</xref>.</p>
<table-wrap id="T0002">
<label>TABLE 2</label>
<caption><p>Discriminant validity of adaptive governance awareness model constructs (Fornell&#x2013;Larcker criterion).</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Construct</th>
<th valign="top" align="center">GP</th>
<th valign="top" align="center">TM</th>
<th valign="top" align="center">RA</th>
<th valign="top" align="center">CB</th>
<th valign="top" align="center">IRR</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">GP</td>
<td align="center">0.726</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">TM</td>
<td align="center">0.129</td>
<td align="center">0.706</td>
<td align="center">-</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">RA</td>
<td align="center">0.168</td>
<td align="center">0.211</td>
<td align="center">0.704</td>
<td align="center">-</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">CB</td>
<td align="center">0.143</td>
<td align="center">0.246</td>
<td align="center">0.330</td>
<td align="center">0.794</td>
<td align="center">-</td>
</tr>
<tr>
<td align="left">IRR</td>
<td align="center">0.336</td>
<td align="center">0.151</td>
<td align="center">0.461</td>
<td align="center">0.335</td>
<td align="center">0.801</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>GP, Governance planning; RA, risk analysis; IRR, incident response and recovery; CB, capacity building; TM, threat management; AGAM, adaptive governance awareness model.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>An AVE threshold of 0.50 or higher is commonly used to affirm construct reliability and validity (Hair et al. <xref ref-type="bibr" rid="CIT0024">2019</xref>), thus supporting the strength of this measurement model. Collectively, these results establish the adequacy of the measurement model and provide a sound basis for subsequent confirmatory factor analysis (CFA) and structural modelling.</p>
</sec>
</sec>
<sec id="s20017">
<title>Model validation</title>
<p>Confirmatory factor analysis was performed to assess how well the AGAM measurement model fits the observed data. The overall model fit statistics are summarised in <xref ref-type="table" rid="T0003">Table 3</xref>.</p>
<table-wrap id="T0003">
<label>TABLE 3</label>
<caption><p>Overall model fit indices for the adaptive governance awareness model measurement model.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">categorisation</th>
<th valign="top" align="left">Index</th>
<th valign="top" align="center">Value</th>
<th valign="top" align="center">Recommended threshold</th>
<th valign="top" align="left">Interpretation</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Absolute fit</td>
<td align="left">CMIN/<italic>df</italic></td>
<td align="center">25.711</td>
<td align="center">&#x003C; 5.000</td>
<td align="left">Above threshold</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">RMR</td>
<td align="center">0.004</td>
<td align="center">&#x003C; 0.008</td>
<td align="left">Excellent fit</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">GFI</td>
<td align="center">0.983</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Excellent fit</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">AGFI</td>
<td align="center">0.922</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Good fit</td>
</tr>
<tr>
<td align="left">Incremental fit</td>
<td align="left">NFI</td>
<td align="center">0.921</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Good fit</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">IFI</td>
<td align="center">0.924</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Good fit</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">TLI</td>
<td align="center">0.914</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Good fit</td>
</tr>
<tr>
<td align="left"></td>
<td align="left">CFI</td>
<td align="center">0.923</td>
<td align="center">&#x2265; 0.900</td>
<td align="left">Good fit</td>
</tr>
<tr>
<td align="left">Parsimony fit</td>
<td align="left">PGFI</td>
<td align="center">0.131</td>
<td align="center">&#x003E; 0.050</td>
<td align="left">Acceptable</td>
</tr>
<tr>
<td align="left">Error of approximation</td>
<td align="left">RMSEA</td>
<td align="center">0.006</td>
<td align="center">&#x2264; 0.080</td>
<td align="left">Excellent fit</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>AGAM, adaptive governance awareness model; CMIN, chi-square minimum discrepancy; <italic>df</italic>, degrees of freedom; RMR, root mean square residual; GFI, goodness of fit index; AGFI; adjusted goodness of fit index; NFI, norm fit index; IFI, incremental fit index; TLI, tucker-lewis index; CFI, comparative fit index; PGFI, parsimony goodness of fit index; RMSEA, root mean square error of approximation.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>Although the Chi-square minimum discrepancy divided by its degrees of freedom (CMIN/<italic>df</italic>) ratio exceeded commonly recommended thresholds, alternative and more robust indices indicated excellent model fit. The goodness of fit index (GFI = 0.983) and adjusted GFI (AGFI = 0.922) surpassed the recommended benchmark of 0.90, demonstrating strong absolute model fit. Incremental fit indices, including NFI (0.921), IFI (0.924), TLI (0.914) and CFI (0.923), also exceeded the 0.90 threshold, indicating that the proposed model substantially improves upon the null model.</p>
<p>Furthermore, error-based indices confirmed high model adequacy, with a root mean square residual (RMR) of 0.004 and a root mean square error of approximation (RMSEA) of 0.006, both well within acceptable limits. Taken together, these indicators provide strong evidence that the AGAM measurement model fits the observed data well and is appropriate for testing the hypothesised structural relationships.</p>
</sec>
<sec id="s20018">
<title>Path analysis</title>
<p>After confirming that the measurement constructs achieved an acceptable level of model fit, the next step involved conducting a path analysis using PLS-SEM to examine the relationships within the proposed model. The results, illustrated in <xref ref-type="fig" rid="F0002">Figure 2</xref>, show the strength and significance of each path coefficient, with significant relationships marked by green arrows (<italic>p</italic> &#x003C; 0.05).</p>
<p>The path analysis confirms that RA and CB play vital roles in cybersecurity management. Risk analysis enhances GP and TM, aligning with frameworks like NIST that highlight risk assessment as central to TM (Freund <xref ref-type="bibr" rid="CIT0018">2024</xref>; NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>; Rahman et al. <xref ref-type="bibr" rid="CIT0050">2024</xref>). Conversely, CB positively affects TM but negatively impacts GP, suggesting targeted approaches are required to integrate capacity-building efforts into strategic governance (Sava&#x015F; &#x0026; Karata&#x015F; <xref ref-type="bibr" rid="CIT0051">2022</xref>). These relationships support the literature emphasising adaptive cybersecurity strategies (ENISA <xref ref-type="bibr" rid="CIT0016">2020</xref>).</p>
</sec>
<sec id="s20019">
<title>Hypothesis testing</title>
<p><xref ref-type="table" rid="T0004">Table 4</xref> summarises the outcomes of the hypothesis tests obtained through path analysis. The path coefficients indicate both the magnitude and direction of the relationships between the constructs, whereas the <italic>p</italic>-values show their level of statistical significance, with values less than 0.05 considered statistically significant.</p>
<table-wrap id="T0004">
<label>TABLE 4</label>
<caption><p>Structural path estimates and hypothesis testing results.</p></caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th valign="top" align="left">Paths</th>
<th valign="top" align="center">Estimate</th>
<th valign="top" align="center">SE</th>
<th valign="top" align="center">CR</th>
<th valign="top" align="center"><italic>p</italic>-value</th>
<th valign="top" align="left">Hypothesis results</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">GP &#x003C;--- RA</td>
<td align="center">0.075</td>
<td align="center">0.013</td>
<td align="center">5.712</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">GP &#x003C;--- CB</td>
<td align="center">&#x2212;0.028</td>
<td align="center">0.006</td>
<td align="center">&#x2212;4.832</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">TM &#x003C;--- RA</td>
<td align="center">0.412</td>
<td align="center">0.048</td>
<td align="center">8.633</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">TM &#x003C;--- GP</td>
<td align="center">&#x2212;0.510</td>
<td align="center">0.105</td>
<td align="center">&#x2212;4.845</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">IRR &#x003C;--- RA</td>
<td align="center">0.498</td>
<td align="center">0.026</td>
<td align="center">19.259</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">IRR &#x003C;--- GP</td>
<td align="center">0.293</td>
<td align="center">0.057</td>
<td align="center">5.147</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">IRR &#x003C;--- CB</td>
<td align="center">&#x2212;0.032</td>
<td align="center">0.011</td>
<td align="center">&#x2212;2.829</td>
<td align="center">0.005</td>
<td align="left">Accept</td>
</tr>
<tr>
<td align="left">TM &#x003C;--- CB</td>
<td align="center">0.174</td>
<td align="center">0.021</td>
<td align="center">8.407</td>
<td align="center"><xref ref-type="table-fn" rid="TFN0001">&#x002A;</xref></td>
<td align="left">Accept</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn><p>Note: Standardised regression weights, critical ratios and <italic>p</italic>-values for hypothesised relationships among AGAM constructs.</p></fn>
<fn><p>SE, standard error; CR, critical ratio; GP, Governance planning; RA, risk analysis; IRR, incident response and recovery; CB, capacity building; TM, threat management.</p></fn>
<fn id="TFN0001"><label>&#x002A;</label><p>, <italic>p</italic> &#x003C; 0.001.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The results of the hypothesis testing, derived from path analysis, are presented in <xref ref-type="table" rid="T0004">Table 4</xref> and highlight the relationships between the constructs in the AGAM. Significant relationships were found across all paths, with estimates ranging from 0.075 to 0.498, all yielding <italic>p</italic>-values of &#x003C; 0.001, signifying strong evidence for the acceptance of the hypotheses. These significant relationships confirm the interconnections between the constructs of governance, risk management and incident recovery within the awareness model. The thresholds used for assessing these relationships &#x2013; such as standardised regression weights (CR values), with critical ratios (CR) exceeding 1.96 (Kline <xref ref-type="bibr" rid="CIT0029">2023</xref>) and <italic>p</italic>-values lower than 0.05 &#x2013; demonstrate the reliability and validity of the model constructs in predicting key cybersecurity outcomes (Hair et al. <xref ref-type="bibr" rid="CIT0024">2019</xref>). This solid empirical foundation supports the proposed model&#x2019;s capability to effectively guide cybersecurity training and awareness strategies.</p>
</sec>
<sec id="s20020">
<title>Final model</title>
<p><xref ref-type="fig" rid="F0003">Figure 3</xref> depicts the final representation of the AGAM.</p>
<fig id="F0003">
<label>FIGURE 3</label>
<caption><p>Final empirically supported adaptive governance awareness model. Final structural representation of adaptive governance awareness model following model testing and validation, highlighting significant interrelationships among governance, risk, capacity building, threat management and incident response.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="SAJIM-28-2166-g003.tif"/>
</fig>
</sec>
</sec>
<sec id="s0021">
<title>Discussion</title>
<p>This study developed and validated the AGAM by integrating constructs from the NIST CSF and the MediaPro adaptive awareness framework to explain cybersecurity awareness among MFSs users. The findings demonstrate that cybersecurity behaviour is shaped by the interdependence of governance, RA, CB and TM, extending prior research that often examines these elements in isolation (Bada et al. <xref ref-type="bibr" rid="CIT0008">2019</xref>; ENISA <xref ref-type="bibr" rid="CIT0016">2020</xref>).</p>
<p>Demographic factors significantly influenced user awareness. Younger users (18&#x2013;40 years) and those with higher educational attainment (Bachelor&#x2019;s or Master&#x2019;s degrees) reported higher competence in device protection and threat detection, while older users and those with minimal education exhibited lower confidence (Branley-Bell et al. <xref ref-type="bibr" rid="CIT0009">2022</xref>; Van Deursen &#x0026; Van Dijk <xref ref-type="bibr" rid="CIT0057">2014</xref>). These findings align with prior work linking digital literacy to age and education, highlighting the need for tailored awareness programmes that account for user characteristics in MFS contexts (GSMA <xref ref-type="bibr" rid="CIT0020">2022</xref>).</p>
<p>Path analysis confirms that RA positively influences GP, TM and IRR, corroborating the NIST emphasis on risk assessment as foundational to cybersecurity (NIST <xref ref-type="bibr" rid="CIT0041">2018</xref>). Conversely, CB positively affects TM but negatively impacts GP, suggesting that while training enhances user-level TM, it must be aligned with governance structures to optimise overall security (Puhakainen &#x0026; Siponen <xref ref-type="bibr" rid="CIT0049">2010</xref>; Sava&#x015F; &#x0026; Karata&#x015F; <xref ref-type="bibr" rid="CIT0051">2022</xref>). Governance planning also positively supports IRR but showed a negative effect on TM, indicating that rigid policies may limit adaptive user practices, a tension noted in cybersecurity governance research (Weber <xref ref-type="bibr" rid="CIT0064">2019</xref>).</p>
<p>The negative relationships observed between GP and TM and between CB and GP suggest potential tensions between formal governance structures and adaptive user practices. In highly dynamic MFS environments, rigid governance mechanisms may constrain flexible TM behaviours at the user level. Similarly, capacity-building initiatives that focus predominantly on individual skills may operate independently of formal governance processes, reducing their integration into strategic planning. This finding aligns with prior cybersecurity governance research, which highlights the risk of misalignment between policy-driven controls and adaptive security behaviour (Melaku <xref ref-type="bibr" rid="CIT0035">2023</xref>; Modi, Kuzminykh &#x0026; Ghita <xref ref-type="bibr" rid="CIT0036">2023</xref>; Puhakainen &#x0026; Siponen <xref ref-type="bibr" rid="CIT0049">2010</xref>; Vrhovec &#x0026; Markelj <xref ref-type="bibr" rid="CIT0061">2024</xref>; Weber <xref ref-type="bibr" rid="CIT0064">2019</xref>).</p>
<p>These findings underscore AGAM&#x2019;s theoretical contribution by bridging technical cybersecurity strategies with user-centric behavioural approaches, empirically demonstrating the interconnections between governance, risk and adaptive awareness. Unlike prior models focusing solely on either organisational controls or individual behaviour, AGAM captures their dynamic interplay, offering a holistic explanation of user cybersecurity behaviour in digital financial ecosystems (Bada et al. <xref ref-type="bibr" rid="CIT0008">2019</xref>; Hadlington <xref ref-type="bibr" rid="CIT0022">2017</xref>).</p>
<p>Practically, AGAM provides MFS providers with a framework to design targeted awareness and capacity-building initiatives, particularly for vulnerable demographics, while integrating these programmes within governance structures. Policymakers can adopt AGAM to inform regulations mandating adaptive cybersecurity training and digital literacy initiatives, supporting safe financial inclusion (ENISA <xref ref-type="bibr" rid="CIT0016">2020</xref>; World Bank <xref ref-type="bibr" rid="CIT0066">2021</xref>). Although tested in Kenya, the model&#x2019;s principles are replicable across diverse socio-economic contexts, providing a flexible foundation for global application.</p>
<p>In conclusion, AGAM advances both theory and practice by demonstrating that effective cybersecurity awareness emerges from the coordinated interaction of governance, RA, CB and adaptive user behaviour, rather than isolated interventions. This integrated perspective addresses critical gaps in existing frameworks and offers actionable guidance for MFS providers, policymakers and educational programmes worldwide.</p>
<sec id="s20022">
<title>Strength and limitations</title>
<p>This study&#x2019;s strengths include the integration of technical (NIST) and behavioural (MediaPro) constructs, combined with robust survey data from 1159 MFS users across diverse demographics and rigorous validation through reliability (Cronbach&#x2019;s alpha 0.711&#x2013;0.802), convergent and discriminant validity and CFA. Path analysis further demonstrated the interdependence of governance, RA, CB and TM. Limitations include the cross-sectional design, which limits causal inference, geographic focus on Kenya affecting generalisability, and reliance on self-reported measures, potentially introducing bias. Results should be interpreted considering these constraints, and longitudinal studies are recommended to strengthen causal and external validity.</p>
</sec>
<sec id="s20023">
<title>Recommendation for further research</title>
<p>Based on the study&#x2019;s findings, several recommendations emerge for future research, policy and practice. The significant effects of age and education on device protection and threat detection suggest that additional socio-economic variables &#x2013; such as income, employment type and digital access &#x2013; should be explored to understand their influence on cybersecurity awareness. Such insights would enable more targeted and inclusive interventions, ensuring that awareness programmes reach vulnerable users effectively. The observed lower confidence among older users highlights the need for age-specific training initiatives; future research should design and evaluate adaptive cybersecurity programmes that consider cognitive and behavioural differences, enhancing learning outcomes and threat response across age groups. Cultural factors also merit investigation, as societal norms, trust dynamics and local perceptions of security may shape behaviour; cross-cultural studies could refine AGAM&#x2019;s adaptability and inform globally relevant awareness strategies. Moreover, validating AGAM in diverse geographic and regulatory contexts would strengthen its generalisability, enabling policymakers and MFS providers to implement evidence-based, context-sensitive interventions that integrate governance, risk assessment and capacity-building efforts.</p>
<p>By linking interventions to demographic, cultural and contextual variables, future studies can ensure that cybersecurity awareness programmes are both effective and equitable, fostering sustained behavioural change.</p>
<p>Collectively, these research avenues will support the development of AGAM as a comprehensive, globally applicable tool for improving cybersecurity awareness and resilience among MFS users, guiding policy, and informing best practices in diverse socio-economic and technological environments.</p>
</sec>
</sec>
<sec id="s0024">
<title>Conclusion</title>
<p>This study developed the AGAM to enhance cybersecurity awareness among MFS users in Kenya, directly addressing the research question: How can NIST and MediaPro framework components be integrated to improve user cybersecurity awareness? The findings show that demographics, particularly age and education, influence cybersecurity behaviours, with younger and more educated users demonstrating higher competence in device protection and threat detection. This highlights the need for tailored, user-centric interventions, fulfilling the first objective.</p>
<p>Adaptive governance awareness model successfully integrates NIST&#x2019;s structured governance and risk management elements with MediaPro&#x2019;s adaptive awareness and capacity-building principles, achieving the second objective. Path analysis (<xref ref-type="table" rid="T0004">Table 4</xref>) confirmed that RA positively affects GP (<italic>&#x03B2;</italic> = 0.075), TM (<italic>&#x03B2;</italic> = 0.412) and IRR (<italic>&#x03B2;</italic> = 0.498), while CB enhances TM (<italic>&#x03B2;</italic> = 0.174) but negatively impacts GP (<italic>&#x03B2;</italic> = &#x2212;0.028). These results demonstrate that coordinated integration of structured controls with adaptive learning strengthens cybersecurity resilience, directly answering the research question.</p>
<p>Contextualised within Kenya, AGAM provides a holistic, empirically supported framework for guiding MFS providers, policymakers and educators. The model shows that aligning governance, RA, CB and adaptive user behaviour fosters proactive security practices, enhancing the safety and resilience of mobile financial ecosystems in Kenya and other developing economies.</p>
</sec>
</body>
<back>
<ack>
<title>Acknowledgements</title>
<p>This article is based on research originally conducted as part of Nicholas W. Omollo&#x2019;s doctoral thesis titled &#x2018;Information Security Education, Training, and Awareness within the Mobile Financial Services Sector&#x2019;, submitted to the Department of Mathematics, Statistics and Computer Science, College of Agriculture, Engineering and Science, University of KwaZulu-Natal in 2025. The thesis was supervised by Manoj Maharaj. The thesis was reworked, revised and adapted into a journal article for publication. The original thesis is available at: <ext-link ext-link-type="uri" xlink:href="https://hdl.handle.net/10413/23992">https://hdl.handle.net/10413/23992</ext-link>.</p>
<p>This article is based on data from a larger study. Two other articles were published from the same thesis. The first article focusing on &#x2018;Exploring Protective Behaviours Among Users of Mobile Financial Services&#x2019; has been published in the <italic>African Journal of Information Systems</italic> Vol 18. The second related article, focusing on Assessing Cybersecurity Threat Avoidance Factors Influencing User Attitudes in Mobile Financial Services in the Context of Kenya, has been published in IST-Africa 2025 Conference Proceedings and by IEEE.</p>
<sec id="s20025" sec-type="COI-statement">
<title>Competing interests</title>
<p>The authors declare that they have no financial or personal relationships that may have inappropriately influenced them in writing this article.</p>
</sec>
<sec id="s20026">
<title>CRediT authorship contribution</title>
<p>Nicholas W. Omollo: Writing &#x2013; original draft. Manoj Maharaj: Supervision, Writing &#x2013; review &#x0026; editing. All authors reviewed the article, contributed to the discussion of results, approved the final version for submission and publication and take responsibility for the integrity of its findings.</p>
</sec>
<sec id="s20027" sec-type="data-availability">
<title>Data availability</title>
<p>The data that support the findings of this study are not openly available because of (ethical restrictions and privacy concerns related to participant confidentiality) and are available from the corresponding author, Nicholas W. Omollo, upon reasonable request. The data is securely kept at the University of KwaZulu-Natal Research office.</p>
</sec>
<sec id="s20028">
<title>Disclaimer</title>
<p>The views and opinions expressed in this article are those of the authors and are the product of professional research. They do not necessarily reflect the official policy or position of any affiliated institution, funder, agency or that of the publisher. The authors are responsible for this article&#x2019;s results, findings and content.</p>
</sec>
</ack>
<ref-list id="references">
<title>Reference</title>
<ref id="CIT0001"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>8Pillars</collab></person-group>, <year>2018</year>, <source><italic>Helping customers solve the human side of security awareness</italic></source>, <comment>viewed 03 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.8pillars.com.au/products/mediapro/">https://www.8pillars.com.au/products/mediapro/</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0002"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abrahams</surname>, <given-names>T.O</given-names></string-name>., <string-name><surname>Farayola</surname>, <given-names>O.A</given-names></string-name>., <string-name><surname>Kaggwa</surname>, <given-names>S</given-names></string-name>., <string-name><surname>Uwaoma</surname>, <given-names>P.U</given-names></string-name>., <string-name><surname>Hassan</surname>, <given-names>A.O</given-names></string-name>. &#x0026; <string-name><surname>Dawodu</surname>, <given-names>S.O</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Cybersecurity awareness and education programs: A review of employee engagement and accountability</article-title>&#x2019;, <source><italic>Computer Science and IT Research Journal</italic></source> <volume>5</volume>(<issue>1</issue>), <fpage>100</fpage>&#x2013;<lpage>119</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.51594/csitrj.v5i1.708">https://doi.org/10.51594/csitrj.v5i1.708</ext-link></comment></mixed-citation></ref>
<ref id="CIT0003"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abrardi</surname>, <given-names>L</given-names></string-name>., <string-name><surname>Comino</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Grassini</surname>, <given-names>S</given-names></string-name></person-group>., <year>2025</year>, &#x2018;<article-title>The economics of cyber risk: A survey of the literature</article-title>&#x2019;, <source><italic>Journal of Industrial and Business Economics</italic></source> <volume>53</volume>, <fpage>1</fpage>&#x2013;<lpage>35</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s40812-025-00370-3">https://doi.org/10.1007/s40812-025-00370-3</ext-link></comment></mixed-citation></ref>
<ref id="CIT0004"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Adongo</surname>, <given-names>M</given-names></string-name></person-group>., <year>2025</year>, <source><italic>Mobile money social engineering attacks in African countries: A survey</italic></source>, <comment>SSRN Working Paper No. 5257020</comment>, <publisher-name>SSRN</publisher-name>, <publisher-loc>Rochester, NY</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0005"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahirrao</surname>, <given-names>K.B</given-names></string-name>. &#x0026; <string-name><surname>Jethani</surname>, <given-names>V</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>A security framework on SIM based authentication technique for mobile financial services</article-title>&#x2019;, <source><italic>International Journal of Engineering Research and Technology</italic></source> <volume>3</volume>(<issue>8</issue>), <comment>viewed 03 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.ijert.org/a-security-framework-on-sim-based-authentication-technique-for-mobile-financial-services">https://www.ijert.org/a-security-framework-on-sim-based-authentication-technique-for-mobile-financial-services</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0006"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al Doghan</surname>, <given-names>M.A</given-names></string-name>. &#x0026; <string-name><surname>Mirzaliev</surname>, <given-names>S</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Cybersecurity awareness and digital banking adoption: Exploring the moderating impact of digital literacy</article-title>&#x2019;, <source><italic>International Journal of Economics and Finance Studies</italic></source> <volume>16</volume>(<issue>3</issue>), <fpage>34</fpage>&#x2013;<lpage>58</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.34109/ijefs.202416303">https://doi.org/10.34109/ijefs.202416303</ext-link></comment></mixed-citation></ref>
<ref id="CIT0007"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Shanfari</surname>, <given-names>I</given-names></string-name>., <string-name><surname>Yassin</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Abdullah</surname>, <given-names>R</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Identify of factors affecting information security awareness and weight analysis process</article-title>&#x2019;, <source><italic>International Journal of Engineering and Advanced Technology</italic></source> <volume>9</volume>(<issue>3</issue>), <fpage>534</fpage>&#x2013;<lpage>542</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.35940/ijeat.C4775.029320">https://doi.org/10.35940/ijeat.C4775.029320</ext-link></comment></mixed-citation></ref>
<ref id="CIT0008"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bada</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Sasse</surname>, <given-names>A.M</given-names></string-name>. &#x0026; <string-name><surname>Nurse</surname>, <given-names>J.R.C</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Cyber security awareness campaigns: Why do they fail to change behaviour?</article-title>&#x2019;, <source><italic>arXiv preprint</italic></source>, <comment>arXiv:1901.02672. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.48550/arXiv.1901.02672">https://doi.org/10.48550/arXiv.1901.02672</ext-link></comment></mixed-citation></ref>
<ref id="CIT0009"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Branley-Bell</surname>, <given-names>D</given-names></string-name>., <string-name><surname>Coventry</surname>, <given-names>L</given-names></string-name>., <string-name><surname>Dixon</surname>, <given-names>M</given-names></string-name>., <string-name><surname>Joinson</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Briggs</surname>, <given-names>P</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>Exploring age and gender differences in ICT cybersecurity behaviour</article-title>&#x2019;, <source><italic>Human Behaviour and Emerging Technologies</italic></source> <volume>2022</volume>(<issue>1</issue>), <fpage>2693080</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1155/2022/2693080">https://doi.org/10.1155/2022/2693080</ext-link></comment></mixed-citation></ref>
<ref id="CIT0010"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Brecht</surname>, <given-names>D</given-names></string-name></person-group>., <year>2019</year>, <source><italic>The components of top security awareness programs</italic></source>, p. <fpage>15</fpage>, <publisher-name>InfoSec Institute</publisher-name>, <comment>viewed 24 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.infosecinstitute.com/resources/security-awareness/components-top-security-awareness-programs/">https://www.infosecinstitute.com/resources/security-awareness/components-top-security-awareness-programs/</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0011"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Chin</surname>, <given-names>W.W</given-names></string-name></person-group>., <year>2009</year>, &#x2018;<chapter-title>How to write up and report PLS analyses</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>V.E.</given-names> <surname>Vinzi</surname></string-name>, <string-name><given-names>W.W.</given-names> <surname>Chin</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Henseler</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Abdi</surname></string-name> &#x0026; <string-name><given-names>G.</given-names> <surname>Russolillo</surname></string-name></person-group> (eds.), <source><italic>Handbook of partial least squares</italic></source>, pp. <fpage>655</fpage>&#x2013;<lpage>690</lpage>, <publisher-name>Springer</publisher-name>, <publisher-loc>Berlin</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0012"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Communications Authority of Kenya</collab></person-group>, <year>2023</year>, &#x2018;<article-title>Cybersecurity report Q1 2023&#x2013;2024</article-title>&#x2019;, <comment>viewed 04 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.ca.go.ke/sites/default/files/2023-10/Cybersecurity&#x0025;20Report&#x0025;20Q1&#x0025;202023-2024.pdf">https://www.ca.go.ke/sites/default/files/2023-10/Cybersecurity&#x0025;20Report&#x0025;20Q1&#x0025;202023-2024.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0013"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Cochran</surname>, <given-names>W.G</given-names></string-name></person-group>., <year>1977</year>, <source><italic>Sampling techniques</italic></source>, <edition>3rd edn.</edition>, <publisher-name>John Wiley &#x0026; Sons</publisher-name>, <publisher-loc>New York</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0014"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dhillon</surname>, <given-names>G</given-names></string-name>. &#x0026; <string-name><surname>Backhouse</surname>, <given-names>J</given-names></string-name></person-group>., <year>2000</year>, &#x2018;<article-title>Information system security management in the new millennium</article-title>&#x2019;, <source><italic>Communications of the ACM</italic></source> <volume>43</volume>(<issue>7</issue>), <fpage>125</fpage>&#x2013;<lpage>128</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/341852.341877">https://doi.org/10.1145/341852.341877</ext-link></comment></mixed-citation></ref>
<ref id="CIT0015"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ebel</surname>, <given-names>A</given-names></string-name>. &#x0026; <string-name><surname>Mitra</surname>, <given-names>D</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Economics and optimal investment policies of attackers and defenders in cybersecurity</article-title>&#x2019;, <source><italic>Journal of Cybersecurity</italic></source> <volume>10</volume>(<issue>1</issue>), <fpage>tyae019</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1093/cybsec/tyae019">https://doi.org/10.1093/cybsec/tyae019</ext-link></comment></mixed-citation></ref>
<ref id="CIT0016"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>European Union Agency for Cybersecurity (ENISA)</collab></person-group>, <year>2020</year>, <source><italic>Threat landscape report</italic></source>, <comment>viewed 25 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape">https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0017"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fornell</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Larcker</surname>, <given-names>D.F</given-names></string-name></person-group>., <year>1981</year>, &#x2018;<article-title>Evaluating structural equation models with unobservable variables and measurement error</article-title>&#x2019;, <source><italic>Journal of Marketing Research</italic></source> <volume>18</volume>(<issue>1</issue>), <fpage>39</fpage>&#x2013;<lpage>50</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/002224378101800104">https://doi.org/10.1177/002224378101800104</ext-link></comment></mixed-citation></ref>
<ref id="CIT0018"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Freund</surname>, <given-names>J</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>From measurement to management: Integrating cyberrisk quantification into risk governance</article-title>&#x2019;, <source><italic>ISACA Journal</italic></source> <volume>5</volume>, <fpage>28</fpage>&#x2013;<lpage>36</lpage>, <comment>viewed 20 April 2026, from <ext-link ext-link-type="uri" xlink:href="https://www.researchgate.net/profile/Jack-Freund/publication/387540955_From_Measurement_to_Management_Integrating_Cyberrisk_Quantification_into_Risk_Governance/links/677360a3117f340ec3e89b97/From-Measurement-to-Management-Integrating-Cyberrisk-Quantification-into-Risk-Governance.pdf">https://www.researchgate.net/profile/Jack-Freund/publication/387540955_From_Measurement_to_Management_Integrating_Cyberrisk_Quantification_into_Risk_Governance/links/677360a3117f340ec3e89b97/From-Measurement-to-Management-Integrating-Cyberrisk-Quantification-into-Risk-Governance.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0019"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>GSMA</collab></person-group>, <year>2021</year>, <source><italic>Cybersecurity and mobile money: Prioritising consumer trust and awareness</italic></source>, <comment>viewed 20 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/topic/financial-inclusion/mobile-money-financial-inclusion/cybersecurity-and-mobile-money-prioritising-consumer-trust-and-awareness">https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/topic/financial-inclusion/mobile-money-financial-inclusion/cybersecurity-and-mobile-money-prioritising-consumer-trust-and-awareness</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0020"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>GSMA</collab></person-group>, <year>2022</year>, <source><italic>State of the industry report on mobile money 2022</italic></source>, <comment>viewed 21 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://media.gsma.com/assets/2022/annual_report.pdf">https://media.gsma.com/assets/2022/annual_report.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0021"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>GSMA</collab></person-group>, <year>2024</year>, <source><italic>Mobile money fraud typologies and mitigation strategies</italic></source>, <comment>viewed 21 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/gsma_resources/mobile-money-fraud-typologies-and-mitigation-strategies/">https://www.gsma.com/solutions-and-impact/connectivity-for-good/mobile-for-development/gsma_resources/mobile-money-fraud-typologies-and-mitigation-strategies/</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0022"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hadlington</surname>, <given-names>L</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>Human factors in cybersecurity; examining the link between Internet addiction, impulsivity, attitudes towards cybersecurity, and risky cybersecurity behaviours</article-title>&#x2019;, <source><italic>Heliyon</italic></source> <volume>3</volume>(<issue>7</issue>), <fpage>e00346</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.heliyon.2017.e00346">https://doi.org/10.1016/j.heliyon.2017.e00346</ext-link></comment></mixed-citation></ref>
<ref id="CIT0023"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hair</surname>, <given-names>J.F</given-names></string-name></person-group>., <year>2014</year>, <source><italic>A primer on partial least squares structural equation modelling (PLS-SEM)</italic></source>, <publisher-name>Sage</publisher-name>, <publisher-loc>Thousand Oaks, CA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0024"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hair</surname>, <given-names>J.F</given-names></string-name>., <string-name><surname>Black</surname>, <given-names>W.C</given-names></string-name>., <string-name><surname>Babin</surname>, <given-names>B.J</given-names></string-name>., <string-name><surname>Anderson</surname>, <given-names>R.E</given-names></string-name>. &#x0026; <string-name><surname>Tatham</surname>, <given-names>R.L</given-names></string-name></person-group>., <year>2019</year>, <source><italic>Multivariate data analysis</italic></source>, <edition>8th edn.</edition>, <publisher-name>Pearson</publisher-name>, <publisher-loc>Harlow</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0025"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>International Telecommunication Union</collab></person-group>, <year>2024</year>, <source><italic>Global cybersecurity index</italic></source>, <comment>viewed 20 April 2026, from <ext-link ext-link-type="uri" xlink:href="https://www.itu.int/en/ITU-D/Cybersecurity/pages/global-cybersecurity-index.aspx">https://www.itu.int/en/ITU-D/Cybersecurity/pages/global-cybersecurity-index.aspx</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0026"><mixed-citation publication-type="journal"><person-group person-group-type="author"><collab>ISO/IEC</collab></person-group>, <year>2023</year>, <source><italic>ISO/IEC 27035-1:2023 Information security incident management</italic></source>, <comment>viewed 21 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.iso.org/standard/78973.html#lifecycle">https://www.iso.org/standard/78973.html#lifecycle</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0027"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Iyelolu</surname>, <given-names>T.V</given-names></string-name>., <string-name><surname>Agu</surname>, <given-names>E.E</given-names></string-name>., <string-name><surname>Idemudia</surname>, <given-names>C</given-names></string-name>. &#x0026; <string-name><surname>Ijomah</surname>, <given-names>T.I</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Conceptualizing mobile banking and payment systems: Adoption trends and security considerations in Africa and the U.S</article-title>&#x2019;, <source><italic>International Journal of Science and Technology Research Archive</italic></source> <volume>7</volume>(<issue>1</issue>), <fpage>1</fpage>&#x2013;<lpage>9</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.53771/ijstra.2024.7.1.0052">https://doi.org/10.53771/ijstra.2024.7.1.0052</ext-link></comment></mixed-citation></ref>
<ref id="CIT0028"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Jack</surname>, <given-names>W</given-names></string-name>. &#x0026; <string-name><surname>Suri</surname>, <given-names>T</given-names></string-name></person-group>., <year>2011</year>, <source><italic>Mobile money: The economics of M-PESA</italic></source>, <comment>NBER Working Paper No. 16721</comment>, <publisher-name>National Bureau of Economic Research</publisher-name>, <publisher-loc>Cambridge, MA</publisher-loc>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3386/w16721">https://doi.org/10.3386/w16721</ext-link></comment></mixed-citation></ref>
<ref id="CIT0029"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Kline</surname>, <given-names>R.B</given-names></string-name></person-group>., <year>2023</year>, <source><italic>Principles and practice of structural equation modeling</italic></source>, <edition>5th edn.</edition>, <publisher-name>Guilford Press</publisher-name>, <publisher-loc>New York, NY</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0030"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kshetri</surname>, <given-names>N</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>Cybercrime and cybersecurity in Africa</article-title>&#x2019;, <source><italic>Journal of Global Information Technology Management</italic></source> <volume>22</volume>(<issue>2</issue>), <fpage>77</fpage>&#x2013;<lpage>81</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/1097198X.2019.1603527">https://doi.org/10.1080/1097198X.2019.1603527</ext-link></comment></mixed-citation></ref>
<ref id="CIT0031"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lamia</surname>, <given-names>I</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Digital illiteracy and the myth of digital natives: Unveiling realities and challenges</article-title>&#x2019;, <source><italic>JETT</italic></source> <volume>15</volume>(<issue>3</issue>), <fpage>263</fpage>&#x2013;<lpage>276</lpage>, <comment>viewed 05 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://dialnet.unirioja.es/descarga/articulo/9896011.pdf">https://dialnet.unirioja.es/descarga/articulo/9896011.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0032"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mater</surname>, <given-names>W</given-names></string-name>., <string-name><surname>Matar</surname>, <given-names>N</given-names></string-name>., <string-name><surname>Alismaiel</surname>, <given-names>O.A</given-names></string-name>., <string-name><surname>Al Moteri</surname>, <given-names>M.A</given-names></string-name>., <string-name><surname>Al Youssef</surname>, <given-names>I.Y</given-names></string-name>. &#x0026; <string-name><surname>Al-Rahmi</surname>, <given-names>W.M</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<article-title>Factors influencing the intention behind mobile wallet adoption: Perceptions of university students</article-title>&#x2019;, <source><italic>Entrepreneurship and Sustainability Issues</italic></source> <volume>9</volume>(<issue>1</issue>), <fpage>447</fpage>&#x2013;<lpage>460</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="http://doi.org/10.9770/jesi.2021.9.1(28)">http://doi.org/10.9770/jesi.2021.9.1(28)</ext-link></comment></mixed-citation></ref>
<ref id="CIT0033"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>MediaPro</collab></person-group>, <year>2018</year>, <source><italic>Adaptive awareness framework</italic></source>, <comment>viewed 25 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.knowbe4.com/products/security-awareness-training">https://www.knowbe4.com/products/security-awareness-training</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0034"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>MediaPro</collab></person-group>, <year>2019</year>, <source><italic>The MediaPro adaptive awareness framework: A model for cybersecurity training</italic></source>, <comment>viewed 25 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.8pillars.com.au/products/mediapro/">https://www.8pillars.com.au/products/mediapro/</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0035"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Melaku</surname>, <given-names>H.M</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>A dynamic and adaptive cybersecurity governance framework</article-title>&#x2019;, <source><italic>Journal of Cybersecurity and Privacy</italic></source> <volume>3</volume>(<issue>3</issue>), <fpage>327</fpage>&#x2013;<lpage>350</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/jcp3030017">https://doi.org/10.3390/jcp3030017</ext-link></comment></mixed-citation></ref>
<ref id="CIT0036"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Modi</surname>, <given-names>A</given-names></string-name>., <string-name><surname>Kuzminykh</surname>, <given-names>I</given-names></string-name>. &#x0026; <string-name><surname>Ghita</surname>, <given-names>B</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Data driven approaches to cybersecurity governance for board decision-making &#x2013; A systematic review</article-title>&#x2019;, <comment>arXiv preprint arXiv:2311.17578. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.48550/arXiv.2311.17578">https://doi.org/10.48550/arXiv.2311.17578</ext-link></comment></mixed-citation></ref>
<ref id="CIT0037"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Musyoka</surname>, <given-names>S.M</given-names></string-name>. &#x0026; <string-name><surname>Mose</surname>, <given-names>T</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Zero trust maturity model and cyber resilience in mobile money providers in Nairobi City County, Kenya</article-title>&#x2019;, <source><italic>International Journal of Social Sciences Management and Entrepreneurship</italic></source> <volume>8</volume>(<issue>3</issue>), <fpage>1037</fpage>&#x2013;<lpage>1051</lpage>, <comment>viewed 20 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.sagepublishers.com/index.php/ijssme/article/download/700/638">https://www.sagepublishers.com/index.php/ijssme/article/download/700/638</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0038"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mwangi</surname>, <given-names>K.K</given-names></string-name>. &#x0026; <string-name><surname>Kasamani</surname>, <given-names>B.S</given-names></string-name></person-group>., <year>2017</year>, &#x2018;<article-title>A universal mobile money transfer platform</article-title>&#x2019;, <source><italic>International Journal of Computer Applications</italic></source> <volume>175</volume>(<issue>6</issue>), <fpage>40</fpage>&#x2013;<lpage>47</lpage>, <comment>viewed 05 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.ijcaonline.org/archives/volume175/number6/mwangi-2017-ijca-915595.pdf">https://www.ijcaonline.org/archives/volume175/number6/mwangi-2017-ijca-915595.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0039"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nagyfejeo</surname>, <given-names>E</given-names></string-name>. &#x0026; <string-name><surname>Von Solms</surname>, <given-names>B</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Why do national cybersecurity awareness programmes often fail</article-title>&#x2019;, <source><italic>International Journal of Information Security and Cybercrime</italic></source> <volume>9</volume>(<issue>2</issue>), <fpage>18</fpage>&#x2013;<lpage>27</lpage>, <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.19107/IJISC.2020.02.03">https://doi.org/10.19107/IJISC.2020.02.03</ext-link></comment></mixed-citation></ref>
<ref id="CIT0040"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Naik</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Sneha</surname>, <given-names>N</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Implementation of techniques to avoid cyber attacks</article-title>&#x2019;, <source><italic>The Online Journal of Distance Education and e-Learning</italic></source> <volume>11</volume>(<issue>2</issue>), <fpage>1488</fpage>&#x2013;<lpage>1499</lpage>, <comment>viewed 20 October 2026, from <ext-link ext-link-type="uri" xlink:href="https://tojdel.net/journals/tojdel/articles/v11i02/v11i02-62.pdf">https://tojdel.net/journals/tojdel/articles/v11i02/v11i02-62.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0041"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>National Institute of Standards and Technology (NIST)</collab></person-group>, <year>2018</year>, <source><italic>Framework for improving critical infrastructure cybersecurity, version 1.1</italic></source>, <comment>viewed 05 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0042"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Ndung&#x2019;u</surname>, <given-names>N</given-names></string-name>. &#x0026; <string-name><surname>Oguso</surname>, <given-names>A</given-names></string-name></person-group>., <year>2021</year>, &#x2018;<chapter-title>Financial sector development and financial inclusion in Africa</chapter-title>&#x2019;, in <person-group person-group-type="editor"><string-name><given-names>A.H.</given-names> <surname>Ahmad</surname></string-name>, <string-name><given-names>D.T.</given-names> <surname>Llewellyn</surname></string-name> &#x0026; <string-name><given-names>V.</given-names> <surname>Murinde</surname></string-name></person-group> (eds.), <source><italic>Inclusive financial development</italic></source>, pp. <fpage>28</fpage>&#x2013;<lpage>51</lpage>, <publisher-name>Edward Elgar</publisher-name>, <publisher-loc>Cheltenham</publisher-loc>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4337/9781800376380.00008">https://doi.org/10.4337/9781800376380.00008</ext-link></comment></mixed-citation></ref>
<ref id="CIT0043"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ngugi</surname>, <given-names>J</given-names></string-name>., <string-name><surname>Mwangi</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Kamau</surname>, <given-names>P</given-names></string-name></person-group>., <year>2020</year>, &#x2018;<article-title>Mobile financial services and cybersecurity threats in Kenya</article-title>&#x2019;, <source><italic>International Journal of Cyber Studies</italic></source> <volume>5</volume>(<issue>2</issue>), <fpage>34</fpage>&#x2013;<lpage>50</lpage>.</mixed-citation></ref>
<ref id="CIT0044"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>NIST</collab></person-group>, <year>2021</year>, <source><italic>Building a cybersecurity and privacy awareness and training program</italic></source>, <comment>viewed 24 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://csrc.nist.gov/publications/detail/sp/800-50/rev-1/draft">https://csrc.nist.gov/publications/detail/sp/800-50/rev-1/draft</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0045"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>NIST</collab></person-group>, <year>2023</year>, <source><italic>NIST cybersecurity framework</italic></source>, <comment>viewed 13 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.nist.gov/cyberframework">https://www.nist.gov/cyberframework</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0046"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Odo</surname>, <given-names>C</given-names></string-name></person-group>., <year>2024</year>, <source><italic>Strengthening cybersecurity resilience</italic></source>, <comment>SSRN Working Paper</comment>, <publisher-name>Social Science Research Network (SSRN)</publisher-name>, <publisher-loc>Rochester, NY</publisher-loc>, <comment>viewed 20 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://dx.doi.org/10.2139/ssrn.4779289">https://dx.doi.org/10.2139/ssrn.4779289</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0047"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Osabutey</surname>, <given-names>E.L.C</given-names></string-name>. &#x0026; <string-name><surname>Jackson</surname>, <given-names>T</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Mobile money and financial inclusion in Africa: Emerging themes, challenges and policy implications</article-title>&#x2019;, <source><italic>Technological Forecasting and Social Change</italic></source> <volume>202</volume>, <fpage>123339</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.techfore.2024.123339">https://doi.org/10.1016/j.techfore.2024.123339</ext-link></comment></mixed-citation></ref>
<ref id="CIT0048"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Popoola</surname>, <given-names>O.A</given-names></string-name>., <string-name><surname>Akinsanya</surname>, <given-names>M.O</given-names></string-name>., <string-name><surname>Nzeako</surname>, <given-names>G</given-names></string-name>., <string-name><surname>Chukwurah</surname>, <given-names>E.G</given-names></string-name>. &#x0026; <string-name><surname>Okeke</surname>, <given-names>C.D</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Exploring theoretical constructs of cybersecurity awareness and training programs: Comparative analysis of African and U.S. Initiatives</article-title>&#x2019;, <source><italic>International Journal of Applied Research in Social Sciences</italic></source> <volume>6</volume>(<issue>5</issue>), <fpage>819</fpage>&#x2013;<lpage>827</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.51594/ijarss.v6i5.1104">https://doi.org/10.51594/ijarss.v6i5.1104</ext-link></comment></mixed-citation></ref>
<ref id="CIT0049"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Puhakainen</surname>, <given-names>P</given-names></string-name>. &#x0026; <string-name><surname>Siponen</surname>, <given-names>M</given-names></string-name></person-group>., <year>2010</year>, &#x2018;<article-title>Improving employees&#x2019; compliance through information systems security training: An action research study</article-title>&#x2019;, <source><italic>MIS Quarterly</italic></source> <volume>34</volume>(<issue>4</issue>), <fpage>757</fpage>&#x2013;<lpage>778</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2307/25750704">https://doi.org/10.2307/25750704</ext-link></comment></mixed-citation></ref>
<ref id="CIT0050"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rahman</surname>, <given-names>M.M</given-names></string-name>., <string-name><surname>Kshetri</surname>, <given-names>N</given-names></string-name>., <string-name><surname>Sayeed</surname>, <given-names>S.A</given-names></string-name>. &#x0026; <string-name><surname>Rana</surname>, <given-names>M.M</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title><italic>AssessITS</italic>: Integrating procedural guidelines and practical evaluation metrics for organizational IT and cybersecurity risk assessment</article-title>&#x2019;, <source><italic>Journal of Information Security</italic></source> <volume>15</volume>, <fpage>564</fpage>&#x2013;<lpage>588</lpage>.</mixed-citation></ref>
<ref id="CIT0051"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sava&#x015F;</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Karata&#x015F;</surname>, <given-names>S</given-names></string-name></person-group>., <year>2022</year>, &#x2018;<article-title>Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance</article-title>&#x2019;, <source><italic>International Cybersecurity Law Review</italic></source> <volume>3</volume>(<issue>1</issue>), <fpage>7</fpage>&#x2013;<lpage>34</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1365/s43439-021-00045-4">https://doi.org/10.1365/s43439-021-00045-4</ext-link></comment></mixed-citation></ref>
<ref id="CIT0052"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Schneider</surname>, <given-names>B</given-names></string-name>., <string-name><surname>Asprion</surname>, <given-names>P.M</given-names></string-name>., <string-name><surname>Androvicsova</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Azan</surname>, <given-names>W</given-names></string-name></person-group>., <year>2020</year>, <source><italic>A practical guideline for developing a managerial information security awareness program</italic></source>, <comment>viewed 05 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://scholar.archive.org/work/kctmudhaubdrfmrvcbmmybpp5m/access/wayback/https://aisel.aisnet.org/cgi/viewcontent.cgi?article=1256&#x0026;context=amcis2020">https://scholar.archive.org/work/kctmudhaubdrfmrvcbmmybpp5m/access/wayback/https://aisel.aisnet.org/cgi/viewcontent.cgi?article=1256&#x0026;context=amcis2020</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0053"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>Serianu</collab></person-group>, <year>2023</year>, <source><italic>Africa cybersecurity report 2023</italic></source>, <comment>viewed 30 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.serianu.com/downloads/KenyaCyberSecurityReport2023.pdf">https://www.serianu.com/downloads/KenyaCyberSecurityReport2023.pdf</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0054"><mixed-citation publication-type="confproc"><person-group person-group-type="author"><string-name><surname>Tobbin</surname>, <given-names>P</given-names></string-name></person-group>., <year>2011</year>, &#x2018;<article-title>Understanding Mobile Money Ecosystem: Roles, Structure and Strategies</article-title>&#x2019;, <conf-name>2011 10th International Conference on Mobile Business</conf-name>, <conf-loc>Como, Italy</conf-loc>, pp. <fpage>185</fpage>&#x2013;<lpage>194</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/ICMB.2011.19">https://doi.org/10.1109/ICMB.2011.19</ext-link></comment></mixed-citation></ref>
<ref id="CIT0055"><mixed-citation publication-type="web"><person-group person-group-type="author"><collab>TransUnion Africa</collab></person-group>, <year>2025</year>, &#x2018;<article-title>More than four-fifths of Kenyans said they were recently targeted with fraud</article-title>&#x2019;, <comment>17 June, viewed 25 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://www.transunionafrica.com/fraud-trends/reports/kenya-2024-h2-omnichannel-fraud-report">https://www.transunionafrica.com/fraud-trends/reports/kenya-2024-h2-omnichannel-fraud-report</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0056"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Trim</surname>, <given-names>P.R</given-names></string-name>. &#x0026; <string-name><surname>Lee</surname>, <given-names>Y.-I</given-names></string-name></person-group>., <year>2019</year>, &#x2018;<article-title>The role of B2B marketers in increasing cyber security awareness and influencing behavioural change</article-title>&#x2019;, <source><italic>Industrial Marketing Management</italic></source> <volume>83</volume>, <fpage>224</fpage>&#x2013;<lpage>238</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.indmarman.2019.04.003">https://doi.org/10.1016/j.indmarman.2019.04.003</ext-link></comment></mixed-citation></ref>
<ref id="CIT0057"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Van Deursen</surname>, <given-names>A.J</given-names></string-name>. &#x0026; <string-name><surname>Van Dijk</surname>, <given-names>J.A</given-names></string-name></person-group>., <year>2014</year>, &#x2018;<article-title>The digital divide shifts to differences in usage</article-title>&#x2019;, <source><italic>New Media and Society</italic></source> <volume>16</volume>(<issue>3</issue>), <fpage>507</fpage>&#x2013;<lpage>526</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1177/1461444813487959">https://doi.org/10.1177/1461444813487959</ext-link></comment></mixed-citation></ref>
<ref id="CIT0058"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Van Zanden</surname>, <given-names>J.L</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Examining the relationship of information and communication technology and financial access in Africa</article-title>&#x2019;, <source><italic>Journal of Business and Economic Options</italic></source> <volume>6</volume>(<issue>3</issue>), <fpage>26</fpage>&#x2013;<lpage>36</lpage>, <comment>viewed 20 July 2025, from <ext-link ext-link-type="uri" xlink:href="https://resdojournals.com/index.php/jbeo/article/view/242">https://resdojournals.com/index.php/jbeo/article/view/242</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0059"><mixed-citation publication-type="web"><person-group person-group-type="author"><string-name><surname>Vitus</surname>, <given-names>E.N</given-names></string-name></person-group>., <year>2023</year>, <source><italic>Cybercrime and online safety: Addressing the challenges and solutions related to cybercrime, online fraud, and ensuring a safe digital environment for all users &#x2013; A case of African States</italic></source>, <comment>viewed 20 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://philpapers.org/go.pl?id=VITCAO&#x0026;proxyId=none&#x0026;u=http&#x0025;3A&#x0025;2F&#x0025;2Fdx.doi.org&#x0025;2F10.6084&#x0025;2Fm9.figshare.24155610.v1">https://philpapers.org/go.pl?id=VITCAO&#x0026;proxyId=none&#x0026;u=http&#x0025;3A&#x0025;2F&#x0025;2Fdx.doi.org&#x0025;2F10.6084&#x0025;2Fm9.figshare.24155610.v1</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0060"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Von Solms</surname>, <given-names>R</given-names></string-name>. &#x0026; <string-name><surname>Van Niekerk</surname>, <given-names>J</given-names></string-name></person-group>., <year>2013</year>, &#x2018;<article-title>From information security to cyber security</article-title>&#x2019;, <source><italic>Computers &#x0026; Security</italic></source> <volume>38</volume>, <fpage>97</fpage>&#x2013;<lpage>102</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2013.04.004">https://doi.org/10.1016/j.cose.2013.04.004</ext-link></comment></mixed-citation></ref>
<ref id="CIT0061"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vrhovec</surname>, <given-names>S</given-names></string-name>. &#x0026; <string-name><surname>Markelj</surname>, <given-names>B</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>We need to aim at the top: Factors associated with cybersecurity awareness of cyber and information security decision-makers</article-title>&#x2019;, <source><italic>PLoS One</italic></source> <volume>19</volume>(<issue>10</issue>), <fpage>e0312266</fpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1371/journal.pone.0312266">https://doi.org/10.1371/journal.pone.0312266</ext-link></comment></mixed-citation></ref>
<ref id="CIT0062"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wainaina</surname>, <given-names>G.N</given-names></string-name>., <string-name><surname>Kiyeng</surname>, <given-names>D</given-names></string-name>. &#x0026; <string-name><surname>Masese</surname>, <given-names>N</given-names></string-name></person-group>., <year>2023</year>, &#x2018;<article-title>Enhancing security measures for mobile banking applications: A comprehensive analysis of threats, vulnerabilities, and countermeasures in Kenya banking industry</article-title>&#x2019;, <source><italic>International Journal of Computer Applications Technology and Research</italic></source> <volume>12</volume>(<issue>8</issue>), <fpage>99</fpage>&#x2013;<lpage>112</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.7753/IJCATR1208.1014">https://doi.org/10.7753/IJCATR1208.1014</ext-link></comment></mixed-citation></ref>
<ref id="CIT0063"><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wakoli</surname>, <given-names>L.W</given-names></string-name></person-group>., <year>2024</year>, &#x2018;<article-title>Factors That influence cybersecurity compliance behaviours by bank employees: A case of banks operating in Kenya</article-title>&#x2019;, <source><italic>International Journal of Scientific Research and Management</italic></source> <volume>12</volume>(<issue>12</issue>), <fpage>8037</fpage>&#x2013;<lpage>8046</lpage>. <comment><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.18535/ijsrm/v12i12.em02">https://doi.org/10.18535/ijsrm/v12i12.em02</ext-link></comment></mixed-citation></ref>
<ref id="CIT0064"><mixed-citation publication-type="confproc"><person-group person-group-type="author"><string-name><surname>Weber</surname>, <given-names>R.H</given-names></string-name></person-group>., <year>2019</year>, <conf-name>A new trade regime for digital assets, WTO Workshop</conf-name>, <conf-loc>London</conf-loc>.</mixed-citation></ref>
<ref id="CIT0065"><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Whitman</surname>, <given-names>M.E</given-names></string-name>. &#x0026; <string-name><surname>Mattord</surname>, <given-names>H.J</given-names></string-name></person-group>., <year>2004</year>, <source><italic>Principles of information security</italic></source>, <publisher-name>Thomson Course Technology</publisher-name>, <publisher-loc>Boston, MA</publisher-loc>.</mixed-citation></ref>
<ref id="CIT0066"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>World Bank</collab></person-group>, <year>2021</year>, <source><italic>Consumer risks in fintech</italic></source>, <publisher-name>World Bank</publisher-name>, <publisher-loc>Washington, DC</publisher-loc>, <comment>viewed 20 October 2025, from <ext-link ext-link-type="uri" xlink:href="https://hdl.handle.net/10986/35699">https://hdl.handle.net/10986/35699</ext-link></comment>.</mixed-citation></ref>
<ref id="CIT0067"><mixed-citation publication-type="book"><person-group person-group-type="author"><collab>World Bank</collab></person-group>, <year>2023</year>, <source><italic>Annual progress report FY23-24</italic></source>, <publisher-name>World Bank</publisher-name>, <publisher-loc>Washington, DC</publisher-loc>, <comment>viewed 20 April 2026, from <ext-link ext-link-type="uri" xlink:href="https://thedocs.worldbank.org/en/doc/ae07a1384f3e2b5242cbdd9f2d12bd4b-0060052024/original/CWPF-FY23-24-Annual-Report-11-4-2024.pdf">https://thedocs.worldbank.org/en/doc/ae07a1384f3e2b5242cbdd9f2d12bd4b-0060052024/original/CWPF-FY23-24-Annual-Report-11-4-2024.pdf</ext-link></comment>.</mixed-citation></ref>
</ref-list>
<fn-group>
<fn><p><bold>How to cite this article:</bold> Omollo, N.W. &#x0026; Maharaj, M., 2026, &#x2018;Adaptive governance awareness model for improving user security in mobile financial services&#x2019;, <italic>South African Journal of Information Management</italic> 28(1), a2166. <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4102/sajim.v28i1.2166">https://doi.org/10.4102/sajim.v28i1.2166</ext-link></p></fn>
</fn-group>
</back>
</article>