Gaps in cybersecurity policies and employee commitment leave organisations vulnerable, Kaspersky survey shows

 

JOHANNESBURG, South Africa, A recent Kaspersky (www.Kaspersky.co.za) survey undertaken in the Middle East, Turkiye and Africa (META) region entitled “Cybersecurity in the workplace: Employee knowledge and behaviour”, showed that 39% of professionals consider cybersecurity rules in their company to be excessive or not fully appropriate. In Kenya, this figure was 25% and in South Africa, 23%. Furthermore, the survey highlighted that 7% of respondents in the META region, 4% in Kenya and 10% in South Africa noted that their organisations do not have cybersecurity rules or that they are not aware of them. These results show a disconnect between corporate cybersecurity policies and employee commitment to these rules, underscoring the risks associated with shadow IT and unmanaged device usage in the workplace.

Shadow IT is defined as the use of unauthorised software, devices, or services without IT oversight, and it has evolved into a critical business risk. While often driven by employee productivity needs, it creates blind spots for IT departments. The rise of hybrid work environments, increased reliance on cloud-based tools and the spread of AI tools have accelerated this trend. Without robust cybersecurity management and oversight, organisations face heightened exposure to ransomware attacks, data leaks, and regulatory penalties.

19% of all survey respondents said there are no policies regarding the use of non-corporate devices in their company. 35% admitted that they can use their own devices to access business information, provided they have some type of cybersecurity protection, even consumer-grade software. On the positive side, 21% of all respondents said they can use their own device, but these must first pass more stringent corporate IT security checks; while 25% indicated that only devices provided by the IT function can be used for work purposes.

The situation is significantly better with permissions for employees to install software on corporate devices without IT department’s approval. 50% of all survey participants reported that only IT specialists in their company are allowed to install software, while in 31% of organisations only top management or designated users can do so. 11% of employees can install software that is approved by the IT team. However, 8% of respondents said that all users can install any software they need without IT agreement in their organisation.

At the same time 21% of professionals surveyed in the META region, 29% in Kenya and 17% in South Africa acknowledged that within the past year they installed software on their work devices without IT supervision. That highlights a persistent shadow IT challenge that continues to expose organisations to security vulnerabilities, compliance risks, and data breaches.

“Shadow IT is now a mainstream operational risk. When one in five employees installs software without IT oversight, it signals a policy gap. Many organisations already have security policies in place, but employee perception must also be considered. Organisations should move beyond restrictive controls and instead implement intelligent, user-centric cybersecurity strategies that combine strategies that integrate technology with employee awareness and responsible use,” said Toufic Derbass, Managing Director for the META region at Kaspersky.

To help organisations strengthen their defences, Kaspersky recommends the following:

  • Conduct a Shadow IT audit to identify all unauthorised software, cloud services, and personal devices accessing corporate data.
  • Implement robust monitoring and cybersecurity solutions, for example from the Kaspersky Next product line with EDR and XDR tiers, to gain visibility into unsanctioned app usage and device behaviour.
  • If employees are allowed to use personal devices, define clear minimum security requirements and enforce them through such solutions as mobile device management (MDM) or endpoint management tools.
  • Complement user-friendly cybersecurity policies for employees with trainings that demonstrates real-life risks and ways to avoid them. Solutions such as Kaspersky Automated Security Awareness Platform can help.

For employees Kaspersky experts advise:

  • Understand your company’s cybersecurity policies. If anything is unclear, ask for clarification.
  • Only use applications that have been approved by your IT department and request access to specific IT resources when needed.
  • Use only authorised devices for work. If personal devices are allowed, make sure they meet all required security standards and have appropriate cybersecurity solutions installed.
  • Store and share work files only through approved platforms.
- Advertisement -

Disclaimer: The above press release has been provided by APO Group. CXO Digital Pulse holds no responsibility for its content in any manner.
Reproduction or Copying in part or whole is not permitted unless approved by author.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch