Skip to content
Review Open access

A Risk-Based Framework for Assessing Cybersecurity Maturity Levels of Savings and Credit Cooperative Societies (SACCOS) in Tanzania

Sep 2026 · East African Journal of Information Technology · 0 citations

TL;DR

A context-specific Risk-Based Cybersecurity Maturity Assessment Framework for Tanzanian SACCOS is developed and evaluated, demonstrating the framework’s internal coherence, contextual fit, and practical utility for institutional self-assessment and risk-based supervision.

Abstract

Savings and Credit Cooperative Societies (SACCOS) are central to financial inclusion in Tanzania; however, their digital transformation has advanced faster than their cybersecurity capabilities. National instruments, including the Cybercrimes Act (CAP 443), the Government Cyber Security Strategy 2022–2027, and the TCDC Guidelines on Cybersecurity and Resilience of SACCOS, establish baseline obligations, but none provide a structured, risk-based mechanism for measuring cybersecurity maturity or tracking improvements over time. This study developed and evaluated a context-specific Risk-Based Cybersecurity Maturity Assessment Framework (RBCMAF) for Tanzanian SACCOS by adapting the NIST Cybersecurity Framework (CSF) 2.0 to local governance, regulatory, and resource conditions. A descriptive, analytical, cross-sectional, mixed-methods design guided by Design Science Research principles was used. The quantitative strand is explicitly positioned as an exploratory pilot baseline rather than a nationally representative survey, drawing on respondents from a small number of purposively selected, anonymised digitised SACCOS using a NIST CSF-aligned questionnaire scored across the six CSF functions. Qualitative data were generated through semi-structured interviews with ICT managers, one per SACCOS, and a structured review of regulatory and supervisory documents. The instrument showed very high internal consistency, which should be read with caution because such values may also indicate item redundancy. The baseline placed the sampled SACCOS at the Developing maturity level overall, with Identify and Protect emerging as the strongest functions, and Respond, Recover, and Detect as the weakest. Gap analysis against an optimised target level confirmed that the largest deficits lay in Respond, Recover, and Detect. A risk-weighted assessment similarly prioritised Respond, Recover, Detect, and Govern as the functions most in need of attention. The resulting RBCMAF comprises five integrated layers operationalised through a six-stage assessment process and six design principles. Evaluation through quantitative application, qualitative triangulation, and regulatory benchmarking demonstrates the framework’s internal coherence, contextual fit, and practical utility for institutional self-assessment and risk-based supervision.

Read PDF

Similar papers

Open access Sep 2026

A Multi-Stage Framework for Examining the Internal Activity and Refinement of the Cybersecurity Risk Mitigation System in Financial-Banking Environments

The rapid digitalization of financial banking services has increased the need for effective cybersecurity risk mitigation as institutions rely on interconnected digital infrastructures. Understanding how technological, organizational, and human-related factors interact is important for supporting cybersecurity planning...

Laurențiu-Constrantin Stama, R. Nechita, D. Deselnicu et al. · 0 citations
Open access Aug 2026

Cybersecurity risk governance and fraud management in invoice-tax data sharing for credit scoring: A tripartite framework for Vietnam

Purpose - Decree 70/2025 and Decree 94/2025 in Vietnam established a tripartite data pipeline that shares real-time e-invoices from the General Department of Taxation (GDT) to credit institutions for enterprise credit scoring. Prevailing Third-Party Risk Management (TPRM) frameworks, including DORA, NIST CSF 2.0, the F...

T. Truong, T. Vu, Van Phong Nguyen · 0 citations
Open access Sep 2026

The Cybersecurity Governance Gap in Ecuadorian SMEs: IT–Management Alignment, Decision Rights, and Incident-Response Accountability

Cybersecurity weaknesses in small and medium-sized enterprises (SMEs) are frequently attributed to limited budgets, inadequate training, and obsolete technology. This explanation is incomplete when employees responsible for cybersecurity recognize risks but lack the authority, executive access, and governance routines...

Franklin Orellana · 0 citations
Open access Sep 2026

Developing and evaluating a zero trust cyber risk governance maturity model for digital government platforms

This paper develops and evaluates a cyber risk engineering framework for multi-agency digital government platforms, employing a design science research (DSR) methodology to construct, operationalise, and preliminarily validate the Cyber Risk Governance Maturity Model (CRGMM) as a reusable computing artefact. Following...

A. Alenezi · 0 citations
Open access 2026

The impact of cybersecurity governance on reducing cloud accounting risks: A study of Saudi companies listed on the financial market

The rapid adoption of cloud computing has revolutionized the accounting and auditing sectors by offering unprecedented scalability and operational efficiency. In the context of Saudi Arabia's Vision 2030, the shift to cloud is a cornerstone of national digital transformation. Yet, this transition exposes sensitive fina...

A. Musa, Mahir Mohammed Sharif, M. Elnasry et al. · 0 citations
Open access Aug 2026

Integrating Accounting Governance, Cybersecurity Governance and Digital Trust for Digital Banking Risk Reduction in Jordanian Banks: A Conceptual Framework for Digital Banking Risk Governance

The paper presents a multi-layered conceptual model illustrating the role that cybersecurity governance plays in supporting both DT and OR, and ultimately reducing DBR, and provides value by integrating previously separate concepts into a cohesive conceptual architecture designed to facilitate understanding of factors...

B. Alrawashdeh · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.