Creating a Cybersecurity Culture Framework in Higher Education

Authors

  • Mafika Nkambule Tshwane University of Technology
  • Prof Joey Jansen van Vuurenj Tshwane University of Technology
  • Prof Louise Leenen University of the Western Cape

DOI:

https://doi.org/10.34190/iccws.20.1.3268

Keywords:

Cybersecurity Risk Management; Cybersecurity Frameworks; Modified General Morphological Analysis; Cybersecurity Strategies; Higher Education in Africa.

Abstract

The increasing cybersecurity threats to higher education institutions in Africa necessitate risk management frameworks that are resilient and sensitive to regional needs. This paper applies Modified General Morphological Analysis (MGMA) to identify essential elements for an adaptable cybersecurity framework, focusing on the African higher education context. African institutions face many challenges, like limited funding, underdeveloped digital infrastructures, and rising cyberattacks. Our proposed MGMA is a structured methodology to examine key cybersecurity dimensions: governance, policy, technical controls, capacity building, and resource allocation. This approach allows for assessing complex interrelations among these elements, aimed at practical solutions suitable for African institutions.   This study focuses on risk management approaches to address the specific vulnerabilities of African higher education institutions (HEIs), such as restricted budgets, inadequate cybersecurity teams, and increasing reliance on digital systems. The study promotes collaborative efforts by creating institutional networks, sharing resources, and enhancing cybersecurity expertise across Africa. The findings will guide decision-makers in aligning cybersecurity investments with strategic institutional goals, providing a framework for protecting critical educational assets, strengthening resilience, and advancing digital infrastructure development across African higher education.

Author Biographies

Mafika Nkambule, Tshwane University of Technology

Mafika William Nkambule is an experienced IT Executive with over 18 years in ICT strategy, governance, and cybersecurity. As Director of ICT Services at Tshwane University of Technology, he leads strategy, architecture, and cybersecurity operations. Mafika has served on various ICT committees, driving excellence and compliance in the field. With extensive experience in IT leadership  is researche focuses on cybersecurity governance

Prof Joey Jansen van Vuurenj, Tshwane University of Technology

Joey Jansen van Vuuren (PhD) is a Professor of Computer Science in the Faculty of ICT at Tshwane University of Technology.  She is the Vice Chair of IFIP Working Group 9.10 and a coordinator of SA for the BRICS University Integrated Thematic Group Computer Science and Information Security. Her research focuses on cybersecurity risk management. education, governance, policy and culture.  She is involved in cybersecurity research for the South African government, police, and defence. She has presented on numerous forums, such as national and international conferences, some of which she has been invited as the keynote speaker

Prof Louise Leenen, University of the Western Cape

Prof. L. Leenen is a professor of Computer Science at the University of the Western Cape.  She did extensive research in Cybersecurity during her time as a Principal Researcher in Cyber Defence at the Council for Scientific Industrial and Research. She is a member of the Centre for Artificial Intelligence Research. She previously was the Chair of the IFIP Working Group, WG9.10 on ICT in Peace and War. She has numerous publications in Artificial Intelligence Applications, Cybersecurity, Social Engineering, and Mathematical Modelling.

Downloads

Published

24-03-2025