Project – Cybersecurity Awareness and Phishing Susceptibility among Employees of Financial Institutions: A Study of Selected Banks in Abuja
CHAPTER ONE
INTRODUCTION
1.1 Background to the Study
The increasing digitalisation of business operations has made cybersecurity a critical component of organisational management, particularly in the financial sector. Banks depend extensively on information and communication technologies for electronic payments, online banking, customer relationship management, interbank transactions, internal communication, data storage and financial reporting. This growing dependence has also expanded the potential attack surface available to cybercriminals. The Central Bank of Nigeria (CBN) recognised this development in its Risk-Based Cybersecurity Framework for Deposit Money Banks and Payment Service Banks, noting that the increasing use of emerging technologies by financial institutions has increased their exposure to cyber threats. The framework therefore requires supervised financial institutions to establish appropriate cybersecurity programmes and controls to strengthen their resilience (Central Bank of Nigeria [CBN], 2024).
Cybersecurity, however, is not solely a technological issue because employees interact directly with the systems, applications, emails and information assets that organisations seek to protect. Cybersecurity awareness refers broadly to employees’ knowledge and understanding of cyber threats, organisational security policies, safe computing practices and appropriate responses to security incidents. Effective awareness should go beyond employees merely completing mandatory training; it should translate into secure behaviour when employees encounter actual threats. Haney and Lutters (2020) argued that security awareness training needs to move beyond “check-the-box” compliance and focus on behavioural change. Similarly, NIST’s more recent guidance emphasises that organisational cybersecurity and privacy learning programmes should promote behaviour change and the development of a security and privacy culture rather than focusing exclusively on training completion (Merritt et al., 2024).
Among the different forms of cyber threats confronting organisations, phishing remains particularly significant because it exploits human interaction rather than relying exclusively on technical vulnerabilities. Phishing involves fraudulent electronic communications designed to deceive recipients into disclosing information, clicking malicious links, downloading harmful attachments or performing other actions that benefit attackers. In the workplace, phishing can provide attackers with an entry point into organisational systems and sensitive information. Williams, Hinds, and Joinson (2018) found that employees remained susceptible to targeted phishing emails even where organisations had awareness campaigns and simulated phishing exercises. Their study further showed that authority and urgency cues could increase the likelihood that employees would interact with suspicious messages.
Phishing susceptibility is therefore an important behavioural dimension of cybersecurity because an employee may possess general knowledge of cybersecurity without necessarily applying that knowledge correctly when confronted with a convincing fraudulent message. NIST’s research on phishing awareness has demonstrated that user context is important in understanding why individuals click on phishing messages. Dawkins and Jacobs (2022, 2023) explain that organisations should examine the human element underlying phishing responses rather than relying exclusively on aggregate click rates to judge the effectiveness of awareness programmes. This perspective suggests that cybersecurity awareness should be examined in relation to actual or likely employee behaviour, including the ability to identify suspicious messages, verify senders, recognise malicious links and attachments, report suspected phishing attempts and avoid disclosing confidential information.
The relationship between cybersecurity awareness and phishing susceptibility has become especially important in financial institutions because banks process highly sensitive information and facilitate transactions involving customers, businesses and other institutions. A successful phishing attack against a bank employee may potentially expose credentials, customer information, internal systems or financial processes. Recent research involving bank employees in a developing-country context found that knowledge of cyber threats, information-security awareness, perceived threat and perceived vulnerability are important factors associated with cybersecurity awareness among bank employees (Al-Kumaim et al., 2025). The study reinforces the importance of strengthening employee awareness as part of broader cybersecurity protection in financial institutions.
The Nigerian banking environment makes this issue particularly relevant because the country’s financial system has become increasingly dependent on digital channels and technology-enabled services. In response to increasing cybersecurity threats, the CBN has established a risk-based cybersecurity framework for deposit money banks and payment service banks covering areas such as cybersecurity governance, risk management, cyber resilience, emerging technologies, monitoring, reporting and regulatory compliance (CBN, 2024). The regulatory emphasis demonstrates that cybersecurity is regarded as an institutional risk rather than merely an information-technology concern. In addition, the CBN’s 2026 deployment of a Cybersecurity Self-Assessment Tool to banks and other regulated financial institutions further illustrates the continuing supervisory attention being given to the cybersecurity posture of the financial sector (CBN, 2026).
Despite technological controls and regulatory requirements, the human element continues to represent an important component of organisational cyber risk. Recent evidence from financial-sector employees demonstrates that phishing susceptibility can vary according to individual and organisational characteristics. Öner, Çetin, and Savaş (2025), using data from 8,102 employees in a large financial organisation and 24 phishing simulation campaigns, found significant differences in phishing susceptibility and reporting behaviour across demographic and organisational groups. Their findings highlight the importance of targeted anti-phishing training and an organisational culture that encourages employees to report suspicious communications. Similarly, a 2026 systematic literature review of 54 studies concluded that phishing susceptibility is influenced by a combination of individual and environmental factors, demonstrating that employee behaviour cannot be understood solely through technical controls (Öner et al., 2025; What makes people susceptible to phishing attacks, 2026).
The Nigerian context is beginning to generate more empirical evidence concerning the relationship between cybersecurity awareness and phishing behaviour. For example, Garba and Otor (2026) investigated cybersecurity awareness training and phishing susceptibility among employees of selected banks in Benue State, Nigeria. Their study focused on employees of Union Bank, Ecobank and Zenith Bank and examined factors associated with employees’ susceptibility to phishing attacks. The emergence of such research demonstrates that employee-focused cybersecurity is becoming an important area of investigation in Nigerian banking. However, findings from Benue State cannot automatically be generalised to employees of banks operating in Abuja, where the financial sector, regulatory institutions and business environment present a different organisational and operational context (Garba & Otor, 2026).
Abuja provides an important setting for examining cybersecurity awareness and phishing susceptibility because it is Nigeria’s Federal Capital Territory and hosts numerous financial institutions, government agencies, corporate organisations and technology-dependent businesses. Employees working in bank branches, administrative offices, customer-service units, operations, information technology, finance and other departments routinely interact with digital systems and electronic communication. The effectiveness of technical cybersecurity measures may therefore depend partly on how employees recognise and respond to suspicious communications. Research on phishing susceptibility has shown that social, task and physical contexts can influence employee responses to phishing attempts, suggesting that susceptibility is shaped not only by what employees know but also by the circumstances under which suspicious messages are encountered (Frank et al., 2022).
Consequently, it is important to investigate cybersecurity awareness and phishing susceptibility together rather than treating them as completely separate organisational issues. Awareness provides employees with knowledge and understanding of cyber risks, while susceptibility reflects how employees may actually respond when confronted with deceptive cyber threats. Research conducted in a large financial institution found that employee responses to simulated phishing emails were influenced by factors including attention to sender information, intuition, message type and elaborative processing (Buckley et al., 2023). These findings suggest that effective cybersecurity programmes should develop practical decision-making skills rather than merely provide employees with general information about cyber threats.
Therefore, this study focuses on Cybersecurity Awareness and Phishing Susceptibility among Employees of Financial Institutions: A Study of Selected Banks in Abuja. The study seeks to examine the level of cybersecurity awareness among employees, assess their susceptibility to phishing techniques, determine whether awareness is associated with reduced susceptibility, and identify factors that may influence employees’ responses to phishing attempts. The study is expected to contribute context-specific evidence that can assist selected banks in strengthening employee awareness programmes, phishing simulations, incident-reporting practices and broader cybersecurity culture. This focus is consistent with the CBN’s continuing emphasis on cybersecurity resilience and the growing research recognition that employees constitute an important component of organisational cyber defence (CBN, 2024; Haney & Lutters, 2020).
1.2 Statement of the Problem
The rapid digital transformation of banking has created substantial benefits in terms of speed, convenience, accessibility and efficiency, but it has also increased banks’ exposure to cyber threats. Financial institutions increasingly depend on interconnected digital platforms and electronic communication systems, thereby creating more opportunities for cybercriminals to exploit weaknesses in organisational systems and human behaviour. The CBN has responded to these risks by establishing risk-based cybersecurity requirements for banks and payment service institutions. However, the existence of regulatory frameworks and technological safeguards does not eliminate risks arising from employees’ interactions with malicious communications (CBN, 2024).
A major concern is that employees may possess basic cybersecurity knowledge but still be susceptible to sophisticated phishing attempts. Phishing messages can be designed to imitate trusted organisations, supervisors, colleagues, service providers or financial institutions and may employ urgency, authority, fear or personalised information to influence recipients. Williams et al. (2018) demonstrated that authority cues could increase employees’ likelihood of clicking suspicious links, while Buckley et al. (2023) showed that message type and information-processing behaviour could influence employees’ phishing responses. Thus, the possession of general cybersecurity knowledge may not necessarily guarantee safe behaviour when employees encounter persuasive or realistic phishing messages.
Another problem concerns the effectiveness of cybersecurity awareness programmes. Organisations may conduct periodic awareness training, circulate security guidelines and require employees to complete cybersecurity courses, yet such activities may not necessarily result in sustained behavioural change. Haney and Lutters (2020) cautioned that security awareness programmes should move beyond compliance-based training and focus on measurable changes in employee behaviour. NIST has similarly emphasised the importance of evaluating awareness programmes through meaningful behavioural outcomes and understanding the human factors that contribute to phishing susceptibility (Dawkins & Jacobs, 2023; Merritt et al., 2024). Consequently, there is a need to determine whether employees of selected banks in Abuja possess sufficient cybersecurity awareness to recognise and appropriately respond to phishing threats.
Although studies have examined phishing susceptibility and cybersecurity awareness in different organisational and national contexts, there remains a need for more context-specific evidence concerning employees of financial institutions in Abuja. Nigerian research has begun to examine cybersecurity training and phishing susceptibility among bank employees in other locations, such as Benue State, while international studies have demonstrated that awareness, contextual conditions, demographic characteristics and organisational factors can influence phishing behaviour (Garba & Otor, 2026; Frank et al., 2022; Öner et al., 2025). However, evidence specifically examining the relationship between cybersecurity awareness and phishing susceptibility among employees of selected banks in Abuja remains limited. This gap provides the basis for the present study, which seeks to determine whether higher cybersecurity awareness is associated with lower susceptibility to phishing among employees of selected banks in Abuja.
1.3 Purpose of the Study
The main purpose of this study is to examine cybersecurity awareness and phishing susceptibility among employees of selected banks in Abuja.
Specifically, the study seeks to:
- determine the level of cybersecurity awareness among employees of selected banks in Abuja;
- assess the level of phishing susceptibility among employees of selected banks in Abuja;
- examine employees’ ability to identify common phishing indicators;
- determine employees’ knowledge of appropriate responses to suspected phishing attempts
1.4 Research Questions
The following research questions will guide the study:
- What is the level of cybersecurity awareness among employees of selected banks in Abuja?
- What is the level of phishing susceptibility among employees of selected banks in Abuja?
- To what extent can employees of selected banks identify common phishing indicators?
- What is the level of employees’ knowledge of appropriate responses to suspected phishing attempts?
1.5 Research Hypothesis
The following null hypothesis will be tested at the 0.05 level of significance:
H₀: There is no significant relationship between cybersecurity awareness and phishing susceptibility among employees of selected banks in Abuja.
1.6 Significance of the Study
The study will be significant to bank management because it will provide empirical information on the level of cybersecurity awareness among employees and the extent to which employees may be susceptible to phishing attacks. The findings may assist management in identifying weaknesses in existing awareness programmes and developing more targeted interventions. This is important because contemporary cybersecurity programmes are increasingly expected to produce behavioural change rather than simply document training completion (Haney & Lutters, 2020; Merritt et al., 2024).
The study will also be useful to employees of financial institutions. It may increase awareness of the techniques used by attackers and encourage safer responses to suspicious emails, messages, links and attachments. Evidence from phishing research indicates that authority, urgency, message type and contextual factors can influence employees’ decisions when confronted with potentially malicious communications (Williams et al., 2018; Frank et al., 2022).
The findings will be relevant to cybersecurity professionals and information technology departments within banks. The study may help cybersecurity teams identify areas requiring additional training, phishing simulations, behavioural monitoring and incident-reporting interventions. This is particularly important because research involving financial-sector employees has shown that susceptibility and reporting behaviour can differ across organisational and demographic groups, supporting the need for targeted rather than entirely uniform awareness interventions (Öner et al., 2025).
The study will also be beneficial to regulators and policymakers, particularly institutions concerned with the safety and resilience of Nigeria’s financial system. The CBN’s cybersecurity framework places cybersecurity governance, risk management, resilience and monitoring at the centre of the protection of supervised financial institutions (CBN, 2024). Empirical evidence on employee awareness and phishing susceptibility may provide additional insight into the human dimension of cybersecurity risk management within banks.
Finally, the study will contribute to academic knowledge by providing empirical evidence on cybersecurity awareness and phishing susceptibility within the Nigerian banking environment. It may serve as a reference for future researchers investigating cybersecurity culture, human cyber risk, social engineering, phishing, information-security behaviour and employee cyber awareness in Nigeria and other developing economies.
1.7 Scope of the Study
The study focuses on cybersecurity awareness and phishing susceptibility among employees of selected banks in Abuja.
The geographical scope is limited to selected banks operating within Abuja, Federal Capital Territory, Nigeria.
The content scope covers employees’ knowledge and understanding of cybersecurity threats, awareness of organisational security practices, recognition of phishing indicators, safe email and internet practices, password and authentication awareness, reporting of suspicious activities and responses to phishing attempts. Phishing susceptibility will focus on employees’ likelihood of interacting with deceptive emails or messages, clicking suspicious links, opening questionable attachments, providing confidential information or failing to report suspected phishing attempts.
The population scope will comprise employees of the selected banks who use organisational digital systems, email, internet-based applications or other electronic communication platforms in the performance of their duties.
1.8 Operational Definition of Terms
Cybersecurity: The practices, processes, technologies and controls used to protect computer systems, networks, applications and information from unauthorised access, disruption, misuse, alteration or destruction.
Cybersecurity Awareness: The level of employees’ knowledge, understanding and recognition of cybersecurity threats and their ability to apply appropriate security practices in the workplace.
Cybersecurity Awareness Training: Organised educational activities designed to improve employees’ knowledge, attitudes and behaviours concerning cybersecurity risks and protective measures.
Phishing: A form of social engineering in which attackers use deceptive electronic communications to persuade individuals to disclose information, click malicious links, open harmful attachments or perform other actions that compromise security.
Phishing Susceptibility: The likelihood that an employee will respond in an unsafe manner to a phishing attempt, such as clicking a malicious link, opening a suspicious attachment, providing confidential information or failing to report the attempt.
Employee: A person formally engaged by a bank to perform assigned organisational duties, whether in an operational, administrative, technical, managerial or customer-facing capacity.
Financial Institution: An organisation involved in financial services and regulated financial activities. In this study, the term primarily refers to selected commercial/deposit money banks.
Bank Employee: An individual employed by a selected bank who has access to organisational information systems, electronic communication platforms or other digital resources.
Phishing Indicator: A characteristic that may signal that an electronic communication is fraudulent, including suspicious sender addresses, unusual requests, urgency, unfamiliar links, unexpected attachments, spelling anomalies or requests for confidential information.
Cybersecurity Culture: The shared values, attitudes, expectations and behaviours within an organisation concerning the protection of information and digital resources.
Security Awareness Programme: A structured organisational programme designed to educate employees and influence their cybersecurity-related attitudes and behaviours.
Social Engineering: The manipulation of individuals into performing actions or disclosing information that compromises security.
Project – Cybersecurity Awareness and Phishing Susceptibility among Employees of Financial Institutions: A Study of Selected Banks in Abuja
Frequently Asked Questions
Our Customers are Happy
Ademola A.
I was skeptical at first, but after placing my order, my full project arrived in my email in under 15 minutes! The process was smooth, clear, and professional. Truly amazing service!
Kwabena K.
I needed a custom project on a new topic. Https://azresearchconsult.com.ng delivered within 3 days, and the quality was outstanding. They even guided me on how to defend it. Highly recommend!
Michael H.
Fast, reliable, and very professional. My research project was delivered on time, with no hidden charges. The team is trustworthy and supportive.
Fatou B.
I got my full project in minutes and my custom request within 3 days. Their communication is clear, and the material is top-notch. Excellent experience!
James O.
https://azresearchconsult.com.ng is a lifesaver! My project was delivered exactly as requested. The team is friendly, professional, and highly responsive. Very satisfied!
Ngozi E.
I was worried about paying online, but the team reassured me and delivered my complete project instantly. Transparent and professional service!
Ama S.
I requested a custom topic project and received it in just 3 days. The guidance and quality were excellent. I recommend azresearchconsult.com.ng to everyone!
Sarah W.
The service is dependable and efficient. My project arrived on time, and every step was transparent. Truly a professional service I trust.
Emmanuel T.
Fast and reliable. My full project was delivered in minutes, and the custom project in 3 days. Communication was excellent throughout.
Aisha N.
Extremely satisfied with the service. My project was delivered promptly, fully transparent, and of high quality. A trustworthy academic partner!
