People before Perimeters: Employee Awareness as the Primary Driver of Zero-Trust Architecture Adoption in Banking

Authors

  • Deogratius Mathew Lashayo The Institute of Finance Management (IFM)

DOI:

https://doi.org/10.62177/apemr.v3i5.1638

Keywords:

Zero-Trust Architecture (ZTA), Technology-Organization-Environment (TOE) Framework, Employee Awareness, Cybersecurity Adoption, Financial Institutions, Tanzania

Abstract

Financial institutions face increasing exposure to sophisticated cyber threats, prompting a shift from traditional perimeter-based security toward Zero-Trust Architecture (ZTA), a model built on continuous verification and least-privilege access. Despite growing global adoption, empirical evidence on the determinants of ZTA adoption within African, and more specifically Tanzanian, banking institutions remains scarce. This study examines the factors influencing ZTA adoption at NMB Bank PLC, Tanzania, using an extended Technology–Organization–Environment (TOE) framework augmented with an employee awareness construct. A quantitative, cross-sectional research design was employed, with data collected from 114 respondents and analyzed using multiple regression. Results indicate that technological readiness (β = .224, p = .021) and employee awareness (β = .673, p < .001) significantly and positively influenced ZTA adoption, with awareness emerging as the strongest predictor overall. Organizational factors (β = -.136, p = .343) and environmental/regulatory factors (β = -.009, p = .964) did not show statistically significant effects. These findings suggest that ZTA adoption in this context is currently driven more by human-capital readiness than by institutional or regulatory pressure, extending the TOE framework's applicability while highlighting its limitations for security technologies whose effectiveness depends on continuous human behaviour. The study offers empirical grounding for prioritizing awareness-building initiatives alongside technological investment in similarly positioned financial institutions, and contributes one of the first empirical assessments of ZTA adoption determinants within a Tanzanian banking context.

Downloads

Download data is not yet available.

References

ORDR. (2026). Zero trust statistics 2026 report. https://ordr.net/blog/zero-trust-statistics-2026-report

National Institute of Standards and Technology. (2020). Zero trust architecture (NIST Special Publication 800-207). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207 DOI: https://doi.org/10.6028/NIST.SP.800-207

Okta, Inc. (2026). State of zero trust security report. As cited in Swif (2026), Zero trust statistics for 2026: Adoption, ROI, federal mandates, and what comes next. https://www.swif.ai/blog/zero-trust-statistics

BobsGuide. (2025). Implementing zero trust security frameworks in banking. https://www.bobsguide.com/implementing-zero-trust-security-frameworks-in-banking/

IBM Security. (2025). Cost of a data breach report 2025. IBM Corporation.

BlueRadius. (2026). Zero trust implementation strategies. https://blueradius.io/zero-trust-implementation-strategies

DataM Intelligence. (2026). Zero trust security market size, share, trends & forecast (2026–2035). https://www.datamintelligence.com/research-report/zero-trust-security-market

Tornatzky, L. G., & Fleischer, M. (1990). The processes of technological innovation. Lexington Books.

Deng, Y., & Inthiran, A. (2025). Towards zero trust architecture: A pilot study on information systems security readiness amongst small and medium enterprises [Completed research paper]. University of Canterbury, Department of Accounting and Information Systems.

Mwemezi, J., & Mandari, H. (2024). Big data analytics usage in the banking industry in Tanzania: Does perceived risk play a moderating role on the technological factors? Journal of Electronic Business & Digital Economics, 3(3), 318–340. https://doi.org/10.1108/JEBDE-01-2024-0001 DOI: https://doi.org/10.1108/JEBDE-01-2024-0001

Kiyanga, D. S. (2024). Factors influencing the adoption of cloud computing technology in the Tanzanian banking industry: A multifaceted analysis. The Journal of Informatics, 4(1). Institute of Accountancy Arusha.

Nguyen, T. H., Le, X. C., & Vu, T. H. L. (2022). An extended technology-organization-environment (TOE) framework for online retailing utilization in digital transformation: Empirical evidence from Vietnam. Journal of Open Innovation: Technology, Market, and Complexity, 8(4), Article 200. https://doi.org/10.3390/joitmc8040200 DOI: https://doi.org/10.3390/joitmc8040200

Pigola, A., & Meirelles, F. de S. (2025). Zero trust in practice: A mixed-methods study under the TOE framework. Journal of Cybersecurity and Privacy, 5(4), Article 99. https://doi.org/10.3390/jcp5040099 DOI: https://doi.org/10.3390/jcp5040099

Lyimo, B. J., & Shaaban, S. Y. (2021). Cybersecurity awareness among employees in banking industry in Tanzania: A case of National Microfinance Bank – Magomeni Branch. Olva Academy – School of Researchers, 3(1), 1–4.

Yamane, T. (1967). Statistics: An introductory analysis (2nd ed.). Harper and Row.

Downloads

How to Cite

Lashayo, D. M. (2026). People before Perimeters: Employee Awareness as the Primary Driver of Zero-Trust Architecture Adoption in Banking. Asia Pacific Economic and Management Review, 3(5). https://doi.org/10.62177/apemr.v3i5.1638

Issue

Section

Articles

DATE

Received: 2026-08-12
Accepted: 2026-08-21
Published: 2026-09-03