People before Perimeters: Employee Awareness as the Primary Driver of Zero-Trust Architecture Adoption in Banking
DOI:
https://doi.org/10.62177/apemr.v3i5.1638Keywords:
Zero-Trust Architecture (ZTA), Technology-Organization-Environment (TOE) Framework, Employee Awareness, Cybersecurity Adoption, Financial Institutions, TanzaniaAbstract
Financial institutions face increasing exposure to sophisticated cyber threats, prompting a shift from traditional perimeter-based security toward Zero-Trust Architecture (ZTA), a model built on continuous verification and least-privilege access. Despite growing global adoption, empirical evidence on the determinants of ZTA adoption within African, and more specifically Tanzanian, banking institutions remains scarce. This study examines the factors influencing ZTA adoption at NMB Bank PLC, Tanzania, using an extended Technology–Organization–Environment (TOE) framework augmented with an employee awareness construct. A quantitative, cross-sectional research design was employed, with data collected from 114 respondents and analyzed using multiple regression. Results indicate that technological readiness (β = .224, p = .021) and employee awareness (β = .673, p < .001) significantly and positively influenced ZTA adoption, with awareness emerging as the strongest predictor overall. Organizational factors (β = -.136, p = .343) and environmental/regulatory factors (β = -.009, p = .964) did not show statistically significant effects. These findings suggest that ZTA adoption in this context is currently driven more by human-capital readiness than by institutional or regulatory pressure, extending the TOE framework's applicability while highlighting its limitations for security technologies whose effectiveness depends on continuous human behaviour. The study offers empirical grounding for prioritizing awareness-building initiatives alongside technological investment in similarly positioned financial institutions, and contributes one of the first empirical assessments of ZTA adoption determinants within a Tanzanian banking context.
Downloads
References
ORDR. (2026). Zero trust statistics 2026 report. https://ordr.net/blog/zero-trust-statistics-2026-report
National Institute of Standards and Technology. (2020). Zero trust architecture (NIST Special Publication 800-207). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207 DOI: https://doi.org/10.6028/NIST.SP.800-207
Okta, Inc. (2026). State of zero trust security report. As cited in Swif (2026), Zero trust statistics for 2026: Adoption, ROI, federal mandates, and what comes next. https://www.swif.ai/blog/zero-trust-statistics
BobsGuide. (2025). Implementing zero trust security frameworks in banking. https://www.bobsguide.com/implementing-zero-trust-security-frameworks-in-banking/
IBM Security. (2025). Cost of a data breach report 2025. IBM Corporation.
BlueRadius. (2026). Zero trust implementation strategies. https://blueradius.io/zero-trust-implementation-strategies
DataM Intelligence. (2026). Zero trust security market size, share, trends & forecast (2026–2035). https://www.datamintelligence.com/research-report/zero-trust-security-market
Tornatzky, L. G., & Fleischer, M. (1990). The processes of technological innovation. Lexington Books.
Deng, Y., & Inthiran, A. (2025). Towards zero trust architecture: A pilot study on information systems security readiness amongst small and medium enterprises [Completed research paper]. University of Canterbury, Department of Accounting and Information Systems.
Mwemezi, J., & Mandari, H. (2024). Big data analytics usage in the banking industry in Tanzania: Does perceived risk play a moderating role on the technological factors? Journal of Electronic Business & Digital Economics, 3(3), 318–340. https://doi.org/10.1108/JEBDE-01-2024-0001 DOI: https://doi.org/10.1108/JEBDE-01-2024-0001
Kiyanga, D. S. (2024). Factors influencing the adoption of cloud computing technology in the Tanzanian banking industry: A multifaceted analysis. The Journal of Informatics, 4(1). Institute of Accountancy Arusha.
Nguyen, T. H., Le, X. C., & Vu, T. H. L. (2022). An extended technology-organization-environment (TOE) framework for online retailing utilization in digital transformation: Empirical evidence from Vietnam. Journal of Open Innovation: Technology, Market, and Complexity, 8(4), Article 200. https://doi.org/10.3390/joitmc8040200 DOI: https://doi.org/10.3390/joitmc8040200
Pigola, A., & Meirelles, F. de S. (2025). Zero trust in practice: A mixed-methods study under the TOE framework. Journal of Cybersecurity and Privacy, 5(4), Article 99. https://doi.org/10.3390/jcp5040099 DOI: https://doi.org/10.3390/jcp5040099
Lyimo, B. J., & Shaaban, S. Y. (2021). Cybersecurity awareness among employees in banking industry in Tanzania: A case of National Microfinance Bank – Magomeni Branch. Olva Academy – School of Researchers, 3(1), 1–4.
Yamane, T. (1967). Statistics: An introductory analysis (2nd ed.). Harper and Row.
Downloads
How to Cite
Issue
Section
License
Copyright (c) 2026 Deogratius Mathew Lashayo

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
DATE
Accepted: 2026-08-21
Published: 2026-09-03








