A Risk-Based Framework for Assessing Cybersecurity Maturity Levels of Savings and Credit Cooperative Societies (SACCOS) in Tanzania
Savings and Credit Cooperative Societies (SACCOS) are central to financial inclusion in Tanzania; however, their digital transformation has advanced faster than their cybersecurity capabilities. National instruments, including the Cybercrimes Act (CAP 443), the Government Cyber Security Strategy 2022–2027, and the TCDC Guidelines on Cybersecurity and Resilience of SACCOS, establish baseline obligations, but none provide a structured, risk-based mechanism for measuring cybersecurity maturity or tracking improvements over time. This study developed and evaluated a context-specific Risk-Based Cybersecurity Maturity Assessment Framework (RBCMAF) for Tanzanian SACCOS by adapting the NIST Cybersecurity Framework (CSF) 2.0 to local governance, regulatory, and resource conditions. A descriptive, analytical, cross-sectional, mixed-methods design guided by Design Science Research principles was used. The quantitative strand is explicitly positioned as an exploratory pilot baseline rather than a nationally representative survey, drawing on respondents from a small number of purposively selected, anonymised digitised SACCOS using a NIST CSF-aligned questionnaire scored across the six CSF functions. Qualitative data were generated through semi-structured interviews with ICT managers, one per SACCOS, and a structured review of regulatory and supervisory documents. The instrument showed very high internal consistency, which should be read with caution because such values may also indicate item redundancy. The baseline placed the sampled SACCOS at the Developing maturity level overall, with Identify and Protect emerging as the strongest functions, and Respond, Recover, and Detect as the weakest. Gap analysis against an optimised target level confirmed that the largest deficits lay in Respond, Recover, and Detect. A risk-weighted assessment similarly prioritised Respond, Recover, Detect, and Govern as the functions most in need of attention. The resulting RBCMAF comprises five integrated layers operationalised through a six-stage assessment process and six design principles. Evaluation through quantitative application, qualitative triangulation, and regulatory benchmarking demonstrates the framework’s internal coherence, contextual fit, and practical utility for institutional self-assessment and risk-based supervision.