Abstract
This study evaluated the effect of cybersecurity awareness on the information management practices of small and medium sized enterprises (SMEs) in Lagos, Nigeria. A quantitative descriptive survey design was adopted, with data collected from 331 valid respondents drawn from SMEs across three major Lagos business districts using a multistage stratified sampling technique. The adapted Human Aspects of Information Security Questionnaire (HAIS-Q) served as the primary data collection instrument. Findings revealed a moderate overall cybersecurity awareness level (M = 3.03) among SME employees, with incident reporting constituting the most acutely deficient focus area. Information management practices were found to be broadly inadequate (M = 2.41), with incident response, backup and recovery recording the most severe deficits. A statistically significant, moderately strong positive relationship was established between cybersecurity awareness and information management practices (r = 0.618, p < .001), with awareness accounting for approximately 38% of the variance in practice scores. Hierarchical moderated regression analysis revealed that training availability, leadership support, and formal cybersecurity policy significantly amplify the behavioral dividend of higher awareness levels, while resource constraints attenuate it. The study concluded that awareness is a pivotal but institutionally conditioned determinant of information management quality in Lagos SMEs.
Keywords: Cybersecurity awareness, information management practices, Protection Motivation Theory, HAIS-Q
https://doi.org/10.5281/zenodo.21133913
Writers
Jude Chinonso Njoku
Shorelands British Academy
0009-0004-2264-8235
Ugonna Onyedikachukwu Chukwueke
Ahmadu Bello University Zaria
0009-0005-8601-9857
