An Evidence-Informed Cybersecurity Maturity Framework for Banking Institutions in Emerging Economies: Integrating Zero Trust Architecture, Governance, and AI-Driven Detection

Banking institutions in sub-Saharan Africa and comparable emerging economies face a threat environment that has changed fundamentally since the early 2000s. Ransomware, advanced persistent threats (APTs), and insider attacks now target financial networks with precision that perimeter-centric defenses were never designed to withstand. Despite sustained investment in hardware controls, governance failures, human-factor vulnerabilities, and the absence of certified security leadership remain the dominant failure modes. This paper proposes an evidence-informed, three-phase cybersecurity maturity framework for banking institutions operating in resource-constrained environments. The framework is grounded in a mixed-methods case study conducted at Stanbic Bank Dar es Salaam, used as a documented historical baseline, and systematically extended through a synthesis of Q1 journal literature published between 2022 and 2025. Three contemporary control paradigms anchor the framework: Zero Trust Architecture (ZTA), AI-assisted anomaly detection, and continuous compliance monitoring aligned with NIST Cybersecurity Framework 2.0 and ISO/IEC 27001:2022. A six-dimension scoring rubric documents the CIA triad coverage index used in gap analysis, ensuring reproducibility. A standardized limitations framework addresses sample size, temporal scope, and generalizability constraints directly. Scenario-based validation against published Q1 benchmarks confirms conservative projected effectiveness across all three maturity phases. Future directions include longitudinal empirical validation across East African banking networks, quantum-resistant cryptography migration planning, and regulatory harmonization with Basel IV operational risk standards.

Keywords: network security; CIA triad; zero trust architecture; banking cybersecurity; NIST CSF 2.0; ISO/IEC 27001:2022; cybersecurity maturity framework; information security governance; emerging economies; anomaly detection