Logo Lanfrica

Compliance Ahead of Capacity: Institutional Isomorphism and Cybersecurity Governance Adoption in Ghana's Business Process Outsourcing and Telecommunications Sectors

Domaine:

digital infrastructure

Type de record:

paper
Créateur:
Den
Éditeur:
Elsevier BV
Hôte:
Ghana built formal cybersecurity governance infrastructure with unusual speed: the Cybersecurity Act, 2020 (Act 1038) established a licensing and accreditation regime, sectoral computer emergency response teams now span banking, telecommunications, and government, and the Bank of Ghana substantially revised its financial-sector cyber directive in 2026, its first major revision since 2018. Yet Kolog and Tijani's (2023) survey of Ghanaian financial institutions found that legal measures were by far the strongest driver of Cybersecurity Act implementation, while organisational measures, the internal governance capacity to sustain compliance, showed no significant effect at all. That finding is reported but not theoretically explained. This paper argues that institutional isomorphism (DiMaggio & Powell, 1983), together with the related concept of decoupling (Meyer & Rowan, 1977), accounts for the asymmetry: coercive pressure, exercised through statute, licensing, and audit, has outpaced the mimetic and normative pressures that typically convert formal compliance into embedded organisational capacity, leaving formal structure and operating practice loosely connected at best. Composite illustrative vignettes from Ghana's business process outsourcing and telecommunications sectors, drawn from operational experience, show the same pattern below the level of national survey data. The paper closes with implications for practitioners, who should not read legal compliance as a proxy for readiness, and an agenda for research testing the three isomorphic pressures directly against cybersecurity governance outcomes in Ghana.

Similaires