By Dr Gabriel O. Akinremi
Nigeria’s digital transformation has changed the way we live and work. We move money from our phones, register businesses online, access public services digitally, store information in the cloud and increasingly depend on technology for communication, education, healthcare and commerce.
That progress is important. But there is another side to the story that we cannot afford to ignore.
Every new digital service also creates another point at which criminals can attack.
Cybercrime in Nigeria is no longer simply internet fraud or stolen passwords. It has become a much broader national resilience challenge. When a bank is attacked, people can lose access to their money.
When a hospital’s systems are compromised, patient care can be disrupted. When a government database is breached, sensitive information can fall into the wrong hands. When a major digital platform goes down, the consequences can spread far beyond the organisation that was attacked.
The real question, therefore, is not whether Nigeria will experience cyber attacks. It is whether our institutions are prepared to withstand them without allowing one incident to become a much larger crisis. The threat has changed. The cybercrime environment has become increasingly organised.
Criminals no longer need to possess every technical skill themselves. Phishing kits, stolen credentials, malware, botnet capacity and other illicit services can be obtained through underground markets. Social engineering has also become more sophisticated. A fraudulent message can be tailored to a particular person, organisation or current event and delivered through email, SMS, social media or messaging applications.
The 2025 INTERPOL Africa Cyberthreat Assessment Report identifies online scams, phishing, ransomware, and business email compromise as significant cyber threats reported across the continent.
The assessment also points to the growing use of artificial intelligence, instant messaging and cybercrime-as-a-service to make attacks easier to scale. Nigeria was among the African countries most frequently targeted in 2024, while finance, healthcare, energy and government were among the sectors significantly affected across Africa.
Artificial intelligence is adding another dimension. AI itself is not the problem. It is a technology with enormous potential for development, education, business and public service. The concern is that criminals can also use it to make fraudulent messages more convincing, personalise scams, imitate voices or generate deceptive audio and video.
That means some of the old warning signs may no longer be enough.
A message that once looked obviously fraudulent because of poor grammar or awkward language may now appear perfectly convincing.
But technology is only part of the problem. Sometimes the weakest link is inside the organisation. Many cyber incidents begin with ordinary weaknesses. An employee may have excessive access privileges. A password may have been reused. A critical system may be running unsupported software.
A payment instruction may not have been properly verified. Remote access may not be adequately protected. Backups may exist but have never been tested.
These may sound like basic issues, but basic weaknesses can create serious consequences when they exist inside organisations responsible for important services. The problem becomes even more complicated because modern organisations rarely operate alone.
A bank may depend on a telecommunications company, cloud provider, payment switch, identity service and several software vendors. A hospital may depend on electricity, internet connectivity, laboratory systems, insurers and external technology providers. Government agencies may share information across ministries and contractors.
An organisation can therefore secure its own office and still be exposed through a supplier or digital dependency. Cybersecurity must consequently move beyond the walls of individual organisations.
Nigeria already has an important foundation. Nigeria is not starting from zero. The country has the National Cybersecurity Policy and Strategy 2021, the Cybercrimes (Prohibition, Prevention, etc.) (Amendment) Act 2024 and the Nigeria Data Protection Act 2023. The Nigeria Data Protection Commission also provides an important institutional framework for privacy and responsible handling of personal information.
The bigger challenge is implementation. A policy is useful only when organisations know what is expected of them, institutions have the resources to act, incidents can be reported without unnecessary barriers, investigators can obtain and preserve digital evidence, and victims know where to seek assistance.
Nigeria does not necessarily need another impressive strategy document sitting on a shelf. We need to ask harder questions. Are our critical organisations actually testing their incident-response plans? Can essential services continue when systems are unavailable? Are backups really recoverable? Can a compromised privileged account be shut down quickly? Do organisations know who they should contact during a serious cyber incident?
These are practical questions, but they are also governance questions.
The cybersecurity conversation becomes more meaningful when we connect it to everyday life. For financial institutions and fintech companies, the danger includes account takeover, credential theft, business email compromise, SIM-swap fraud, payment manipulation, ransomware and attacks through third-party providers. Strong authentication, separation of payment responsibilities, privileged-access monitoring and effective customer reporting mechanisms are therefore not simply technical requirements. They are part of protecting people’s livelihoods.
Telecommunications companies face another set of risks, including SIM-swap attacks, account takeover, denial-of-service attacks and compromise of network-management systems. Identity verification and remote administrative access security are particularly important.
For hospitals and public-health systems, ransomware and data breaches can become patient-safety issues. A hospital that cannot access critical records is facing more than an IT problem.
The same principle applies to electricity, water, transport, government services and other essential infrastructure. If the digital systems supporting these services fail, the consequences can eventually be felt in the physical world.
This is why cybersecurity should not be treated as the responsibility of the IT department alone.
A chief executive, finance officer, procurement officer, engineer, doctor, journalist, lecturer or administrator can make a decision that either increases or reduces cyber risk.
Identity may be our first line of defence One area deserves particular attention: identity.
Attackers often don’t need to break through sophisticated technical barriers if they can obtain a legitimate user’s credentials.
Privileged accounts are particularly sensitive because they can provide access to critical systems and information. The same applies to administrators of payment systems, telecommunications platforms, government databases and cloud environments.
Nigeria needs stronger identity and access management across critical digital services. Multi-factor authentication, appropriate separation of duties, rapid revocation of compromised accounts and stronger protection for privileged users should become normal practice.
The objective is straightforward: make it difficult for an attacker to become a trusted user.
We must prepare for failure, not just prevention. There is an uncomfortable truth about cybersecurity: even good security controls can fail.
That is why resilience matters. A backup is useful only if the organisation can restore its systems from it. An incident-response plan is useful only if people know their responsibilities before the crisis begins.
Every organisation providing an important service should know what to restore first, how much downtime it can tolerate, who can authorise emergency or degraded operations, and how it will inform the public.
Cyber exercises should not be limited to theoretical discussions. Organisations should practise realistic scenarios involving ransomware, stolen data, supplier compromise, loss of connectivity and even the spread of false information during a technical crisis.
The goal is not to pretend that attacks can always be prevented. The goal is to ensure that when prevention fails, society does not fail with it. The justice system is part of cybersecurity.
Another part of the conversation deserves greater attention: justice.
People are less likely to report cybercrime when they believe nothing will happen after reporting it.
Effective cybersecurity therefore extends from prevention to investigation and prosecution. Digital forensic capability, proper chain-of-custody procedures, trained prosecutors, judicial understanding of electronic evidence and international cooperation all matter.
INTERPOL has identified uneven investigative capacity, limited forensic tools, delays in mutual legal assistance and cross-border jurisdictional challenges as continuing obstacles in Africa.
A successful cybercrime response should not end with identifying that an attack happened. Evidence must be able to move through the justice system and, where appropriate, support accountability.
Cybersecurity is also about people. Technology will not solve a problem created partly by human behaviour and institutional weaknesses.
Cybersecurity education therefore needs to move beyond the traditional audience of IT professionals.
Boards need to understand cyber risk. Procurement officers need to understand technology suppliers. Finance teams need to recognise payment fraud. Journalists need to identify manipulated digital content. Teachers and university administrators need to protect student information. Community leaders need to know where citizens can report incidents.
Public awareness should also reflect the realities of Nigerian society.
People need practical guidance on payment verification, SIM-swap fraud, suspicious links, deepfakes, identity theft and the safe handling of personal information.
Education should be available in forms and languages ordinary citizens can understand. A national conversation about resilience: Nigeria now needs a more practical national conversation about cyber resilience.
We should know which digital systems are essential to the country’s functioning and understand the dependencies behind them. Organisations providing high-impact services should meet proportionate minimum security standards. Incident reporting should be straightforward and useful, not something organisations fear.
Information sharing between government, regulators, telecommunications companies, banks, technology companies, civil society and professional bodies should become more effective.
Most importantly, lessons from one incident should help prevent the next one.
Cybersecurity should become part of how we design digital services, procure technology, manage institutions and deliver public services, not something added after a system has already been built.
Nigeria’s digital future depends on this shift. We cannot build a digital economy on systems that citizens do not trust. We cannot expect people to embrace digital public services if they believe their information is unsafe. And we cannot protect critical infrastructure by waiting until something goes wrong before asking who was responsible.
The challenge before Nigeria is therefore bigger than stopping hackers. It is about building institutions and digital systems that can withstand disruption, recover quickly and retain public confidence.
The country already has important laws, policies, institutions and technical expertise. What is needed now is stronger implementation, clearer ownership, better coordination and a culture in which cybersecurity is treated as everyone’s responsibility.
Cybersecurity is no longer simply about protecting computers. It is about protecting the services, institutions, livelihoods and public trust that increasingly depend on them.
About the Author
Dr Gabriel O. Akinremi is an AI, Management Information Systems, cybersecurity, data governance and digital transformation scholar and practitioner with over 15 years of professional experience. He is Director of Programme at the Cyber Security Experts Association of Nigeria (CSEAN), a lecturer and technology professional. He has worked across cybersecurity, information systems, digital governance, data analytics and technology-driven organisational development. He is also engaged with the UNESCO AI RAM Technical Working Group Nigeria, contributing to discussions around responsible artificial intelligence, digital governance and ethical technology.
Discover more from TheTimes Nigeria
Subscribe to get the latest posts sent to your email.









