An unprecedented surge
African companies face an unprecedented surge in cyberattacks. Ransomware, targeted phishing and CEO fraud are the three main threats, with recorded incidents up 200% in two years.
The banking sector and telecom operators are prime targets, given the immediate value of the data they hold and their exposure to significant financial flows.
A preparedness gap
Most organizations have neither a formalized security policy nor a dedicated team. This lack of preparation makes the sub-region a prime target for increasingly organized attackers, who recycle campaigns already proven in other markets.
The picture is worsened by a weak reporting culture: many incidents are never disclosed, preventing any pooling of lessons learned across organizations.
Three urgent investments
It is urgent to invest in staff awareness, detection solutions and incident response plans.
Together, these three workstreams drastically reduce risk exposure — exactly the method we apply for our banking and institutional clients.
What we recommend
Start with a complete security audit including penetration testing, then prioritize by asset criticality — there is no need to secure everything at the same level from day one.
A managed SOC, even shared at group scale, offers continuous monitoring accessible to organizations that cannot yet staff a dedicated in-house team.



