Screenshot
Cybersecurity expert and Chief Technology Officer of 3cs Aquarah Limited, Gideon Aniechi, says the 22% year-on-year decline in weekly cyberattack volumes across Africa does not signal a reduction in cyber threats but rather reflects a shift towards more sophisticated, organised and targeted attacks.
Speaking during an interview with ARISE NEWS on Friday, Aniechi said cybercriminals are increasingly operating like well-structured organisations, executing carefully planned attacks against specific victims instead of launching indiscriminate campaigns.
Speaking on the reported decline in cyberattack volumes, he said:
“Attackers are no longer attacking the way they used to before. They are now more organised, more specific and more targeted at their victims. While attacks have reduced in number, the damage they cause is much greater.”
Aniechi explained that attackers now spend weeks inside compromised systems, quietly gathering intelligence and extracting sensitive information while organisations continue operating without detecting the breach.
“Attackers could remain in an organisation for weeks while business continues as usual, but at the end of the day, massive amounts of sensitive data are stolen”.
On what is driving the growing sophistication of cyberattacks, Aniechi said cybercrime has become institutionalised, with criminal groups operating like legitimate businesses and assigning specialised roles to maximise the effectiveness of their operations.
“Fraud has become institutionalised. These groups now operate like organisations with dedicated teams carrying out different responsibilities, making their attacks more strategic and effective”.
Addressing the growing threat of identity theft, Aniechi warned that cybercriminals are increasingly targeting sensitive personal information, including Bank Verification Numbers (BVNs) and national identification data, because such information cannot easily be changed once compromised.
“They are no longer just after money. They are targeting identities such as BVN and national identification data because those cannot simply be changed after they are compromised”.
Speaking on emerging cybersecurity priorities, Aniechi stressed that organisations must adopt a zero-trust security model, noting that advances in artificial intelligence have made identity impersonation easier than ever.
“Zero-trust has become the key driver of security. Today, a person’s voice can be cloned within seconds, so organisations can no longer rely on traditional methods of trust”.
Speaking on Africa’s cybersecurity capabilities, Aniechi said the continent should develop and adopt security technologies tailored to its unique operating environment rather than relying heavily on imported solutions.
“The tools we use should reflect Africa’s realities. We need security solutions and policies designed for our environment rather than depending entirely on imported systems”.
Aniechi also welcomed recent cybersecurity and data protection initiatives introduced by Nigerian regulators, including the Central Bank of Nigeria (CBN) and the Nigeria Data Protection Commission (NDPC), saying stronger policies would enhance cyber resilience across Africa.
“Whether it is cybersecurity regulations or data protection policies, stronger frameworks are needed to help organisations and individuals stay ahead of evolving digital threats.”
Concluding, Aniechi stressed that tackling Africa’s evolving cyber threats requires stronger collaboration among governments, regulators and private-sector organisations to develop cybersecurity frameworks tailored to the continent’s needs.
“Public and private institutions must work together to define the level of cybersecurity that best suits Africa and ensure those standards are effectively implemented”.
By Goodness Anunobi
