Nigeria’s digital economy is growing fast – Cybersecurity must grow faster

unnamed

By Iyanuoluwa David Adeoye

From instant bank transfers and fintech applications to digital government and artificial intelligence, Nigeria is building one of Africa’s most dynamic digital economies. Protecting that progress must now become a national economic priority.

A decade ago, completing a financial transaction in Nigeria could mean visiting a bank branch, joining a queue and filling out paperwork. Today, millions of Nigerians move money, pay bills, purchase goods, access loans and operate businesses from a mobile phone. That transformation is remarkable.

Nigeria has developed one of Africa’s most dynamic financial-technology ecosystems. Instant payments have become part of everyday life, Point-of-Sale terminals have reached communities far beyond traditional bank branches, and entrepreneurs can establish digitally enabled businesses with considerably fewer barriers than previous generations faced.

The numbers illustrate the scale of the transformation. Nigeria Inter-Bank Settlement System data indicate that close to 8 billion electronic transactions were processed in 2023, compared with approximately five billion in 2022. NIBSS has also reported that more than a quarter of electronic transactions in Nigeria now pass through real-time payment channels and the NIBSS Instant Payment platform. This progress should be celebrated.

But there is another side to Nigeria’s digital transformation that deserves equal attention. Every new digital account creates an identity that must be protected. Every online payment creates a transaction that somebody may attempt to manipulate. Every database creates information that criminals may want to steal. Every business that migrates to the cloud creates new technical dependencies. And every Nigerian who enters the digital economy becomes a potential target for increasingly sophisticated cyber-enabled fraud.

For Nigeria, cybersecurity is therefore no longer simply a technology issue. It is an economic-development issue. The ₦25.85 billion warning. There is evidence that Nigeria is making progress against payment fraud.

NIBSS reported that losses from digital-payment fraud fell to approximately ₦25.85 billion in 2023, representing a 51 per cent reduction from the ₦52.26 billion recorded in 2020. Reported fraud incidents also declined from 123,918 in 2021 to approximately 67,518 in 2023. That reduction is significant and demonstrates that stronger industry controls, identity management, monitoring and cooperation can produce results.

But ₦25.85 billion remains ₦25.85 billion too much for the people and organisations that lose it.

More importantly, the statistics reveal how the threat is evolving. NIBSS identified e-commerce and internet banking among the most affected channels and highlighted social engineering and insider abuse as significant fraud techniques. SIM-swap fraud, account compromise and phishing continue to evolve.

This is important because Nigeria’s cybersecurity problem cannot be solved simply by installing better firewalls.

Many successful attacks target people rather than machines. A criminal may impersonate a bank employee. Someone’s WhatsApp account may be hijacked and used to request money from friends or relatives.

A fake investment opportunity may be circulated online. An employee may receive what appears to be an urgent instruction from a senior executive. A customer may be persuaded to disclose authentication information.

NIBSS itself has previously warned about fraudulent messages circulated through compromised WhatsApp accounts, where criminals exploit trusted relationships to persuade victims to transfer money.

Cybersecurity in Nigeria must consequently deal not only with malicious software but also with malicious persuasion.

Artificial intelligence is making deception easier

The next stage of this challenge is artificial intelligence. AI offers enormous opportunities for Nigeria. It can support financial services, healthcare, agriculture, education, government administration and cybersecurity itself. But artificial intelligence is also becoming part of the cybercriminal’s toolkit. INTERPOL’s recent African Cyberthreat Assessment reported that AI was linked to 55 per cent of reported cybercrimes across Africa. The organisation said cybercrime-related losses recorded across the continent had risen from approximately US$192 million to US$484 million since 2020, with AI-facilitated scams, credential theft and automated social engineering among the drivers.

For Nigeria, this deserves serious attention. We have traditionally taught citizens to identify scams through poor grammar, strange spelling or suspicious messages. Generative AI can remove many of those warning signs. A scam message can now be professionally written in seconds.

AI-generated speech can potentially imitate familiar voices. Synthetic images and video can make impersonation more convincing. Automated systems can help criminals approach more potential victims simultaneously. INTERPOL’s assessment had already found criminals combining social engineering with AI-generated text, audio and video, including campaigns adapted to local languages and cultural contexts. This means Nigeria’s cybersecurity awareness programmes must evolve. “Do not click suspicious links” is still useful advice, but it is no longer enough.

Citizens need to understand that something can look professional and still be fraudulent. Trust, but verify especially when money is involved. Nigeria should encourage a cultural shift towards verification. If a relative suddenly sends a WhatsApp message requesting an urgent transfer, call the person through a trusted number. If somebody claiming to represent a bank requests confidential authentication information, use the bank’s official communication channel rather than responding directly. If a senior executive sends an unusual payment instruction, organisations should have processes requiring independent verification.

This principle matters particularly for businesses. Business Email Compromise, commonly known as BEC, is a form of fraud in which criminals manipulate business communications to redirect payments or induce employees to make fraudulent transfers.

INTERPOL identifies BEC as a significant threat across Africa, with particularly notable activity associated with West Africa. Its assessment found that financial institutions, import and export businesses, oil and gas companies, pharmaceuticals, transport, e-commerce organisations and government institutions have all faced such risks.

Nigeria’s growing SMEs should pay particular attention. A business does not need to be a multinational corporation to become a worthwhile cybercrime target. If an SME regularly makes payments, stores customer information or relies on email for business instructions, there is something worth attacking.

Cybersecurity must not become a luxury for big companies

This is one of the areas where Nigeria requires a different cybersecurity conversation. Large banks and telecommunications companies may maintain specialist security teams, threat-monitoring systems and sophisticated controls. The average Nigerian SME cannot necessarily do the same. Yet SMEs are essential to the economy.

The challenge is therefore to make basic cybersecurity achievable and affordable. A small business should, at minimum, know what its important digital assets are. It should use multi-factor authentication for important accounts. Staff should not share passwords. Administrative privileges should be restricted. Important data should be backed up. Software should receive security updates. Employees responsible for payments should understand common fraud techniques.

Financial instructions that are unusual or high-value should be independently verified. The business should also know what it will do if an important email account, computer or payment system becomes compromised. None of these actions requires a futuristic cybersecurity laboratory. What they require is discipline.

Data protection is cybersecurity too

Nigeria’s digital economy is built not only on money but also on information. Banks collect identity information. Telecommunications companies hold subscriber data. Hospitals process medical information. Schools hold children’s and families’ records. Technology businesses collect behavioural and transaction data. Government agencies maintain databases containing information on millions of citizens.

The Nigeria Data Protection Act 2023 therefore represents an important part of the country’s digital-security framework. Among its stated objectives are protecting individuals’ rights, regulating personal-data processing, requiring responsible handling of information and strengthening trust in Nigeria’s digital economy.

Cybersecurity and privacy cannot be separated. An organisation cannot claim to respect customers’ privacy while leaving their information poorly protected. The Act also creates consequences for organisations that fail in their responsibilities. Depending upon the category of data controller or processor, sanctions can include substantial remedial fees. Guidance associated with the Act also provides for notification to the Nigeria Data Protection Commission within 72 hours where a breach is likely to create risks to individuals’ rights and freedoms.

But compliance should not become another box-ticking exercise. The better question is not: “Have we produced a privacy policy?”

It is: “If someone tried to steal our customers’ information tonight, how quickly would we know?”

Cybersecurity can become a competitive advantage

The digital economy ultimately runs on trust. When Nigerians believe that mobile banking is safe, they use it. When international companies believe data will be adequately protected, investment becomes easier. When customers trust fintech platforms, those businesses can grow. When government digital services are dependable, citizens are more willing to use them.

And when technology companies can demonstrate strong security practices, Nigerian digital products become more competitive globally. Cybersecurity should therefore not be seen as money spent without generating value.

Security creates value by creating trust.

The businesses that recognise this early will have an advantage. Nigeria’s digital future must be secure by design. Nigeria’s digital transformation will continue. More citizens will come online. More payments will become digital. More government services will move onto technology platforms.

Artificial intelligence will become embedded in more businesses. Cloud services will continue expanding. The number of connected devices will increase. The solution is not to slow this transformation because cybercriminals exist. It is to make cybersecurity part of the transformation itself. Banks must build security into financial products.

Technology businesses must protect customer information from the beginning rather than after an incident. Government agencies must treat critical databases as national assets. Businesses must train employees while designing systems that do not depend upon employees being perfect. Citizens must become more sceptical of unexpected digital requests.

Schools and universities must develop the next generation of defenders. And executives must understand that cybersecurity is their responsibility too. Nigeria has already demonstrated that it can build digital systems at enormous scale. Its real-time payments ecosystem is evidence of what Nigerian technology, regulation and entrepreneurship can achieve. The next challenge is ensuring that the security surrounding those systems grows at the same speed. We should measure progress not by whether Nigeria can eliminate every cyberattack. No country can.

We should measure it by whether attacks become more difficult to execute, fraud becomes easier to detect, stolen accounts become less powerful, critical services become harder to disrupt, victims receive faster protection and organisations recover more effectively when incidents happen.

Nigeria’s digital economy is becoming too important for cybersecurity to remain an afterthought.

The nation has spent years building the infrastructure of its digital future. It must now build the trust that will sustain it.

Adeoye is an emerging cybersecurity professional specializing in threat management, risk governance, and digital resilience. He has supported high-impact tech initiatives for over 200,000 citizens at KWASSIP and is focused on building secure, sustainable digital ecosystems.

Breaking news & top stories

Stay connected with The Sun Newspaper

Get breaking news, exclusive stories, and live updates delivered straight to your phone. Join thousands of readers already following us on Whatsapp Channel and Telegram.

Breaking news & top stories

Follow The Sun Newspaper

Get live updates & exclusive stories delivered straight to your phone.

Breaking news & top stories

Stay connected with The Sun Newspaper

Get breaking news, exclusive stories, and live updates delivered straight to your phone. Join thousands of readers already following us on Whatsapp Channel and Telegram.