Why COVID exposed Nigeria’s weakest corporate security links

IMG-20250820-WA0031

By Benson Michael

When COVID-19 forced businesses to adapt to Zoom calls and cloud platforms, an old flaw resurfaced: corporate security rules designed for desktops and office VPNs weren’t built for a workforce logging in from everywhere. This opened blind spots for today’s cyber attackers to exploit.

 

“In those first months, companies were just focused on staying connected,” Halliday recalls. “Security wasn’t reimagined, it was patched. And that’s where the real risk began.”

Halliday has a front-row seat to these challenges. At Netskope, she manages high-priority incidents for premium clients worldwide, fine-tuning data loss prevention systems, replicating complex environments to resolve vulnerabilities, and coordinating rapid responses to emerging threats. She has observed how even well-resourced organizations falter when remote work exposes gaps in identity management, access control, and behavioral safeguards.

 

“I started seeing the same pattern in 2021 and 2022: companies patched systems, but left people and policies exposed,” says Nnennaya Halliday, a cloud security engineer at Netskope. “When your security playbook assumes everyone sits behind a corporate VPN at 9am, remote work doesn’t just change the routine , it exposes the predictability attackers wait for.”

That shift has shaped attacker behaviour. Instead of relying only on malware, fraudsters lean into manipulation: forged emails from senior staff, urgent approval requests, and instructions disguised as routine. “Deception hides in what looks normal,” Halliday notes. “A message that reads like a colleague’s could be the beginning of a breach.”

Her conclusion is blunt: the remedy isn’t a silver-bullet tool, but a policy-and-people reset. That means updating access rules for distributed endpoints, deploying behaviour-aware systems that flag odd patterns, and training staff to treat timing and language as threat signals. “Security by design means workflows that assume distribution from day one , not retrofitting yesterday’s controls,” she says.

Still, she adds a note of caution: behaviour monitoring must come with clear privacy guardrails. “You can’t fight deception by becoming intrusive.”

By mid-2022, her warnings resonated in Nigeria’s tech circles; not as alarm, but as a practical wake-up call. Remote work had made security personal. Every employee was a gatekeeper, and every inbox a possible entry point.

Looking ahead, Halliday plans to publish a framework specifically designed for distributed teams, bridging SMEs, large enterprises, and gig-driven organizations. It will combine technical defenses with ethical monitoring, governance guidelines, and employee education. “Remote work is here to stay,” she says. “If security policies don’t evolve with it, breaches are inevitable. My goal is to give Nigerian businesses a practical roadmap before it’s too late.”

Finally, she leaves executives a simple but urgent question: When remote employees are the norm, will companies update the rules they rely on, or keep pretending the office never left?

 

Breaking news & top stories

Stay connected with The Sun Newspaper

Get breaking news, exclusive stories, and live updates delivered straight to your phone. Join thousands of readers already following us on Whatsapp Channel and Telegram.

Breaking news & top stories

Follow The Sun Newspaper

Get live updates & exclusive stories delivered straight to your phone.

Breaking news & top stories

Stay connected with The Sun Newspaper

Get breaking news, exclusive stories, and live updates delivered straight to your phone. Join thousands of readers already following us on Whatsapp Channel and Telegram.