Spotlight on African Cyber Leadership: Shaping Digital Trust and National Security. As rapid digital transformation sweeps across Africa, establishing robust national cybersecurity frameworks and resilient digital infrastructure has evolved from an IT priority into a strategic national imperative. Building digital trust is now the cornerstone of economic growth, international investment, and sovereign security. As part of CyberCory.com’s official launch in Côte d’Ivoire for French-speaking Africa, our Director, Ouaissou DEMBELE discussed with Josué ROMBA on “Cyber Resilience: Preparing African Organizations for the Next Major Cyberattacks“. In this exclusive interview, Josué ROMBA shares key insights into developing national cybersecurity programs, navigating the evolving threat landscape, and fostering the next generation of cyber resilience across the continent. Below is our full conversation on strategy, governance, and the future of cybersecurity in Africa.
Biography: Josué ROMBA
Josué ROMBA is a Chief Information Security Officer (CISO) and cybersecurity expert based in Abidjan, Côte d’Ivoire. He operates at the heart of the digital financial services sector a highly regulated environment where payment continuity and user trust represent critical stakes.
Holding over nine international certifications including Senior Lead Cybersecurity Manager, Senior Lead Incident Manager, EBIOS Risk Manager Confirmed, ISO/IEC 27001 Lead Implementer, ISO/IEC 27005 Risk Manager, PECB Certified Trainer, ISC2 Certified in Cybersecurity, and AWS Certified Cloud Practitioner—he has built his expertise at the intersection of IT governance, risk management, and operational resilience.
Throughout his career, he has advised private companies, financial institutions, and public sector entities in defining and steering their cybersecurity strategies: governance, digital risk assessment, structuring resilience frameworks, and implementing compliance architectures based on ISO/IEC 27001, ISO/IEC 27005, and EBIOS Risk Manager standards.
Author of the white paper “Cybersecurity in Africa: Positioning the CISO as the Architect of African Institutional Resilience” (2026), he is also the founder of the editorial platform cybersecuriteenafrique.com and co-initiator of the CyberSchool Tour, an awareness campaign across Ivorian schools and universities. As a certified trainer and an engaged voice in African cybersecurity, he champions an unwavering conviction: cybersecurity is a lever for sovereignty and institutional trust, not a constraint.
Introduction
The objective of this interview is to move beyond mere cyberattack prevention and explore the true capacity of organizations to anticipate, withstand, respond to, and rapidly recover from a major cyber incident.
We invite you to select the questions you wish to answer from those provided below. Feel free to elaborate on your answers or share real-world insights from your professional experience without disclosing confidential information.
I. Vision and Evolution of Cyber Resilience in Africa
1. How do you assess the overall level of cyber resilience among African organizations today, and what do you consider to be the most urgent gaps that need to be addressed?
ANSWER:
First, we must distinguish between two concepts that are still too often confused: security and resilience. Many African organizations have made progress on the former by deploying firewalls, antivirus software, and basic policies. Very few have tackled the latter that is, the capacity to remain operational when controls fail.
Data frames this diagnosis clearly. In its Africa Cyberthreat Assessment Report 2025, INTERPOL notes that two-thirds of surveyed African countries consider digital crime to represent a medium-to-high proportion of overall crime, exceeding 30% of reported crimes in West and East Africa. The same report highlights that 90% of African nations identify a critical need to significantly improve their investigative and prosecutorial capabilities. Regarding volume, Kaspersky recorded over 92 million cyber threats in West Africa in 2025 alone.
Three urgent gaps must be addressed:
- Governance: As long as cybersecurity is not a standing agenda item at the board level, it remains a technical subject arbitrated at the bottom of the budget.
- Detection: You cannot respond to what you cannot see; many organizations lack actionable logging and continuous monitoring.
- Recovery Capabilities: Untested backups are not backups they are wishful thinking.
A Kaspersky survey conducted in late 2025 among African decision-makers (including in Côte d’Ivoire and Senegal) illustrates this issue well: 65% admit that their cybersecurity strategy remains more theoretical than applied. The gap is not between those who know and those who do not; it is between those who have written plans and those who have tested them.
2. Are African organizations adequately prepared to face a major cyberattack that could disrupt their operations for several days or even weeks?
ANSWER:
To answer honestly: the majority are not. Not out of negligence, but because most existing Business Continuity Plans (BCPs) were designed for physical disasters – power outages, fires, facility unavailability – and not for the simultaneous loss of the information system, active directory, and backups.
The diagnostic test I propose to executives is simple. Three questions:
- When was the last time you performed an end-to-end restoration of a critical system, and how long did it actually take?
- Do your teams know how to operate in a degraded manual mode for five days without IT systems?
- Where are your crisis management team’s contact details stored if your corporate email is compromised?
In most organizations, these three questions lack documented answers.
For financial institutions and payment providers, the stakes extend far beyond technical rebooting. A multi-day outage means service disruption for millions of users, mandatory regulatory notifications, and an erosion of trust that takes much longer to repair than a server.
3. In your view, what is the fundamental difference between an organization that is simply “secure” and one that is truly “cyber-resilient”?
ANSWER:
A secure organization invests to prevent incidents. It measures itself prior to an attack through controls, audits, and compliance.
A cyber-resilient organization has taken an additional step one that is culturally more difficult: it has accepted the assumption of its own compromise and structured itself to continue creating value despite it. Concretely, this means knowing its critical assets, establishing Maximum Tolerable Downtime (MTD) driven by business units rather than IT, maintaining offline and immutable backups with timed restoration drills, having an identified crisis escalation pathway up to the Board, and treating every incident as a lessons-learned feedback loop.
As I often phrase it: security is measured before the incident; resilience is measured during and after. The former protects systems; the latter protects the institution.
II. Preparing Organizations for Upcoming Major Cyberattacks
4. Cybercriminals are becoming more sophisticated, leveraging AI, automation, and advanced social engineering. Which new threat vectors should African organizations prioritize for defense?
ANSWER:
The primary shift is not the emergence of novel threats, but the industrial scaling of known attack vectors.
- Priority 1: AI-Assisted Wire Fraud & Business Email Compromise (BEC). INTERPOL identifies about ten African countries where the bulk of BEC activity is concentrated, with West African threat groups described as highly structured and well-funded. A recent case is telling: during Operation Sentinel in late 2025, a major oil company in Senegal detected CEO fraud attempting an unauthorized $7.9 million wire transfer. Generative AI removes the subtle indicators we used to train staff on: no more typos, flawless grammar, deep contextual knowledge of internal operations, and now voice deepfakes impersonating executives to authorize transfers.
- Priority 2: Double-Extortion Ransomware targeting financial institutions and public sector agencies, combining data encryption with exfiltration and leak threats.
- Priority 3: Industrialized Social Engineering on Mobile Money platforms. In the WAEMU (UEMOA) region, the BCEAO recorded 248.7 million registered electronic money accounts at the end of 2024 (76.8 million active), marking an ~19% YoY growth. Smishing and vishing – fraudulent SMS and calls spoofing operators to harvest PINs – primarily hit populations least familiar with digital risks. INTERPOL notes, based on Kaspersky data, up to a 3,000% increase in reported scams year-over-year in certain African countries.
- Priority 4: Digital Supply Chain Risks (elucidated further below).
5. If you were to identify three major cyberattack scenarios capable of inflicting systemic impact on African businesses or infrastructure in the coming years, which would you name?
ANSWER:
- Scenario 1: Paralysis of Shared Payment Infrastructure. A ransomware strain reaching an interbank clearing system, national switch, or shared payment platform does not just lock down a single institution it paralyzes an entire country. Precedents exist at the single-entity level: during Operation Serengeti, Kenyan police documented an $8.6 million fraud scheme where funds were routed via SWIFT to entities in the UAE, Nigeria, and China following the alteration of a banking security protocol. The margin between a contained incident and a systemic crisis is thin.
- Scenario 2: Single-Point-of-Failure Vendor Compromise. The continent relies on a concentrated ecosystem of software vendors and service providers. Compromising a single core-banking vendor, regional system integrator, or cloud provider could simultaneously impact dozens of institutions across multiple countries. This is the SolarWinds paradigm transposed onto a significantly more concentrated market.
- Scenario 3: Disruption of Non-Financial Critical National Infrastructure (CNI). INTERPOL has already documented attacks against public entities such as Kenya’s urban roads authority or Nigeria’s national bureau of statistics. Power grids, telecommunications, national registries: without power or network connectivity, no financial continuity plan holds. This is the least exercised scenario, yet the one with the widest cascading failure effect.
6. Are ransomware attacks, supply chain compromises, and threats against critical infrastructure adequately accounted for by African business leaders?
ANSWER:
My response is nuanced yet clear: Ransomware is now understood; supply chain risk is largely ignored; and critical infrastructure protection is addressed very unevenly.
The World Economic Forum (WEF), in its Global Cybersecurity Outlook 2026, documents a significant perception gap: CEOs now rank cyber fraud and phishing as their top concerns, whereas CISOs place ransomware first and supply chain disruption second for two consecutive years. In short, executives look at financial loss; CISOs look at operational shutdown. These are two different time horizons, and that is precisely where budget misallocations occur.
To assess whether a risk is truly addressed, I offer three tests to executives:
- Does this risk appear on the enterprise risk register with a quantified financial impact, rather than in an IT-only spreadsheet?
- Is there a designated executive-level owner and a dedicated budget allocation?
- Has it been tested via tabletop or simulation exercises in the past 12 months?
On ransomware, many organizations pass the first test. Very few pass the third.
On supply chain risk, the lag is structural. The WEF observes that top-tier resilient organizations evaluate supplier security maturity far more aggressively (74% vs. 48%), involve security teams in procurement decisions (76% vs. 53%), and simulate ecosystem incidents with partners. In Africa, where dependency on a limited pool of service providers is high, this domain remains largely outside board visibility. A signed contract is not a security control.
Regarding critical infrastructure, the challenge is governance: risk is split among private operators, regulators, and state agencies, resulting in diffuse ownership. Until joint crisis exercises are conducted between telecom operators, energy grid providers, and the financial sector of a country, readiness remains purely theoretical.
7. How should organizations structure their preparation to manage a situation where critical systems become entirely unavailable due to a cyberattack?
ANSWER:
By working backward, starting from business operations rather than technical infrastructure. I recommend six key workstreams:
- Map Critical Assets: Have business leaders – not IT – define the Maximum Tolerable Downtime (MTD) and Recovery Point Objective (RPO) for each critical process.
- Secure Recovery Capabilities: Implement the 3-2-1 backup strategy with at least one offline or immutable copy, and routinely run timed restoration drills. You don’t recover a file; you recover a business service.
- Document and Practice Degraded-Mode Operations: Establish manual procedures, lowered transaction limits, deferred reconciliation, and physical paper ledgers. It is unglamorous, but it preserves customer trust.
- Prepare Crisis Decision Pathways: Define who has authority to pull the plug, who notifies regulators, who speaks to clients, and who communicates with the media supported by pre-drafted messaging and out-of-band communication channels outside the compromised domain.
- Establish Retainers for Incident Response (IR) and Forensics: Retain external incident response and digital forensics support in advance. You do not negotiate an IR retainer at 3:00 AM on a Sunday.
- Conduct Executive Simulations: Run at least one annual simulation with the C-suite around the table, presenting post-mortem findings directly to the Board of Directors.
III. Governance, Leadership, and the Role of the CISO/CIO
8. What role must the Board of Directors and Executive Management play in cultivating a genuine culture of cyber resilience?
ANSWER:
A role of co-governance, not delegation. This correlation is well-documented: in the WEF’s Global Cybersecurity Outlook 2026, 99% of organizations reporting high resilience state that their Board is actively engaged in cybersecurity oversight, with over half conducting regular board-level briefings. Board engagement is not an added bonus; it is a statistical indicator of resilience.
I identify four core responsibilities for the Board and Executive Leadership toward the CISO:
- Grant a Formal Mandate: Direct reporting line to the CEO, direct escalation access to the Board, a seat on the Executive Committee (EXCO), and a documented charter.
- Allocate Ring-Fenced Budgets: Allocate dedicated funding protected from mid-year reallocations a point emphasized in the WEF CISO white paper.
- Participate in Crisis Simulations: Actively join crisis exercises and formally accept residual risk in writing.
- Educate Themselves: Build sufficient cyber literacy among non-technical board members to challenge the CISO rather than rubber-stamping reports.
We must break a pervasive cycle: executives feeling overwhelmed, delegating total responsibility to the CISO without giving them the necessary authority or resources, and discovering their exposure only on the day an incident strikes. Culture is set by example: when the CEO personally participates in a crisis simulation, the entire organization aligns.
9. Should the CISO today be viewed primarily as a technical manager or as a strategic advisor to Executive Management and the Board?
ANSWER:
A strategic advisor, without ambiguity. But a strategic advisor who has not lost their technical credibility.
In my work, I outline four evolutionary stages of the CISO role:
- Pre-2015 Technical CISO: Focused primarily on firewalls and antivirus tools.
- 2015-2020 Managerial CISO: Focused on compliance frameworks and IT reporting.
- Today’s Strategic CISO: A partner to executive leadership and architect of institutional trust.
- 2030 Horizon Systemic CISO: Deeply engaged in AI governance, digital sovereignty, and cyber diplomacy.
The majority of African organizations currently operate at the managerial level.
The WEF white paper, Elevating Cybersecurity: Ensuring Strategic and Sustainable Impact for CISOs, describes the modern CISO as an enterprise strategist whose primary operating model is relationship-building: the ability to build alliances inside and outside the organization matters more than reporting lines. From this, I derive six roles for the strategic African CISO: executive partner, guardian of resilience, architect of security culture, business-fluent communicator, talent leader, and resource negotiator. Technical mastery remains the foundation of credibility, but it is no longer the core job description.
10. How can organizations better integrate cyber risk into their broader Enterprise Risk Management (ERM), Business Continuity, and Operational Resilience strategies?
ANSWER:
By dismantling parallel governance structures. As long as cyber risk lives in a siloed register managed by IT and presented once a year, it will never carry the weight of credit risk or operational risk. Successful integration relies on three concrete conditions:
- Translate Cyber Risk into Business Impact: Cyber risk must be expressed in business metrics. “Active Directory compromise” is an IT issue. “48 hours of payment system downtime resulting in X millions in lost fee revenue, Y affected clients, and mandatory regulatory sanctions” is an enterprise risk. Translating technical risk to financial/operational impact is a core competency of the modern CISO.
- Unified Business Impact Analysis (BIA): Business Continuity and Information Security must share a single BIA. Target recovery times (RTO) and data loss thresholds (RPO) are strategic business decisions, not technical parameters. When set by IT alone, they are invariably overly optimistic.
- Harmonized Governance Bodies & Methodologies: Cyber risk must be reviewed by the Audit & Risk Committee with the same frequency as other principal risks, with residual risk formally signed off in writing. Methodologically, standard alignment is clear: EBIOS Risk Manager or ISO/IEC 27005 for scenario modeling, ISO 22301 for continuity, ISO/IEC 27001 for overarching management, and the NIST CSF 2.0 to communicate with international stakeholders.
The WEF formalizes this approach in its Cyber Resilience Compass, structuring resilience across seven domains: Leadership; Governance, Risk & Compliance; People & Culture; Business Processes; Technical Systems; Crisis Management; and Ecosystem Engagement. Notice that five of these seven pillars are non-technical. Operational resilience cannot be outsourced to the IT department; it must be orchestrated at the enterprise level.
11. What key metrics or KPIs would you recommend to executives to measure their true level of cyber resilience?
ANSWER:
I would begin with a mindset shift. Leadership must accept that their organization can and will suffer an incident. Once accepted, the core question shifts from “What is the probability of an attack?” to “How fast do we recover, and in what sequence?” Board-level metrics should focus on recovery capabilities rather than vanity activity metrics:
- Prioritized Business Service Recovery Sequence: A board-approved, business-aligned restoration list. If recovery priorities aren’t decided in peacetime, they will be decided during a crisis by whoever shouts loudest.
- Demonstrated (vs. Declared) Mean Time to Recover (MTTR): The actual measured duration during the latest restoration test for critical services compared against the business MTD. The delta between these two numbers belongs on page one of executive reporting.
- Percentage of Critical Services Validated via Restoration Testing in the Last 12 Months: Any service whose recovery has not been validated in a live test should be assumed non-resilient, regardless of the budget spent.
- Calculated Cost per Hour of Downtime (by Critical Service): The metric that turns abstract budget debates into concrete investment decisions.
- Crisis Decision-Making Velocity: The time elapsed during a crisis exercise between initial threat detection and the first strategic executive action (e.g., isolating networks, failing over, publishing external communications, notifying regulators). This is almost always the slowest link in the chain.
- Single-Point-of-Failure (SPOF) Third-Party Dependencies: The number of essential services reliant on a single vendor with no documented fallback option. This metric must be visible to the Board and systematically reduced year-over-year.
I intentionally exclude technical operational metrics—such as alert counts, patch rates, or phishing click rates—from board dashboards. While essential for internal security operations, they do not inform executive decision-making. A Board must know four things: Which services first, how quickly, proven when, and at what cost per hour?
IV. Emerging Technologies and Artificial Intelligence
12. Artificial Intelligence presents both opportunities and threats. How can African organizations leverage AI for cyberdefense while mitigating its risks?
ANSWER:
Defensive AI democratizes capabilities previously reserved for elite enterprises: automated alert triage and correlation, anomaly detection across high-volume Mobile Money transactions, and Tier-1 SOC automation. For small security teams of 3 to 5 people, AI is a force multiplier.
In the WEF Global Cybersecurity Outlook 2026, 94% of respondents identify AI as the primary driver transforming cybersecurity, while 87% highlight AI-related vulnerabilities as their fastest-growing risk. Yet governance lags: 71% of highly resilient organizations regularly audit their AI toolsets, compared to just 20% among lower-performing peers.
The risks fall into two categories:
- Offensive AI: Highly believable spear-phishing in local languages and executive voice cloning.
- Shadow AI: Employees inputting proprietary source code, customer data, or contracts into public AI models without security oversight.
I recommend establishing governance before tool deployment: clear Acceptable Use Policies (AUP), data classification guidelines specifying what can never leave the perimeter, contractual terms regarding data retention and model retraining, usage monitoring, and a human-in-the-loop requirement for critical security actions. AI generating alerts that no human reviews adds zero resilience.
13. Do African organizations currently possess the skills, technologies, and resources to detect and respond to automated, AI-driven attacks?
ANSWER:
Not yet, and capability varies widely by country and sector. This talent shortfall is global: the WEF notes that only 14% of organizations worldwide feel confident they possess the cybersecurity skills they require, with two-thirds reporting moderate to severe skills shortages. What sets Africa apart is that this gap intersects with tighter budgets and direct global competition for local talent.
Kaspersky’s late-2025 survey across African decision-makers mirrors this reality: roughly one-third reported gaps in understanding security fundamentals, and 34% cited a need to enhance incident response competencies—the exact skill needed to counter automated threats.
Two positive trends stand out:
- Regional cooperation is expanding, demonstrated by joint INTERPOL-AFRIPOL law enforcement operations.
- Resource constraints force smart prioritization, whereas better-resourced global counterparts often accumulate shelfware tools they fail to fully operationalize.
Pragmatic solutions include: leveraging shared industry SOCs, using Managed Detection and Response (MDR) services with clear skills-transfer clauses, and positioning the CISO as an internal talent multiplier. Developing security champions within business units often yields better ROI than buying another tool.
14. Which technology investments should be prioritized over the next three years (e.g., SOC, XDR, SIEM, Zero Trust, Cloud Security, IAM, Data Protection)?
ANSWER:
Sequence matters more than the tool list. Before deploying advanced tools, two prerequisites are non-negotiable: an accurate asset inventory and actionable central logging. Without these, a SIEM is an expensive distraction.
- Priority 1: Identity & Access Management (IAM). Robust IAM, universal Multi-Factor Authentication (MFA), and Privileged Access Management (PAM). The overwhelming majority of breaches exploit compromised credentials rather than zero-day vulnerabilities.
- Priority 2: Detection and Response. EDR expanding into XDR, a right-sized SIEM focused on actionable alerts, and 24/7 continuous monitoring (internal or managed).
- Priority 3: Immutable Recovery. Immutable/air-gapped backups and regular restoration drills. This is the last line of defense determining whether ransomware is a manageable incident or an existential crisis.
- Priority 4: Cloud & Third-Party Risk Management. As attack surfaces shift toward partner APIs and cloud hosted assets.
Zero Trust is a strategic journey, not a single product purchase; it is realized through identity, micro-segmentation, and continuous verification. Encryption and data protection remain cross-cutting baselines. Golden rule: Never acquire a tool without the human expertise to operate it.
V. Skills, Talent, and Pan-African Cooperation
15. The cybersecurity skills shortage remains a major bottleneck. How can corporations, governments, and educational institutions collaborate to build local talent?
ANSWER:
Each stakeholder has a distinct role to play:
- Corporations: Hire for learning potential rather than demanding years of specialized experience. Upskill generalist IT staff, offer work-study apprenticeships, mentor juniors, and provide certification stipends. Crucially, focus on retention we are competing in a global remote work marketplace. Clear career progression, high-impact responsibilities, and continuous learning often outweigh salary bidding wars.
- Governments: Fund specialized academic tracks, make public-sector cybersecurity roles competitive, and leverage national CERTs as incident response training grounds.
- Academic Institutions: Co-design curricula with active industry practitioners, invest in real-world hands-on labs, and mandate practical internships exposing students to live production environments.
This is a deep personal conviction: through the CyberSchool Tour, I personally engage with Ivorian students, and through my role as a certified instructor, I work to make this profession accessible and clear. Young people cannot aspire to a career path they cannot see.
16. Can national cyber resilience be achieved without public-private partnerships involving CERTs/CSIRTs, CNI operators, and industry vendors?
ANSWER:
No, it is structurally impossible. Threat actors targeting the financial sector reuse the exact same infrastructure, lures, and TTPs (Tactics, Techniques, and Procedures) against peer institutions. Without threat intelligence sharing, every organization pays to relearn lessons its neighbor has already paid for.
Four pillars are essential:
- Fully operational national CERTs/CSIRTs viewed as trusted partners rather than punitive regulators.
- Clear, proportionate, non-punitive incident reporting mandates.
- Sectoral ISACs (Information Sharing and Analysis Centers), particularly across finance, telecom, and energy sectors.
- Safe-harbor legal frameworks protecting organizations that share threat indicators.
The main barrier is cultural, not technical. Institutions fear reputational damage and regulatory penalties following incident disclosure. Until reporting an incident is viewed as a responsible civic act rather than an admission of failure, information sharing will remain limited. This is a trust and governance issue, not an engineering one.
17. What role should regional and pan-African cooperation play in threat intelligence sharing, incident response, and cross-border crisis management?
ANSWER:
A central role, because cybercrime operates transnationally while defenses remain fragmented nationally. Joint operations demonstrate this power clearly:
- Operation Serengeti (Sept–Oct 2024): 19 countries, 1,006 arrests, over 35,000 victims identified, and ~$193 million in documented losses.
- Operation Serengeti 2.0 (June–Aug 2025): 18 African nations and the UK, leading to 1,209 arrests and $97.4 million recovered.
- Operation Sentinel (Oct–Nov 2025): Focused on BEC, cyber extortion, and ransomware, resulting in 574 arrests.
- Operation Red Card 2.0 (Dec 2025–Jan 2026): Executed across 16 African nations, yielding 651 arrests and recovering >$4.3 million tied to schemes responsible for >$45 million in losses. In Côte d’Ivoire alone, 58 individuals were arrested for fraudulent loan applications targeting vulnerable populations.
Four regional priorities for the decade:
- Legal Harmonization: Aligning national frameworks around the Malabo Convention, eliminating regulatory arbitrage exploited by attackers.
- Real-Time Threat Intelligence Exchange: Automated IOC sharing between national CERTs and sectoral ISACs.
- Cross-Border Incident Response Assistance: Shared pools of specialized experts deployable to assist smaller nations during major incidents.
- Cross-Border Crisis Exercises: Essential for integrated economic blocks like the WAEMU (UEMOA), where intra-regional cross-border transactions exceeded 102 million operations in 2024. A cyber crisis affecting a regional payment system will not stop at national borders.
VI. Guidance for African Business Leaders
18. What three priority recommendations would you give to an African CEO, CIO, or CISO seeking to prepare their organization for a major cyber incident?
ANSWER:
- Empower the CISO with a Clear Mandate and Ring-Fenced Budget: Establish direct reporting to executive leadership, direct access to the Board, a formal charter, and a protected budget shielded from mid-year cuts. Without this structural authority, CISO effectiveness remains constrained regardless of personal talent.
- Know What Must Be Protected and Prove What Can Be Restored: Conduct a critical asset mapping exercise and run a timed, end-to-end recovery test within the next 90 days. These two exercises are cost-effective and highly illuminating.
- Conduct Executive Tabletop Exercises Before a Crisis Hits: Run an annual crisis simulation with executive leadership to wrestle with tough strategic choices (e.g., when to disconnect systems, public communications strategy, regulatory disclosures). Feed lessons learned directly into board reporting.
A foundational reminder: Humans remain the primary entry point for threat actors. A continuous, culturally relevant awareness program paired with a non-punitive phishing reporting mechanism yields an ROI that few technologies can match.
19. What is the single most common mistake organizations still make when preparing for a cyber crisis?
ANSWER:
Confusing having a plan with being prepared.
In Kaspersky’s late-2025 survey, 65% of African decision-makers admitted that their cybersecurity strategy remains more theoretical than operational, or fragmented into isolated goals. The pattern recurs: a Business Continuity Plan approved on paper but never battle-tested; backups scheduled but never restored; a crisis team contact sheet saved inside an email server that just got encrypted. When an incident hits, the organization realizes its plan reflected intent rather than capability.
The second common error is treating a cyber crisis solely as an IT problem. The most consequential crisis decisions are business decisions: shutting down digital services for millions of users, managing media relations, navigating regulatory notifications, and balancing operational recovery against legal evidence preservation. These strategic decisions cannot be improvised at 3:00 AM by an engineer working in isolation without an executive mandate.
The remedy is straightforward: test written procedures and ensure executive decision-makers participate actively in exercises.
20. In closing, what is your vision for cyber resilience in Africa by 2030, and what final message would you leave for leaders preparing for tomorrow’s threats?
ANSWER:
My vision is optimistic, provided key conditions are met.
Four major dynamics are converging leading up to 2030: regional regulatory harmonization, expanding local technical training capacity, the democratization of defensive AI detection capabilities, and increasingly effective regional cyber diplomacy (demonstrated by INTERPOL-AFRIPOL operations). If consolidated, African cybersecurity will transition from being viewed as a cost center into a measurable competitive advantage.
Africa leapfrogged legacy banking infrastructure through mobile technology. The continent can achieve the same leapfrog effect in resilience because we are building modern infrastructure today: we can embed Security by Design rather than retrofitting thirty years of legacy tech debt. That is a distinct advantage provided we seize it now.
My concluding message to executives is captured in the final line of my white paper: Cybersecurity is not an expense to be optimized; it is an investment in operational sovereignty, stakeholder trust, and institutional longevity. Do not wait for a major breach to give your CISO the mandate you will inevitably give them that day under crisis conditions. In Africa, cybersecurity is not a luxury, it is the prerequisite for our digital sovereignty.
Conclusion
We sincerely thank you for your time, your leadership, and your contribution to this essential reflection on the future of cybersecurity in Africa.
Your experience and insights will enable our community of readers – CISOs, CIOs, business executives, IT leaders, cybersecurity professionals, public policy makers, and stakeholders across the African technology ecosystem – to better understand the challenges organizations must prepare for.
We also thank you for your commitment to developing a safer, more resilient, and more reliable African digital ecosystem capable of strengthening the confidence of citizens, businesses, and international investors.




