By Nkiruka Aimienoho

A subtle anomaly. An unpopular call to isolate critical systems. Resistance from every direction. That decision, made years ago with a key stakeholder during a live cybersecurity incident I was managing as a consultant, looked excessive at the time. It turned out to be the difference between a contained event and a ransomware attack that could have crippled operations for weeks. The lesson has never left me: resilience is decided in the moments before certainty arrives, when leaders must act on incomplete information, ahead of the crisis, not after it.

I’ve since sat in boardrooms across banking, telecoms, energy, and FMCG, watching organisations struggle not because attackers were unstoppable, but because the hard decisions had never been rehearsed. As Nigeria’s digital economy, and Africa’s with it, races ahead on instant payments, mobile banking, and digital lending, that lesson has only sharpened. Cybersecurity can no longer be viewed as a back-office technology concern. It has become a trust issue, a financial stability issue, and a board-level business priority.

Cyber Risk Is Now Systemic

No organisation is immune, and the threat is no longer local. INTERPOL’s Operation Red Card, run across 16 African countries between late 2025 and early 2026, led to 651 arrests and uncovered roughly $45 million in losses affecting 1,247 victims. Its message was blunt: African cybercrime is now organised, platform-enabled, and coordinated across borders. Meanwhile, crime itself has industrialised. Phishing kits, ransomware tools, and stolen credentials are now available as a service, collapsing the barrier to entry even as attack sophistication rises. Increasingly, criminals don’t need to break in. They simply log in, exploiting weak identity controls and misplaced trust. Cybercriminals innovate faster than most organisations.