Many small and medium-sized businesses in Nigeria think about cybersecurity as something only big corporations and government agencies have to prioritise. In reality, because small businesses form the backbone of Nigeria’s economy and often have weaker defenses, they are the easiest targets for cybercriminals.
The scale of the cybersecurity threat facing Nigerian businesses is staggering and growing every day, driven by the rapid digitization of the Nigerian economy, the increasing sophistication of cybercriminals, and the pervasive lack of cybersecurity awareness and investment among Nigerian businesses.
Managing cyber risks has become a big part of building a business today. Regardless of the size of your business, you must incorporate cybersecurity strategies that would protect your business from cyberattacks that could lead to financial ruin, reputational damage, or total operational collapse.
Common Cyber Threats Targeting Businesses
Understanding the threat landscape is the first step towards protecting yourself. Hence, it is important to identify some of the most common threats that businesses face today.
- Business Email Compromise (BEC)
Business Email Compromise (BEC) targets people, not technology. By hacking or impersonating legitimate accounts, attackers trick employees into diverting funds or sharing sensitive data.
BEC bypasses technical security by exploiting human trust, losses from BEC exceed billions of dollars annually, and Nigeria is both a major source and a major victim of BEC attacks.
- Ransomware
Ransomware is a rapidly growing threat to businesses. In a ransomware attack, criminals use malware to encrypt a company’s files, databases, and systems, rendering them completely inaccessible, and then demand a ransom payment, usually in cryptocurrency in exchange for the decryption key.
Ransoms range from hundreds of thousands to billions of naira, yet paying never guarantees data recovery. Beyond the immediate extortion, the operational downtime often leads to lost revenue, regulatory fines, and long-term reputational damage.
- Distributed Denial of Service (DDoS)
Malicious actors flood company servers or websites with overwhelming traffic, causing system crashes and severe service disruptions.
The Nigeria Computer Emergency Response Team (ngCERT) warns that a sustained wave of Distributed Denial-of-Service (DDoS) attacks are increasingly threatening Nigeria’s critical digital infrastructure, with both public and private sector organisations under heightened risk.
- Phishing Attacks
Fraudulent emails, text messages, or websites designed to trick people into revealing passwords, financial information, or other sensitive data is another common entry point for virtually all types of cyber attacks, including BEC and ransomware.
Nigerian businesses are particularly vulnerable to phishing because of low levels of cybersecurity awareness among employees, the widespread use of personal email accounts and devices for work purposes, and the general culture of clicking on links and opening attachments without verifying their legitimacy.
I have only highlighted the above as they are the most common forms of cyberattacks targeting businesses. There are other examples of cyber attacks targeting businesses such as Supply Chain Attacks, and SQL Injection & Zero-Day Exploit among others.
Why Small and Medium Businesses Are the Most Vulnerable
There is a dangerous misconception that cybercriminals only target large corporations because that is where the big money is. This could not be further from the truth.
Small and medium-sized businesses are disproportionately targeted by cybercriminals precisely because they tend to have weaker security defences, less cybersecurity awareness, and fewer resources for incident response and recovery.
A cybercriminal might not be able to steal a billion naira from a single business, but they can steal ten million naira each from a hundred small businesses with a fraction of the effort it would take to breach a major bank or telecom company.
According to Kaspersky, 86% of small and medium sized businesses encountered cybersecurity incidents over the past year. The average cost of a cyber attack for a small business is often enough to threaten the viability of the entire enterprise.
In the Nigerian context, where most businesses operate with thin profit margins, limited cash reserves, and no cyber insurance, a single significant cyber attack can be an extinction-level event forcing the business to close permanently because it simply cannot absorb the financial loss or recover from the operational disruption.
The vulnerability of Nigerian SMEs is compounded by several factors that are specific to the Nigerian business environment. First, most Nigerian SMEs do not have dedicated IT staff, let alone cybersecurity specialists. Technology decisions are often made by the business owner or a generalist office manager who may have basic computer skills but no expertise in cybersecurity.
Second, the rapid digitization of Nigerian businesses driven by mobile payments, online banking, e-commerce, cloud computing, and social media marketing has dramatically expanded the attack surface for cybercriminals without a corresponding increase in security awareness and investment.
A small business owner who used to operate entirely in cash and paper now has a POS terminal, a mobile banking app, an Instagram business account, a WhatsApp business number, and a cloud-based accounting system, each of which represents a potential entry point for cybercriminals.
Third, the BYOD (Bring Your Own Device) culture that is prevalent in many small Nigerian businesses creates significant security risks because employees are accessing sensitive business data and systems from personal phones and laptops that may be infected with malware, connected to unsecured public Wi-Fi networks, or shared with family members and friends.
The Human Factor: Your Employees Are Your Biggest Security Vulnerability
Cybersecurity professionals have a saying: humans are the weakest link in the security chain, and this is especially true in the Nigerian context where cybersecurity awareness and training are virtually non-existent in most organizations.
Think about how many times a day your employees click on links in emails without checking where they lead, open attachments from unknown senders, use the same password for their personal email, their bank account, and their work systems, share sensitive business information over WhatsApp without encryption, connect to public Wi-Fi at hotels, airports, and coffee shops while accessing company systems, and leave their laptops unlocked and unattended in public spaces.
Each of these behaviours represents a potential security breach waiting to happen, and in an organization with dozens or hundreds of employees all engaging in these risky behaviours simultaneously, it is only a matter of time before a cybercriminal exploits one of these vulnerabilities.
The solution is not to blame your employees but to train them. Cybersecurity awareness training should be a mandatory, regular, ongoing programme in every business, regardless of size or industry. The training does not need to be expensive or complicated. There are numerous free and low-cost cybersecurity awareness resources available online.
What matters is that the training is consistent, practical, and reinforced through regular reminders, simulated phishing exercises, and a culture where cybersecurity is treated as everyone’s responsibility, not just the IT department’s problem.
The business owner or CEO must lead by example, demonstrating good cybersecurity practices and making it clear that security is a priority. If the CEO is using ‘12345’ or thinks they are being clever by having “password” as their email password and clicking on every link that promises a free iPhone, you cannot expect the intern to be more security-conscious.
Cybersecurity culture starts at the top and flows down through the organization, and until Nigerian business leaders take personal responsibility for cybersecurity, their employees will continue to be the easiest target for cybercriminals.
The Regulatory Landscape: What Nigerian Businesses Need to Know
The regulatory landscape for cybersecurity and data protection in Nigeria has evolved significantly in recent years, and Nigerian businesses that are not paying attention to these developments are exposing themselves to significant legal and financial risk.
The most important piece of legislation is the Nigeria Data Protection Act (NDPA), which was signed into law in June 2023 and establishes a comprehensive legal framework for the protection of personal data in Nigeria.
The NDPA applies to all organizations that process personal data of individuals in Nigeria, regardless of the size of the organization or where the data processing takes place, and it imposes strict obligations on data controllers and processors regarding how personal data is collected, stored, used, shared, and secured.
Organizations that violate the NDPA can face fines of up to two percent of their annual gross revenue or ten million naira, whichever is greater, and individuals whose data rights are violated can sue for compensation.
The NDPA also requires organizations to implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction. In other words, cybersecurity is no longer just a best practice in Nigeria, it is a legal requirement.
Beyond the NDPA, there are sector-specific cybersecurity regulations that Nigerian businesses need to be aware of. The Central Bank of Nigeria (CBN) has issued comprehensive cybersecurity frameworks and guidelines for banks and other financial institutions, requiring them to implement specific security controls, conduct regular penetration testing, maintain incident response plans, and report cyber incidents within specified timeframes.
The Nigerian Communications Commission has similar requirements for telecom operators and internet service providers. The Securities and Exchange Commission has issued cybersecurity guidelines for capital market operators. And various industry regulators are increasingly incorporating cybersecurity requirements into their licensing and compliance frameworks.
For Nigerian businesses that operate in multiple sectors or that process data across borders, the regulatory compliance burden can be significant, and failure to comply can result in fines, licence revocations, and reputational damage.
The message is clear: the Nigerian government and its regulatory agencies are taking cybersecurity seriously, and businesses that do not keep pace with the evolving regulatory landscape will face consequences. Cybersecurity and regulatory compliance are two hands that must work together, and Nigerian businesses need to invest in both to protect themselves from the dual threats of cybercriminals and regulatory sanctions.
Building a Cybersecurity Strategy on a Budget
I know what many Nigerian business owners are thinking right now: ‘All of this sounds important, but I am running a business with tight margins in a harsh economic environment, and I cannot afford to hire a team of cybersecurity experts or buy expensive security software.’
I hear you, and I understand the challenge, but here is the thing: you cannot afford NOT to invest in cybersecurity, because the cost of a single successful cyber attack will almost certainly be far greater than the cost of basic security measures that could have prevented it.
The good news is that building a baseline cybersecurity posture does not require a massive budget. It requires awareness, discipline, and a commitment to implementing basic security hygiene that will protect your business from the vast majority of common cyber threats.
First, implement multi-factor authentication on every account that supports it —email, banking, cloud services, social media, everything. Multi-factor authentication, or MFA, requires users to provide more than one form of verification to access an account, typically a password plus a code sent to their phone or generated by an authenticator app.
Multi-factor authentication is free or very low cost for most services, and it can be set up in minutes. There is absolutely no excuse for any business not to have MFA enabled on all critical accounts.
Second, ensure that all your software, operating systems, and applications are kept up to date with the latest security patches. Many cyber attacks exploit known vulnerabilities in software that have already been patched by the vendor but not yet applied by the user. Keeping your systems updated is free and takes minimal time but provides enormous protection against a wide range of attacks.
Third, implement a robust backup strategy. Back up your critical business data regularly, daily if possible and store backups in a separate location from your primary systems, ideally in the cloud using a reputable service provider like Google Workspace, Microsoft 365, or AWS. If your systems are hit by ransomware, having a recent backup means you can restore your data without paying the ransom.
Additionally, use strong, unique passwords for every account and use a password manager to keep track of them. Password managers like Bitwarden and 1Password generate and store complex passwords so your employees do not have to remember them or resort to using the same weak password everywhere.
Furthermore, install and maintain reputable antivirus and anti-malware software on all devices used for business purposes, including personal devices used for work. Finally, secure your Wi-Fi networks with strong passwords and encryption, and use a VPN when accessing business systems from public networks.
These measures form the foundation of a basic cybersecurity strategy that will protect your business from the vast majority of common cyber threats, and they can all be implemented for less than a hundred thousand naira per month if you are opting for paid options. That is less than the cost of a single stolen payment, and it is a fraction of what you will lose if you become a victim of cybercrime.
The Role of Cyber Insurance in Protecting Nigerian Businesses
One area of cybersecurity preparedness that is still largely unknown or ignored by Nigerian businesses is cyber insurance.
Cyber insurance is a type of insurance policy that covers the financial losses and costs associated with cyber attacks and data breaches, including the cost of incident response, data recovery, business interruption, legal defence, regulatory fines, and even ransom payments in some cases.
In mature markets like the US, UK, and Europe, cyber insurance has become a standard part of business risk management, with a significant percentage of businesses carrying some form of cyber insurance coverage.
In Nigeria, cyber insurance is still in its infancy, with few insurance companies offering dedicated cyber insurance products and very few businesses purchasing them. However, this is expected to change as the frequency and severity of cyber attacks increase and as regulatory requirements for data protection and cybersecurity become more stringent.
Insurance companies like Custodian Investment PLC, AXA Mansard, Leadway Assurance, and a handful of others have begun offering cyber insurance products tailored to the Nigerian market, and I expect the availability and uptake of cyber insurance to increase significantly in the coming years.
Please note, cyber insurance is not a substitute for good cybersecurity practices. Insurance companies typically require policyholders to demonstrate that they have implemented basic security measures as a condition of coverage, and claims may be denied if the business is found to have been negligent in its cybersecurity practices.
However, even the best cybersecurity measures cannot guarantee one hundred percent protection against all threats, and cyber insurance provides a financial safety net that can mean the difference between recovering from an attack and going out of business.
For Nigerian businesses, especially those that handle sensitive customer data, process financial transactions, or operate in regulated industries, cyber insurance should be a serious consideration as part of their overall risk management strategy.
The cost of cyber insurance varies depending on the size of the business, the industry, the level of coverage, and the security measures in place, but for most businesses, the premiums are likely to be affordable relative to the potential financial impact of an uninsured cyber attack.
The smart Nigerian business owner is the one who prepares for the worst while hoping for the best, and cyber insurance is a critical part of that preparation. Talk to your insurance provider about cyber coverage, understand what is available in the Nigerian market, and make an informed decision about whether cyber insurance is right for your business.
What the Nigerian Government Must Do to Improve the National Cybersecurity Posture
While individual businesses have a responsibility to protect themselves from cyber threats, the Nigerian government also has a critical role to play in improving the country’s overall cybersecurity posture.
The government’s efforts so far including the establishment of the Nigerian Computer Emergency Response Team (ngCERT), the passage of the Nigeria Data Protection Act, and the issuance of various sector-specific cybersecurity guidelines are commendable but insufficient given the scale and pace of the cyber threat.
First, the government needs to invest significantly in building the country’s cybersecurity workforce. Nigeria has a severe shortage of qualified cybersecurity professionals, and the few that exist are being actively recruited by companies in Europe, North America, and the Middle East, where salaries are many times higher than what Nigerian employers can offer.
The government should fund cybersecurity education programmes at universities and institutes, establish scholarships and bursaries for students pursuing cybersecurity degrees and certifications, and create incentives for Nigerian cybersecurity professionals to work in Nigeria rather than emigrating.
The global cybersecurity workforce shortage stands at an estimated 4.8 million unfilled positions, driven by rising demand, AI-driven threats, and budget pressures. Nigeria needs to act decisively to ensure it is producing enough skilled professionals to protect its rapidly digitizing economy.
Second, the government needs to strengthen the capacity of law enforcement agencies to investigate and prosecute cybercrime. The Economic and Financial Crimes Commission (EFCC) and the Nigeria Police Force have made efforts to combat cybercrime, but their capacity is limited by inadequate technical expertise, insufficient funding, outdated equipment, and jurisdictional challenges that arise when cybercriminals operate across national borders.
International cooperation is essential, and Nigeria needs to strengthen its partnerships with foreign law enforcement agencies and international organizations like INTERPOL and the AFRIPOL to improve its ability to track, apprehend, and prosecute cybercriminals.
Third, the government should provide tax incentives and financial support for Nigerian businesses that invest in cybersecurity, recognizing that improving the cybersecurity posture of individual businesses contributes to the national cybersecurity of the entire country.
Tax deductions for cybersecurity investments, subsidized cybersecurity training programmes for SMEs, and government-funded cybersecurity resources and tools for small businesses would all help to raise the baseline level of cybersecurity across the national economy.
The Nigerian government must watch over its digital economy with the same vigilance it applies to physical security, because the threats in cyberspace are just as real and potentially even more devastating than the threats on the streets.
Final Thoughts — Act Now not After the Attack
I want to close this piece with a direct, urgent appeal to every business owner, CEO, managing director, and executive who reads this: the time to take cybersecurity seriously is now, not after you have been attacked, not after you have lost millions of naira to cybercriminals, not after your customers’ data has been exposed, and definitely not after your business has been crippled by ransomware.
The threats are real, they are growing, and they are targeting businesses exactly like yours, not because you are special but because you are vulnerable. The good news is that the most effective cybersecurity measures are not expensive, complicated, or time-consuming to implement. Basic security hygiene will protect you from the vast majority of cyber threats.
The cost of prevention is always, ALWAYS lower than the cost of recovery, and in many cases, there is no recovery because the damage from a major cyber attack is simply too great for the business to survive.
August 8, 2026
Isreal Oyarinde
Why Nigerian Customer Service Is an Oxymoron: The Anti-Customer Economy
Customer service is supposed to help you resolve whatever issues you may have with a customer and potentially save you time, energy, and money. Unfortunately, customer service is sometimes designed to make you accept a bad product or service so that you don’t end up losing more than you already did. We have all been there. And it does not matter what the service is, the experience is almost uniform; at the bank, at the telecom office, at the passport office, at the airline counter, at the hospital reception. You walk in as a paying customer, and you are treated like a beggar asking for free rice at a politician’s rally. You are shuffled around, or worse ignored, insulted, lied to, and made to feel like you should be grateful they even acknowledged your existence. Businesses have normalised treating paying customers like garbage and I am sick of it. I am concerned about this issue not just as a customer who wants full value for their money but also as an entrepreneur who wants the business ecosystem to be driven by excellence and not just an acceptance of “quality mediocrity”. The ‘Take It or Leave It’ Mentality: Where Did This Come From? According to a PwC survey on customer experience, 73% of consumers globally say customer experience is a key factor in their purchasing decisions. If customer experience is so important, why are businesses choosing to ignore it? We live in a country where businesses seem to be actively punishing you for being their customer. Welcome to the anti-customer economy. To understand why Nigerian customer service is the way it is, you have to understand the psychology behind it. And that psychology is rooted in scarcity and a culture of deference to any semblance of authority. For decades, Nigeria has operated as a scarcity-driven economy. There were not enough goods, not enough services, not enough infrastructure. When you are the only person selling bread in a village of five thousand hungry people, you do not need to smile or say ‘please’ or ‘thank you.’ That scarcity mindset never left. Even as the economy grew, even as competition entered certain sectors, the fundamental attitude of Nigerian business owners and their staff remained the same. The business believes they are doing you a favour by existing and the customer has simply learned to accept this dynamic as normal. This mentality pervades every type of business across every sector. From the woman selling tomatoes at Mile 12 who will curse you out for asking for a discount, to the multinational bank that will make you wait three hours to resolve an error they created. The attitude is the same: take it or leave it. And because Nigerians have been conditioned to take it, businesses have had zero incentive to change. The Monopoly Effect: Why Competition Alone Cannot Fix This The standard economic argument is that competition fixes customer service. When customers have choices, businesses that treat them poorly lose them to competitors that treat them better. This is a beautiful theory that works in countries with functional market structures. In Nigeria, it collapses for several reasons. First, many sectors have oligopolies, not true competition. If there is one industry that perfectly encapsulates everything wrong with Nigerian customer service, it is telecommunications. These companies have over 200 million subscribers combined, and they treat every single one of them like disposable waste. The Nigerian Communications Commission publishes subscriber data showing massive numbers, but nobody publishes the millions of hours Nigerians waste every year trying to get basic issues resolved with their network providers. The telecom sector has four major players, all of whom provide equally terrible customer service. Switching from MTN to Airtel because of bad customer service is like jumping from a frying pan into a different frying pan. The pan is a slightly different colour, but the heat is exactly the same. Banks? Same thing. There are over twenty commercial banks in Nigeria, and the customer service difference between them ranges from ‘bad’ to ‘slightly less bad.’ There is no bank that has genuinely cracked the code of consistent, excellent customer service across all touchpoints. Second, switching costs are artificially high. Porting your phone number is a bureaucratic nightmare. Changing banks requires updating direct debits, salary accounts, BVN linkages, and a dozen other things that make the process so painful that most people simply endure the devil they know. These switching costs are not accidental. They are designed to trap customers in relationships they would otherwise leave. Third, and this is the most important point, competition only drives better service when customers actually punish bad service by leaving. Nigerian customers have been so thoroughly beaten down by decades of terrible treatment that they have developed a form of learned helplessness. They do not expect good service. They do not demand it. According to Harvard Business Review, acquiring a new customer costs five to twenty-five times more than retaining an existing one. Nigerian businesses have not internalized this data because they have never had to. In an economy where customers do not leave, retention is free. And when retention is free, investing in customer service is seen as an unnecessary cost, not a competitive advantage. Government Agencies: The Undisputed Champions of Anti-Customer Service If Nigerian private sector customer service is bad, government agencies are on a different level entirely. The undefeated champions of terrible service delivery. At least with a private business, there is a theoretical possibility that a competitor could emerge and steal their customers. With government agencies, you have no choice. You cannot get your passport from a private company. You cannot register your business with an alternative CAC. You cannot get your driver’s license from a competitor. They have a monopoly on the services you need. They know it and they behave accordingly. The Nigeria Immigration Service passport application process is a masterclass in institutional contempt for citizens. You pay online, you book an appointment, you show up on time,