African Firms Urged to Prioritize Cybersecurity Governance
New regulatory mandates and a $3 billion loss footprint are forcing companies to elevate security oversight to the board level.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you believe company boards should be held directly accountable for protecting against cyber threats?
Kreston Pedabo issued a report in September 2026 calling for board-level security accountability as cybercrime losses across Africa reached $3 billion since 2019. This advisory follows the introduction of stricter data protection and security mandates in Nigeria and Ghana.
Why it matters
The rapid expansion of digital payments and cloud infrastructure has created a surge in sophisticated fraud, making traditional IT security insufficient. Companies are now moving toward rigorous oversight frameworks to satisfy new compliance standards and mitigate rising ransomware risks.
The KP TRUST framework mandates proactive third-party vendor oversight and periodic security control testing to address vulnerabilities. This shift complements the Nigeria Data Protection Act, which requires mandatory notification of qualifying data breaches within a 72-hour window.
The players
Kreston Pedabo
An advisory and accounting firm providing business oversight frameworks and security guidance for African markets.
Central Bank of Nigeria
The national financial regulator responsible for implementing digital security and self-assessment mandates for the banking sector.
Bank of Ghana
The regulatory body that issued the 2026 Cyber and Information Security Directive for regional financial institutions.
INTERPOL
The international police organization that tracks and coordinates responses to global cybercriminal syndicates.
The details
Organizations are adopting zero-trust security models—a strategy requiring strict identity verification for every person and device accessing network resources—to replace outdated perimeter-based defenses. The Kreston Pedabo approach emphasizes integrating these technical controls directly into corporate governance structures. By formalizing board-level responsibility, firms aim to better manage the risks associated with the increasing frequency of targeted phishing and ransomware campaigns.
Timeline
Since 2019, cumulative financial losses from cybercrime have reached $3 billion.
The Central Bank of Nigeria introduced a Cybersecurity Self-Assessment Tool in March 2026.
Kreston Pedabo published its latest advisory report in September 2026.
The Tech Race
This move toward board-level oversight mirrors global trends seen in the implementation of the General Data Protection Regulation. It marks a departure from treating security as a purely technical concern, forcing African firms to compete on their ability to maintain data integrity under tightening regional directives.
Businesses operating in Nigeria and Ghana must now align internal processes with new mandatory breach reporting timelines and vendor oversight standards. Employees should prepare for more rigorous identity verification workflows as firms accelerate the adoption of zero-trust authentication.
The takeaway
Cybersecurity is shifting from an IT operational task to a mandatory component of corporate governance across Africa. Watch for the 2027 regulatory audits in Nigeria and Ghana to see which industries are successfully meeting the new security threshold.
Further reading
For more on evolving defense strategies, explore the latest Cybersecurity analysis.
Live Poll
Do you believe company boards should be held directly accountable for protecting against cyber threats?






