Nigeria’s digital economy is facing a severe surge in cybercrime with financial losses reaching an estimated N12 billion annually. Data presented by the Nigeria Data Protection Commission at the IoT West Africa Conference 2026 reveals that the country now records over 4,000 cyberattacks weekly. The National Commissioner of the NDPC Dr. Vincent Olatunji noted that while the digital economy contributes nearly 20 percent to the national GDP it remains dangerously exposed due to significant infrastructure and security gaps. He emphasized the shift in the value of information stating “Data is no longer just an asset; it has become critical infrastructure.” Nigeria currently accounts for about 45 percent of reported cybercrime incidents on the continent including phishing ransomware and identity theft targeting financial and telecom platforms.
A major structural challenge remains the country’s heavy reliance on foreign data infrastructure with nearly 90 percent of national data hosted outside Africa. This dependency leads to an estimated $850 million annual expenditure on offshore cloud services creating risks related to regulatory control and national security. Addressing these concerns Olatunji stated “Data sovereignty is not optional. It determines who controls national information, who profits from it, and how secure citizens are in the digital space.” Although Nigeria operates 26 data centers with a combined capacity of 136.7 megawatts regulators argue that this remains insufficient for the scale of emerging technologies like AI and the Internet of Things. Under the Nigeria Data Protection Act 2023 stricter compliance obligations have been introduced including mandatory audits and a 72 hour breach reporting window.
Cybersecurity expert Dr. Peter Obadare warned that rapid digital innovation is widening system vulnerabilities especially within payment infrastructure. He observed that many systems remain exposed due to weak design and poor security implementation rather than advanced techniques. Addressing the friction between developers and regulators he noted “When we talk about regulation, innovators think it is too much. But in cybersecurity, regulation is not excessive, it is necessary.” Industry analysts suggest that threats are evolving from basic fraud to more sophisticated attacks as weak system controls remain a primary enabler for criminals. The NDPC maintains that regulatory and physical infrastructure must evolve quickly to match the pace of digital growth to prevent further economic leakage and protect the sovereignty of Nigerian data.
0 Comments