$3bn cybercrime losses raise business security concerns

Cybercrime. Photo: Investopedia
Mounting cybercrime losses estimated at $3bn across Africa since 2019 are forcing businesses in Nigeria, Ghana and other West African markets to elevate cybersecurity from an operational concern to a boardroom priority, according to Kreston Pedabo.
The accounting and advisory firm stated this in its September 2026 monthly report, which noted that the growing adoption of digital payments, cloud services and electronic invoicing was increasing cyber risks while regulators tightened compliance requirements.
Drawing on INTERPOL’s Africa Cyberthreat Assessment Report 2025, the report said cybercrime represented a medium-to-high share of reported crime in two-thirds of surveyed African countries, rising to about 30 per cent in West and East Africa.
It identified phishing, ransomware, business email compromise and digital sextortion among the continent’s persistent cyber threats, affecting both private companies and public institutions.
The report’s author and Lead, Management Consulting at Kreston Pedabo, Tyna Adediran, said many organisations remained vulnerable because attackers were increasingly exploiting trusted business relationships rather than relying solely on sophisticated technical breaches.
She cited the case of a Ghanaian manufacturing distributor that unknowingly transferred funds to fraudsters after receiving what appeared to be a legitimate payment request from a long-standing supplier whose communications had been secretly monitored for weeks.
According to Adediran, such incidents showed that cyber risk increasingly stemmed from weaknesses in business processes and human decision-making rather than failures of technology alone.
She also said the true scale of cybercrime was likely greater than official figures suggested because many African countries still lacked comprehensive incident-reporting systems, digital evidence repositories and coordinated threat-intelligence infrastructure.
The report said Nigeria had entered a more stringent phase of cybersecurity regulation, with the Central Bank of Nigeria’s Cybersecurity Self-Assessment Tool, introduced in March 2026, reinforcing oversight of financial institutions.
Adediran noted that implementing regulations under the Nigeria Data Protection Act, which require qualifying data breaches to be reported within 72 hours, further indicated that organisations could no longer rely on silence following cyber incidents.
- Nigeria must measure social security impact – Institute
- World Bank pushes digital data platforms for agriculture
- NITDA advocates inclusive AI framework for Nigeria
Drawing on Deloitte’s Nigeria Cybersecurity Outlook 2026, she said ransomware and targeted phishing attacks were expected to intensify as businesses embraced electronic invoicing and real-time transaction reporting.
She added that zero-trust security models and stronger identity verification were becoming increasingly important.
Adediran also cited the ISC2 2025 Cybersecurity Workforce Study, which estimates 4.8 million unfilled cybersecurity positions globally. She said the talent shortage was becoming a significant constraint on organisations’ ability to respond effectively to cyber threats.
In Ghana, the report said regulatory requirements were also placing greater responsibility on company boards.
Adediran noted that the Bank of Ghana’s Cyber and Information Security Directive 2026 places cybersecurity accountability directly on company boards, requires regulated institutions to conduct documented due diligence on third-party vendors with access to their systems, mandates PCI DSS certification for entities handling payment-card data and aligns compliance expectations with internationally recognised standards.
She said the reforms reflected a broader recognition that cybersecurity had become an executive governance issue rather than an operational responsibility confined to technology departments.
The report also cited KPMG’s 2025 Global CEO Outlook, which found that 86 per cent of banking chief executives surveyed identified cybercrime as the greatest long-term threat to organisational prosperity, ahead of artificial intelligence workforce readiness and technology infrastructure costs.
As digital risks increase, Kreston Pedabo recommended what it described as the KP TRUST framework, which encourages organisations to strengthen oversight of third-party vendors, improve board-level reporting, identify hidden system vulnerabilities, strengthen protection against social-engineering attacks and regularly test security controls under realistic conditions.
According to Adediran, organisations that independently verify payment instructions, scrutinise supplier access to critical systems and make cybersecurity a permanent boardroom agenda are more likely to preserve customer confidence as regulatory expectations continue to tighten across West Africa.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.