Executive summary
Cyber risk across African markets is overwhelmingly a governance problem rather than a technology problem. The dominant loss events — business email compromise, ransomware and third-party breach — exploit process gaps, not exotic capability.
This bulletin summarises the quarter's observed activity and translates it into board-level governance actions.
Sources · [2] UCDP · [5] FEWS NET
Full report
Governance actions
Enforce out-of-band verification for all payment instruction changes. Review third-party and partner access quarterly. Test restore-from-backup, not just backup completion. Rehearse incident response with finance and communications in the room, not only IT.
Sources · [4] GDACS · [7] GDELT Project
Key findings
- Business email compromise remains the highest-frequency, highest-loss event type for organisations operating in the region.
- Ransomware operators continue to target public health, education and logistics entities with weak backup discipline.
- Third-party and implementing-partner access is the most common unmanaged pathway into NGO environments.
- Mandatory data protection regimes are maturing faster than most in-country compliance functions.
Analyst assessment
We assess with high confidence that governance-led controls — payment verification, access review, backup testing and incident rehearsal — will prevent more loss than additional security tooling for most organisations in this region.
Related reports
Footnotes & sources
- [1] ACLED — Armed Conflict Location & Event Data — Africa event recordsL1 Conflict · reliability A
- [2] UCDP — Uppsala Conflict Data Program — organised violence datasetL1 Conflict · reliability A
- [3] UN OCHA / ReliefWeb — Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
- [4] GDACS — Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
- [5] FEWS NET — Food security outlooks and alertsL2 Early warning · reliability A
- [6] NASA FIRMS / Copernicus — Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
- [7] GDELT Project — Global media event and tone monitoringL5 Strategic · reliability C
- [8] Institute for Security Studies (ISS Africa) — Regional political and security analysisL5 Strategic · reliability B
- [9] INGO ADVISORY analyst desk — Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
- [10] AlienVault OTX — Open threat exchange indicatorsL4 Cyber · reliability B
- [11] URLhaus / AbuseIPDB — Malicious infrastructure and abuse reportingL4 Cyber · reliability B
- [12] OpenSanctions — Sanctions, PEP and enforcement screening dataL5 Strategic · reliability A
Free operational toolkit
Act on this assessment
Six free operational tools for NGO and charity teams — no sign-up, nothing leaves your browser.
- Travel risk authorisationRisk-tiered approval form with control verification before movement is signed off.
- Vehicle & convoy check13-point pre-departure inspection with go / no-go clearance logic.
- Safeguarding / PSEA referralAnonymised referral log for PSEA and misconduct concerns.
- Cyber hygiene assessmentScored self-assessment producing a prioritised remediation workplan.
- Staff accountability roll callReal-time headcount and status tracking during an incident.
- Endurance calculatorContingency stock planning for water, food, fuel and cash.