Subscribe to our Daily Briefings
HomeDigital TransformationAfrica Companies Face a Growing Cybersecurity Burden as Government Support Lags

Africa Companies Face a Growing Cybersecurity Burden as Government Support Lags

Featured Summary:

  • African companies are increasing cybersecurity spending as attacks expose more business systems
  • High borrowing and operating costs are putting additional pressure on corporate budgets
  • Governments are tightening cybersecurity rules, while public support for implementation remains limited across many markets
  • Smaller businesses face the greatest difficulty funding the security requirements now reaching corporate operations

More African businesses now depend on digital systems to handle payments and customer information.

Mastercard found that 78% of small and medium-sized businesses surveyed across Eastern Europe, the Middle East and Africa regarded protection from cyber threats as a priority. Cybersecurity tools were in use at 42%.

Cybersecurity accounted for 9% of IT budgets among 1,080 organisations surveyed by the European Union Agency for Cybersecurity.

Afritech Biz Hub Daily Briefings — get the week’s Africa business, tech, and finance signals. Sign up here.

Median spending stood at €1.5 million, with large enterprises accounting for most of the organisations surveyed.

Companies across Nigeria, Kenya, Ghana and South Africa disclose far less about cybersecurity spending.

Large institutions advertise security positions and award contracts for specialist services, while company-wide figures for cybersecurity budgets are rarely published.

In Nigeria, 69% of SMEs surveyed by Mastercard this year were seeking credit for expansion. Cybersecurity spending is being added to businesses already financing their wider operations.

More corporate activity is moving online while the cost of protecting it is becoming part of the company budget.

Government policy is expanding around cybersecurity as well, raising a separate question over how much of that cost companies are expected to carry themselves.

Cybersecurity Is Competing With Africa’s High Cost of Doing Business

Companies in low- and middle-income economies pay about two percentage points more in real interest than comparable businesses in advanced economies, according to World Bank research published in June.

Credit is particularly difficult to obtain for smaller Nigerian businesses. Fewer than one in 20 micro, small and medium-sized enterprises have access to bank credit.

The World Bank says loans are often expensive and short-term, while collateral requirements keep many firms outside formal lending.

Electricity presents a different problem. World Bank enterprise data show that 74.6% of Kenyan firms experienced power outages in 2025.

The latest survey for Ghana put the figure at 73.8%. Businesses that require continuous power must absorb the disruption or pay for alternative supply.

South Africa has gone about a year and a half with little load shedding, easing one source of pressure on companies.

Problems with electricity infrastructure, freight and water have nevertheless raised business costs and weakened investment, according to the World Bank. A $1.5 billion programme approved this year is funding reforms in those areas.

None of these figures shows companies cutting cybersecurity budgets to cover loans or electricity.

They establish a different point: spending on cybersecurity is being added to businesses already paying for unreliable infrastructure and relatively expensive finance.

Cyber Regulation Is Expanding Without Setting Technology Pay

Nigeria’s Data Protection Act places responsibility on companies for the personal information they collect and use, including measures to prevent unauthorised access, loss or disclosure.

Banks and other regulated financial institutions face additional requirements around the technology used to store information and deliver digital services.

Lagos State’s 2026 cybersecurity guidelines give businesses more detail on how that protection should be organised.

Enterprises are advised to appoint security and data-protection officers, monitor their systems for threats and involve boards in cybersecurity oversight.

Incidents covered by the national data-protection framework must be reported within the applicable 72-hour period.

These obligations require companies to put people and technology behind cybersecurity compliance, but the rules do not establish what those employees should earn.

Businesses still set compensation when recruiting the staff responsible for operating security systems and meeting regulatory requirements.

South Africa provides a similar distinction on wages. Its national minimum wage increased to R30.23 an hour on March 1, 2026, setting a general wage floor for workers covered by the legislation.

Cybersecurity professionals do not have a separate statutory salary floor based on their occupation.

African governments can require companies to meet cybersecurity standards without setting salaries for the specialists employed to meet them.

Regulation raises the obligations placed on businesses, while the cost of recruiting cybersecurity staff remains part of the company’s employment budget.

Stronger Cyber Rules Run Into a More Expensive Business Environment

External public-debt service absorbed 18% of government revenue across Sub-Saharan Africa in 2025, up from 9% in 2017, according to the World Bank. Public capital investment remained about 20% below its 2014 level.

The World Bank’s June economic outlook identified high financing costs and unreliable infrastructure among the constraints on private investment in developing economies.

Governments are dealing with those conditions while spending on public services and meeting existing debt obligations.

Cybersecurity regulation adds requirements for the private sector, but the companies covered by those rules vary considerably in size and financial capacity.

Large banks and telecommunications companies run extensive digital operations, while smaller businesses may rely on outside providers for technology and security services.

That difference is not reflected in a single measure of what African companies can afford to spend on cybersecurity.

Regulations establish the security obligations businesses must meet, while the cost of meeting them remains with companies operating under very different financial conditions.

Africa’s Cybersecurity Bill Is Being Split Between Companies and Governments

Kenya launched a €3 million cyber-resilience programme in January with funding from the European Union.

The three-year project involves government agencies responsible for cybercrime coordination and incident response.

Nigeria’s Small and Medium Enterprises Development Agency provides cybersecurity training and free security tools to smaller businesses through its digital programmes.

The National Cybersecurity Training Institute also trains professionals working in cybersecurity and critical infrastructure.

South African organisations recorded an average data-breach cost of R44.1 million in 2025, compared with R53.1 million the previous year.

Detection and escalation accounted for R17.5 million, lost business for R13.1 million and post-breach response for R12.54 million.

Financial companies recorded an average breach cost of R70.2 million. The underlying research also found lower breach costs among organisations using security automation extensively.

Government programmes can provide training and national cyber infrastructure before an attack occurs. Once a company is breached, the losses move directly onto its balance sheet.

Gideon Omojaunfo
Gideon Omojaunfo
Gideon Omojaunfo covers Africa’s business, technology and financial markets, with a focus on macroeconomic policy, capital flows and FX regimes. His analysis examines structural reform, digital infrastructure and investment risk across the continent.
RELATED ARTICLES

Most Popular

Recent Comments