By Abigail Mbah
Synthesizing insights from Medinatu Musa, National Cybersecurity Thought Leader and regular TV Analyst.
Nigeria current cyber security posture is a clear reflection of disjointed national coordination. Judging by the National Cyber Security Index, (NCSI), that focuses on evaluation of threat prevention and incident management, Nigeria global position is between 40th to 50th out of 160 counties evaluated.
This appears to be a fair position based on frameworks and cyber security governance instrument that Nigeria uses to govern cyber security across the nation. Nigeria can be considered as one of the top leaders in Sub-Saharan Africa. However, as a nationally prominent cybersecurity thought leader Medinatu Musa always emphasizes during some of her public appearances, Nigeria’s fragmented cyber readiness has not translated to strategic international leadership.
The Global Cyber Security Index (GCI) released by the International Telecommunication Union (ITU), ranked Nigeria as a Tier 3 (“Establishing”) nation with a composite score of 82.4 out of 100. Tier 2: Advancing or Tier 1: Role-Modelling (Highest) — Scores 95–100 is achievable. These seven Africa nations are ranked Tier1: Mauritius, Ghana, Tanzania, Kenya, Rwanda, Egypt and Morocco and these four nations are ranked Tier2: South Africa, Zambia, Benin and Togo.
The mid-tier classification can be traced to severe structural vulnerabilities, national governance gaps, fragmented framework, underdevelop capacity and poor execution of strategy and policy compliance deficit. Nigeria can do better.
The key issues preventing Nigeria from global cyber security leadership are recurring points Medinatu Musa always raise, some of which are: fragmented law and regulations, institutional framework, poor compliance campaigns, and a clear gap in national coordination and uniform policy execution across both federal and state tiers. For Instance, it was just on the 19th and 20th of August that the Nigeria Data Protection Commission urged state government tiers to enforce the Nigeria Data Protection Act which was established since 2023.
Whereas, MultiChoice Nigeria was fined ₦766.2 million, Fidelity Bank Plc was fined ₦555.8 million. Zenith Bank Plc, Guaranty Trust Bank (GTBank), First Bank of Nigeria, Wema Bank were fined ₦400 million, paid in June 2024. Multiple Microfinance & Online Lending Apps were fined also but no single Federal and state government MDAs was fined. Whereas, the state governments are just been urged to prioritise compliance to Nigeria Data Protection Act.
Rather than adopting a unified national cyber security authority, cyber security governance is scattered across an uncoordinated maze of ministries, departments and regulatory bodies. The office of the National Security Adviser (ONSA) which is supposed to be in charge of National defense owns and operates the National Cyber Security Coordinating Center (NCCC) and function as the body that manages ngCERT. Nigeria Police Force (NPF) owns the National Cyber Crime Coordinating Center (NCCC).
Simultaneously, regulations and laws ownership, execution and compliance efforts are distributed among the Nigeria Communication Commission (NCC), the Centra Bank of Nigeria (CBN), the Securities and Exchange Commission (SEC), the Nigeria Data Protection Commission (NDPC), Nigeria Information Technology Development Agency (NITDA), Nigeria Ministry of Justice for the National Cybercrime Act, Nigeria Police Force, and the Ministry of Communication, Innovation and Digital Economy.
Regional peers in Africa continent have overtaken Nigeria by having less focus on institutional duplications but prioritises regulatory consolidation. Ghana, Kenya and other five countries have attained UN ITU Tier 1 status, role model status. They have become global benchmarks for digital security leadership. Ghana attained this position by having a centralized Cyber Security Authority (CSA) which was sponsored by their Cybersecurity Act of 2020.
CSA is the single regulatory body that enforces national cyber security controls and ensure a compliance framework is functional. CSA oversee Critical National Information Infrastructure (CNII), risk management, public-private incidents management through Joint Cybersecurity committee. Similarly, Kenya secured its Tier 1 standing by streamlining its National Cybersecurity Strategy under unified technical direction, eliminating inter-agency rivalries, harmonizing threat monitoring mechanisms, and establishing clear operational mandates that accelerate public-private capacity building across its national digital ecosystem.
In Europe, the consolidation of cyber security statutory instruments has directly contributed to a high global cybersecurity ranking. Estonia has been generally recognised as global leaders in digital governance, by extension, cybersecurity governance. Estonia has Information System Authority – RIA (“Riigi Infosüsteemi Amet”) which is the single national governance body for information technology.
The body focuses on incident handling and mandate standardization of security architecture across private sectors. In France, there is National Cybersecurity Agency of France (ANSSI), it is a single but authoritative agency that seats under the oversight of the Prime Minister. ANSSI binds technical security standard, with certifying commercial products and the management of national cyber crisis.
In similar instance, the United Kingdom has National Cyber Security Center (NCSS), this body acts as a single body under GCHQ (Government Communications Headquarters – the UK’s intelligence, security, and cyber agency). NCSC simplified UK national resilience, serving as the sole authority interfacing with businesses, critical national infrastructure operations and the general public. NCSC has developed a national assessment farmwork called Cyber Assessment Framework (CAF). These single governance authority makes these nations secure because they do not have fragmented governance structure like Nigeria.
For Nigeria to advance its global ranking and defeat the current structural deficiency and governance inefficiencies, Nigeria must re-strategize and overhaul its fragmented cybersecurity governance architecture. As Medinatu Musa has advocated in some occasions, during some of this public engagement where she spoke as the national thought leader, the Nigeria federal government must combine all the divergent governance bodies into a single, comprehensive national cyber security body, with a detailed and comprehensive framework that harmonizes all existing sectoral frameworks, regulations, laws, cloud guidelines, guideline for digital forensic investigation operational instrument into one coherent statutory structure.
If immediate compliance efficiency is to be the national goal, Nigeria must avoid the duplicate operational directives, steers, initiatives issued by disparate agencies or bodies like NITDA, NCC, CBN, NDPC, etc. Having these mandates consolidated into a single unified regulatory framework will streamline incident reporting protocols, harmonize cloud technical compliance standards, remove administrative redundancies for private enterprise, and provide international partners with a clear, single point of contact for mutual legal assistance and global cyber threat intelligence sharing.
Technical expertise without unified institutional governance will perpetually trap the nation in mid-tier classifications
To operationalize this unified framework effectively, Nigeria requires an institutional overhaul, centered on statutory consolidation rather than creating unnecessary bureaucratic entities. Establishing a single, independent national cybersecurity agency, a dedicated authority directly modeled after Ghana’s CSA or Estonia’s RIA would dramatically improve the nation’s international index standing.
Rather than attempting to set up a brand-new federal ministry, the federal government should consolidate existing technical units, elevating and merging NITDA’s IT oversight functions, ngCERT’s operational response capabilities, NCCC’s coordination mandates, and law enforcement elements into one empowered statutory body. Granting this single national authority exclusive jurisdiction over Critical National Information Infrastructure (CNII) assurance, cloud security enforcement, information security management systems, AI governance, and cybersecurity professional accreditation will instantly resolve inter-agency turf wars, streamline institutional accountability, and eliminate the systemic paralysis currently hindering national cyber defense.
Ultimately, Nigeria possesses all the necessary raw technical capabilities, high digital adoption rates, and operational expertise required to become a global cybersecurity powerhouse. However, technical expertise without unified institutional governance will perpetually trap the nation in mid-tier classifications. By heeding the strategic blueprint championed by thought leaders like Medinatu Musa, replacing its fragmented web of conflicting agency mandates with a single national framework and an empowered, centralized statutory agency. Nigeria can optimize its threat prevention mechanisms, boost international investor confidence, and secure digital sovereignty. If the federal leadership acts decisively to enforce this institutional consolidation, Nigeria’s national cybersecurity posture will undergo a rapid transformation, successfully propelling the country out of Tier 3 status and directly into the upper ranks of Tier 1 global digital leaders



