
Cybersecurity: African countries must invest $4.2 billion a year to improve their resilience (report)
July 19th 2023
The report reveals that Africa records direct losses estimated at 3.5 billion dollars each year due to cyberattacks. And billions more due to missed business opportunities arising from reputational damage.
Africa needs to mobilize around $4.2 billion a year in additional investment in cybersecurity to improve its resilience to cyberattacks which are becoming more numerous, more varied and more dangerous amid accelerating transformation on the continent, according to a report published on June 20 by the American strategy consulting firm Kearney.
Entitled ” Cybersecurity in Africa- a call to Action “, the report specifies that this amount represents approximately 0.25% of the continent’s cumulative GDP. This ratio of investment to GDP corresponds to the average level of expenditure made in the field of cybersecurity in mature markets such as the United States, the United Kingdom and Germany.
With annual expenditure estimated at 0.19% of its GDP, only South Africa comes close to the level of investment recorded in mature markets. In North African countries, investments in cybersecurity represent on average only 0.06% of GDP. This rate is even lower in sub-Saharan African countries excluding South Africa (0.03% of GDP).
The size of the African cybersecurity market was valued at $2.5 billion in 2020. It is expected to reach $3.7 billion by 2025, representing an average annual growth rate of 7.9%.
Yet the rapid adoption of information and communication technologies and the growing strategic importance of the continent make it a prime target for cybercriminals.
Africa also records direct losses estimated at 3.5 billion dollars per year due to these attacks, not to mention the missed business opportunities resulting from reputational damage. These colossal losses indicate a low level of cyber-resilience.
Cyberattacks are still perceived as a technical problem
African businesses still perceive cyberattacks as a purely technical problem rather than a factor that can affect their revenues.
The nascent cybersecurity market on the continent also faces a dearth of local capacity and expertise. The products and solutions offered to companies are often fragmented, due to the lack of total solution providers.
The report further underlines that the number, intensity and complexity of cyberattacks targeting Africa are expected to increase significantly in the coming years. Several factors expose the continent to an increase in cyber threats.
The growing interconnectedness and increased movement of people, goods and information on a continental scale, facilitated by the entry into force of the African Continental Free Trade Area (AfCFTA), will intensify systemic risk.
Widespread socio-economic hardship, which has been accelerated by the Covid-19 pandemic, food crisis and inflation, should also continue to foster a sustained pattern of underinvestment.
On the other hand, countries’ reluctance to share threat intelligence, often due to mistrust and lack of transparency, will make cyber defense mechanisms even more porous.
And last but not least, threat monitoring has become more complex, due in part to the rise of encryption and multi-cloud operations, the proliferation of interconnected Internet of Things devices, and the convergence of operational technologies. and computing environments.
In addition to increased spending on cybersecurity, the report recommends African countries adopt collaborative approaches to address the expected rise in cyberattacks by ratifying the African Union Convention on Cybersecurity and Personal Data Protection. to which only 13 countries have so far joined, by stepping up the training of cybersecurity experts and encouraging the sharing of threat intelligence and the development of regional public-private partnerships (PPPs) and industry alliances.
Source: Agence Ecofin Back