Nigeria and the United Kingdom are deepening their cybersecurity partnership to strengthen Nigeria’s capacity to combat AI-driven cyber threats, financial cybercrime and attacks on critical national infrastructure.
Through the UK-funded Africa Cyber Programme and the broader UK-Nigeria Cyber Memorandum of Understanding, both countries have expanded cooperation in intelligence sharing, cyber resilience, digital forensics, policy development and workforce development, positioning Nigeria as one of Africa’s leading cybersecurity hubs.
Stakeholders say the partnership has moved beyond isolated training programmes to become a long-term institution-building initiative designed to leave Nigeria with sustainable local capacity.
The intervention comes as Nigeria’s cyber threat landscape continues to evolve, with financially motivated cybercrime targeting banks and fintech companies remaining the country’s biggest digital security challenge, while ransomware attacks against critical infrastructure, including energy facilities and cloud-hosted services, continue to increase.
In an interview with BusinessDay Newspapers in Abuja, Lawrence Devlin, Head of Counter-Terrorism British High Commission West Africa, noted that the partnership has focused on building the institutional foundations required for Nigeria to independently identify, investigate and respond to cyber threats rather than relying on external support.
A major outcome of the collaboration has been the strengthening of Nigeria’s cyber governance architecture through the review of the National Incident Response Plan, development of cyber maturity frameworks for the protection of Critical National Information Infrastructure and foundational work on the country’s National Digital Forensics Policy framework.
Devlin said these initiatives have significantly improved Nigeria’s ability to standardise digital forensic investigations, ensuring that electronic evidence gathered during cyber investigations can withstand scrutiny in both domestic and international courts.
Another landmark achievement has been the development of highly specialised Nigerian cybersecurity professionals.
“Through the programme, four officers of the National Cybersecurity Coordination Centre (NCCC) became among the first SIM3-certified cybersecurity auditors in Africa. SIM3 is an internationally recognised framework for assessing the maturity of Computer Security Incident Response Teams (CSIRTs), giving Nigeria the ability to independently evaluate and strengthen its cyber incident response capability without depending solely on foreign expertise.
“The programme has also produced Certified Threat Intelligence Managers who are helping shift Nigeria’s cybersecurity posture from reacting to isolated attacks to analysing patterns across multiple incidents, enabling intelligence-led investigations and more proactive responses to emerging threats”, he said.
He described these achievements as evidence of Nigeria’s growing institutional maturity, noting that the country was recognised as the top-performing partner nation under the Africa Cyber Programme.
Sheriff Salawu, Technical Assistant to the National Cybersecurity Coordinator, described the UK partnership as one of Nigeria’s most productive international cybersecurity collaborations.
He said implementation of the bilateral Memorandum of Understanding had been rated above 90 per cent by the National Cybersecurity Coordinator, with the UK also describing the relationship as a model for cooperation across Africa.
According to Salawu, the partnership has strengthened Nigeria’s capacity through internationally recognised certifications, operational support, specialised equipment, intelligence sharing and stronger links with global cybersecurity institutions.
He explained that before the UK’s intervention, Africa had only one or two SIM3-certified auditors, but UK-supported training significantly increased that capacity, improving the continent’s ability to evaluate and strengthen cyber incident response systems.
Beyond technical skills, Salawu said the UK also supported the review of Nigeria’s National Cybersecurity Policy and Strategy, development of the National Incident Response Plan and establishment of the National Digital Forensics Framework.
He added that the partnership has evolved into a genuine exchange rather than a one-sided donor relationship, noting that Nigerian authorities successfully persuaded their British counterparts to incorporate more local expertise into programmes such as the training of prosecutors handling cybercrime cases.
According to him, sustainability has remained central to the partnership from the outset.
“The National Cybersecurity Coordinator made it clear that Nigeria would not accept support that could not be sustained after the programme ended,” Salawu said.
He added that plans are already underway to transfer the knowledge acquired through the UK partnership to other African countries.
“Nigeria has already begun implementing that strategy through regional initiatives such as the Counter Ransomware Initiative, bringing together cybersecurity professionals from countries including Ghana, Senegal, The Gambia, Mozambique, Togo, Chad and Niger to improve intelligence sharing and strengthen regional cyber resilience.
“If we do not improve cybersecurity collectively across Africa, then we are only deceiving ourselves because cyber threats do not recognise national borders,” he said.
While acknowledging the impact of the UK’s interventions, Abdul-Hakeem Ajijola, Chair of the African Union Cyber Security Expert Group (AUCSEG), said the long-term success of such partnerships would ultimately depend on Africa’s ability to build indigenous capacity and strengthen coordination among institutions.
Ajijola described the UK’s cybersecurity interventions as among the most significant by any international partner, particularly at a time when global funding for development programmes has declined.
He noted that British support has contributed to cybersecurity policy development and capacity building across the continent but argued that future investments should increasingly prioritise African ownership.
“Africa today has the talent and capacity to develop its own policies and strategies.
“Funding should increasingly support locally developed solutions so that African countries have ownership while also serving the interests of international partners,” he said.
Ajijola identified coordination rather than technology as Nigeria’s biggest cybersecurity challenge.
Although the Office of the National Security Adviser has established cyber incident reporting platforms, he said they remain underutilised because many organisations lack confidence that reporting incidents will result in support rather than sanctions.
According to him, improving cybersecurity requires stronger collaboration among government agencies, regulators, private companies and the media.
He advocated the establishment of a national council of Chief Information Security Officers (CISOs) to facilitate regular intelligence sharing across sectors and welcomed the Nigerian Communications Commission’s directive requiring telecommunications companies to appoint CISOs and Data Protection Officers.
He also stressed that intelligence sharing should not be limited to governments but should extend to trusted stakeholders, including the media, to improve public awareness without creating unnecessary panic.
Ajijola warned that artificial intelligence-enabled attacks, state-sponsored cyber operations and online disinformation pose greater long-term risks than conventional cyber threats.
“My greatest concern is that we are approaching a stage where people may no longer believe the truth because of the volume of manipulated content online,” he said.
Despite the progress recorded, both the UK and Nigerian cybersecurity experts agree that cyber threats continue to evolve faster than technology, legal frameworks and institutional processes can adapt.
They argue that sustained investment in skilled professionals, stronger institutions, intelligence sharing and international cooperation will remain essential as cybercriminals increasingly exploit artificial intelligence, ransomware and other emerging technologies.
For both, the next phase of cooperation will focus on consolidating the gains already made, expanding technical expertise, strengthening protection for critical infrastructure and ensuring that Nigeria continues to build a resilient, intelligence-driven cybersecurity ecosystem capable of protecting its digital economy.
Join BusinessDay whatsapp Channel, to stay up to date
