Skip to content
Securing 2027 elections: Convergence of physical and cyber defences needed

Securing 2027 elections: Convergence of physical and cyber defences needed

Punchng • October 9, 2026

Securing Nigeria’s 2027 elections will require a convergence of physical and cybersecurity defences capable of mitigating threat elements to the elections that span both physical and cyber domains. While election planning has traditionally focused on physical security, the digital domain is now equally critical, and the two must be integrated if Nigeria is to maintain a mature level of security preparedness for the elections. Current threat estimates show both physical and cyber threats to be at varying assessed levels that, if not adequately mitigated, will affect the Independent National Electoral Commission’s ability to conduct free, fair and credible elections in Nigeria in January and February 2027. The physical security challenges are complex and multifaceted and include terrorism and insurgency, banditry, gang violence and cultism, and armed ethnic militias, among others. According to data from Beacon Security and Innovations Limited, a company I founded and run, and the international platform Armed Conflict and Event Location Data, from January to September 2026, an average of 700 people are killed and another 500 abducted monthly across Nigeria, despite ongoing security forces operations that have successfully targeted and killed a significant number of the leadership of the violent actor groups operating in Nigeria. This is even as livelihoods continue to be destroyed by these threat actors, with huge humanitarian and development consequences for communities where they remain active. Similarly, Nigeria’s cyberspace faces numerous institutional and structural challenges that manifest as diverse threats as the country increasingly digitises its election infrastructure for the scheduled January and February 2027 national elections. Nigeria is currently facing an average of 4,906 cyberattacks per organisation every week, more than twice the global average of 2,422, and a 45 per cent year-on-year increase, according to Check Point Research’s August 2026 threat intelligence. That volume eased only slightly from 4,975 weekly attacks in July, and leaves Nigeria second only to Angola among the African markets tracked. Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5bn in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192m in 2024 to $484m. The measurable losses are concentrated in payments: banks and customers lost N52.26bn to fraud in 2024 and N25.85bn in 2025, for a cumulative N134.48bn between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at N1.1tn between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain. In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public. National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the general elections vulnerable to the very syndicates and state- actors currently probing our physical and cyber networks. Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right, and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed. Dr Kabir Adamu is the Managing Director of Beacon Security and Innovations Ltd

The physical security challenges are complex and multifaceted and include terrorism and insurgency, banditry, gang violence and cultism, and armed ethnic militias, among others. According to data from Beacon Security and Innovations Limited, a company I founded and run, and the international platform Armed Conflict and Event Location Data, from January to September 2026, an average of 700 people are killed and another 500 abducted monthly across Nigeria, despite ongoing security forces operations that have successfully targeted and killed a significant number of the leadership of the violent actor groups operating in Nigeria. This is even as livelihoods continue to be destroyed by these threat actors, with huge humanitarian and development consequences for communities where they remain active. Similarly, Nigeria’s cyberspace faces numerous institutional and structural challenges that manifest as diverse threats as the country increasingly digitises its election infrastructure for the scheduled January and February 2027 national elections. Nigeria is currently facing an average of 4,906 cyberattacks per organisation every week, more than twice the global average of 2,422, and a 45 per cent year-on-year increase, according to Check Point Research’s August 2026 threat intelligence. That volume eased only slightly from 4,975 weekly attacks in July, and leaves Nigeria second only to Angola among the African markets tracked. Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5bn in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192m in 2024 to $484m. The measurable losses are concentrated in payments: banks and customers lost N52.26bn to fraud in 2024 and N25.85bn in 2025, for a cumulative N134.48bn between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at N1.1tn between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain. In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public. National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the general elections vulnerable to the very syndicates and state- actors currently probing our physical and cyber networks. Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right, and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed. Dr Kabir Adamu is the Managing Director of Beacon Security and Innovations Ltd

Similarly, Nigeria’s cyberspace faces numerous institutional and structural challenges that manifest as diverse threats as the country increasingly digitises its election infrastructure for the scheduled January and February 2027 national elections. Nigeria is currently facing an average of 4,906 cyberattacks per organisation every week, more than twice the global average of 2,422, and a 45 per cent year-on-year increase, according to Check Point Research’s August 2026 threat intelligence. That volume eased only slightly from 4,975 weekly attacks in July, and leaves Nigeria second only to Angola among the African markets tracked. Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5bn in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192m in 2024 to $484m. The measurable losses are concentrated in payments: banks and customers lost N52.26bn to fraud in 2024 and N25.85bn in 2025, for a cumulative N134.48bn between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at N1.1tn between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain. In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public. National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the general elections vulnerable to the very syndicates and state- actors currently probing our physical and cyber networks. Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right, and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed. Dr Kabir Adamu is the Managing Director of Beacon Security and Innovations Ltd

Nigeria is currently facing an average of 4,906 cyberattacks per organisation every week, more than twice the global average of 2,422, and a 45 per cent year-on-year increase, according to Check Point Research’s August 2026 threat intelligence. That volume eased only slightly from 4,975 weekly attacks in July, and leaves Nigeria second only to Angola among the African markets tracked. Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5bn in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192m in 2024 to $484m. The measurable losses are concentrated in payments: banks and customers lost N52.26bn to fraud in 2024 and N25.85bn in 2025, for a cumulative N134.48bn between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at N1.1tn between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain. In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public. National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the general elections vulnerable to the very syndicates and state- actors currently probing our physical and cyber networks. Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right, and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed. Dr Kabir Adamu is the Managing Director of Beacon Security and Innovations Ltd

Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5bn in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192m in 2024 to $484m. The measurable losses are concentrated in payments: banks and customers lost N52.26bn to fraud in 2024 and N25.85bn in 2025, for a cumulative N134.48bn between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at N1.1tn between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain. In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public. National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the general elections vulnerable to the very syndicates and state- actors currently probing our physical and cyber networks. Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right, and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed. Dr Kabir Adamu is the Managing Director of Beacon Security and Innovations Ltd

In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement in which it indicated that in the lead-up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”. See more Punch stories on Google. Add Punch on Google These statistics are a glaring warning the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 general elections, the stakes are existential to our democracy. Significant progress has already been made in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions. However, the cyber security function is less mature than the physical security functions, despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System, the Result Viewing Portal, the National Register of Voters, and the vast digital communication networks used by political parties and the media add additional exposure points and new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state- disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process. Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology’s Computer Emergency Readiness and Response Team, the Nigerian Communications Commission’s Computer Security Incident Response Team, and Galaxy Backbone’s Security Operations Centre. Technical skills can reduce youth unemployment — IIT ADC insists on releasing election results despite INEC warning FG to deploy 90,000km fibre across Nigeria by 2028 – APC chair While these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure. We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser, the Independent National Electoral Commission, and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead in advancing a unified capability effort. Ad hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like: First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre, must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state- APT tactics for the security architecture. Second, INEC must elevate electoral technology to critical national information infrastructure status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigour applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cybersecurity functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria. Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences. Fourth, ONSA, INEC, and the ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC,...