Connect with us

E-Business

7 Cyber Security Myths that Could Cost Your Business Dearly

Published

on

Cyberthreats.jpg
Kindly share this post

Cyber-security is a major threat to every business today. This reality is amplified by our increasingly inter-connected world which makes dependence on digital services an absolute necessity. Despite the increasing global spend on cyber-security, cyber criminals are still having a field day.
In this piece, the Research/Development Unit of Yudala – Nigeria’s fastest growing e-commerce outfit – dissects the myths that prevent businesses and other individuals from taking effective measures to counter imminent cyber-security threats, with attendant huge losses and costs.

Strong passwords keep me protected
This is one of the myths that often leads to a hacking breach. While strong passwords are good, they are more effective when combined with other measures such as a two-factor authentication. This provides a second layer of security for your account(s). Furthermore, strong passwords may expose the user to self-imposed dangers. When passwords become difficult to remember or too complicated, the user may have no choice than to change them too frequently. As a result, you may be forced to write these passwords down since you can no longer memorize them, thereby opening the door to unauthorized access to your account.

My small business is not a target. Only big businesses are at risk
If you think that small businesses are not at risk of cyber-attacks, then think again. According to a recent report by Radware, 98% of organizations experienced cyberattacks in 2016. Small and mid-sized companies with less than 250 employees were the target of a reported 31% of these attacks. Organizations on the lower end of the scale are much more attractive to hackers as it is widely believed that less is being done by these companies to protect their sensitive data. This has manifested in an increasingly popular mode of attack known as Ransomware, where attackers encrypt data taken from the victim and in return for decrypting the data, they ask for an acceptable amount from the victim as ransom. These victims include individuals, small or medium-sized enterprises (SMEs) and large corporates.

The website is HTTPS, so I am secure from attacks
Hyper Text Transfer Protocol Secure (HTTPS) is the secure version of HTTP, the protocol over which data is sent between your browser and the website that you are connected to. The ‘S’ at the end of HTTPS stands for ‘Secure’. It means all communications between your browser and the website are encrypted.  While it secures your website at a minimal level, it is important to note that HTTPS does not prevent the hacking of a website, server, or a network. By diminishing Distributed Denial of Services (DDOS) attacks, hackers can force their way into your access controls exposing a website’s availability. Hence, every activity you carry out online must be done with this knowledge at the back of your mind.

Hackers will find nothing worth stealing
Many individuals and small business owners have this mind-set when confronted with news of the global effects of cyber-security. This myth or mind-set is, however, debunked by the potentially costly effects of enduring a breach, whether on a personal or corporate level. On a personal level, every individual has sensitive personal data that we would not wish to fall into the wrong hands. Pictures, video files or other personal information could expose us to grave danger or loss when unauthorized persons gain access to them. And on the corporate level, several small business owners who feel they have nothing worth stealing have had their fingers burned.
Research from Kaspersky Lab notes that a single cyber security incident now costs small and medium businesses (SMBs) an average of $86 500 per incident, mainly through loss of data. This data ranges from information about clients, customer details, bank details or access to your customers’ systems through e-commerce links or via email.

Advertisement

My computer is at risk only when I connect to a network or the internet
In addition to external attacks launched when a device is connected online, internal threats are also a major source of hacks or data breach. Users working inside your firewall with laptops, tablets, USB drives and other removable media that have been exposed to malware represent one of the most common access points for hackers. It is therefore, not surprising that many cyber-security specialists see the USB drive as the biggest hazard to cyber security. One out of every 8 attacks on computers these days, is believed to enter via USB devices.

Firewalls and network security are in place. I can go to sleep
For hackers, the art of circumventing a firewall is not an alien skill. Most hackers find it easy to disrupt codes or capitalize on loop-holes to gain access to your system, so the existence of a firewall is not a sure-fire guarantee of security. While it is clear that most cyber security threats are avoidable, your organization can not rely solely on firewalls for protection. Research also shows that, despite the huge outlay on network security, cyber-attacks are more severe at the application layer of your system infrastructure as network security does not often pose much resistance to cyber- bandits.

Security is assured since my website is externally hosted
Web hosting providers abound in their numbers. The likes of HostGator, Blue Host, Web.com, GoDaddy, DreamHost, InMotion and eHost, among others, have thousands of websites on their client list. As a result, effectively monitoring each site may be a herculean task. A significant majority of all external attacks occur as a result of poorly administered, misconfigured or inadequately managed systems. These loop-holes are easy for any eagle-eyed hacker to take advantage of. Hence, while a host is guaranteed to provide server level security; the major responsibility for managing the security of your website resides with you, the site owner.

Advertisement

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Kaspersky Uncovers New Mirage Kitten Malware Used in Cyber-espionage Campaign Across Africa, Others

Published

on

Kindly share this post

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META).

The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.

It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network.

Advertisement

This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods.

The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa.

“Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts.

Advertisement

“Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.

 

Kindly share this post
Continue Reading

E-Business

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.

DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).

In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC,  described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.

The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.

Advertisement

According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.

Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”

It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”

The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”

According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”

Advertisement

Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.

“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.

Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.

The commission warned that entities failing to comply with the registration requirement could face legal consequences.

“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.

Advertisement

 

Kindly share this post
Continue Reading

E-Business

UNN to Partner Firm on AI, Smart Mobility Innovation Centre

Published

on

Kindly share this post

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.

The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.

Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.

He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.

Advertisement

According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.

He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.

“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.

Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.

He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.

Advertisement

Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.

“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.

He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.

The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.

Advertisement

Kindly share this post
Continue Reading

Trending