E-Business
Curbing N127bn Cybersecurity Annual Losses via Tardigrade’s ERA Roadmap
With cyber attacks on the rise, organisations across the globe are contending with loss of reputation, loss of customers, potential financial liabilities, regulatory notification requirements and sometimes, litigation.
To address this menace, however, Tardigrade, a Nollysoft’s Enterprise Risk Assessment (ERA) solution, has been identified by experts as a veritable roadmap that would provide a better understanding of the cybersecurity space and a good grasp of the internal control mechanisms to organisations towards cyber threats.
The greatest war that countries in the 21st Century currently face and which they must prepare to win headlong to actively participate in the global economy largely driven by the Internet is cyber warfare.
As such, the need for organisations to deploy a security solution that helps to identify factors contributing to and determining the organisation’s overall cyber risk; assess the organisation’s cybersecurity preparedness; evaluate whether the organisation’s cybersecurity preparedness is aligned with its risks; determine risk management practices and controls that are needed or need enhancement and actions to be taken to achieve the desired state and offers informed risk management strategies to organisations cannot be under-estimated.
Indeed, local and regional authorities, professional IT associations and various reports home and abroad have raised the sentiments around the danger posed by cyber threats and the need for each organisation to get its IT infrastructure weaponised through effective internal controls and security solutions.
Rising wave of concerns
For instance, the telecoms industry regulator in Nigeria, the Nigerian Communications Commission, has noted that cybersecurity has become an essential component of the human activity. This was the position of the Executive Vice Chairman of the Commission, Prof. Umar Danbatta, at a cybersecurity forum in Lagos,where he noted that cyber attacks’ high level of complexity requires action at different levels (both virtual and physical) and by different actors, including governments, private sector, civil society, intergovernmental organisations, among others.
According to him, the current scale and growth of ICT applications transcend all spheres of social and economic boundaries worldwide. “Whether it is broadcasting (digital TV) or social networking, e-Commerce (mobile banking and financial services), e-Governance (government services management, e-education, e-health, e-taxation, e-commerce), governments, institutions and the society, in general, are increasingly embracing these technologies and at the same time becoming exposed to vulnerabilities of cyber-attacks,” he said.
He, therefore, strongly advocated that technical measures such as theNollysoft’s Enterprise Risk Assessment (ERA) solution and appropriate legal instruments must be put in place to enhance the resilience of cybersecurity infrastructure and safeguard cyber technologies users.
In the same vein, Secretary-General of the Commonwealth Telecommunications Organisation (CTO), Mr. Shola Taylor, has also raised serious concerns about the dangers of cyber attacks and the need for a synergy by stakeholders to mitigate and, if possible, prevent their potential risks on organisations IT infrastructure.
According to Taylor, “Cyberspace contributes significantly to achieving countries’ national development goals, and so international organisations, national security services, operators, intelligence and data protection agencies, as well as citizens all, have a role to play in making cyberspace safer and more resilient,” he said, while sharing the CTO’s experience in developing national cybersecurity strategies for Commonwealth member countries as well as other countries, including Senegal last year.
Potential risks, exposures and losses
In Nigeria, over N127 billion is lost annually by mostly business organisations and ministries, departments and agencies (MDAs) of government, translating to 0.08 per cent loss in the `country’s annual Gross Domestic Product (GDP), according to the country’s Minister of Communications, Adebayo Shittu.
Also,62 per cent of firms are being attacked weekly, according to a 2017 International Data Corporation (IDC) InfoBriefsponsored by Splunk. In the report, it was noted that with malware becoming more advanced with encrypted ransomware, the security breach impacts on organisations may include loss of reputation, loss of customers, potential financial liabilities, regulatory notification requirements and sometimes litigation instigated by victim customers.
President, Cyber Secure Conference organised by the Cyber Security Experts Association of Nigeria (CSEAN), Mr. Remi Afon quoted another statistics, which puts the cost of cyber-crime globally at $700 billion per year.He said the loss is projected to rise to about $2 trillion by 2019, due to the rapid digitisation of consumer lives and company records. Breaches like these have steadily been on the rise as according to reports, the number of incidents has increased by more 38 per cent annually since 2015.
According to U.S. State of Cybercrime survey, Ponemon Institute, and Juniper research, cybersecurity events and costs are increasing, data breaches are expected to reach $2.1 trillion globally by 2019.
Thus, Afon argues that there is a need for Nigeria to implement the National Cyber Security Strategy and Policy and ensure effective implementation of the Cybercrime Act 2015 as well making organisations embrace the newest solution. One of such security solutions ready to tackle cyber attacks on organisations in the country is Tardigrade, a Nollysoft’s Enterprise Risk Assessment (ERA) solution.
This is instructive as industry experts have said organisations in Nigeria are in dire need of cyber experts that could help secure the cyberspace and one of the ways to boost protection is to embrace and deploy innovative solutions offered by security company/experts.
Tardigrade – an Enterprise Risk Assessment (ERA) solution to the rescue
In the industry today, Tardigrade, an Enterprise Risk Assessment (ERA) solution, introduced into Nigeria by Nollysoft, towers among other Risk assessment solutions present robust impact assessments and strategic security solutions to organisation by helping them to have in place processes that ensure they understand their gaps and state of preparedness to respond to cyber breaches. Senior Management and Board of organisations are often faced with the following key concerns among several: How protected is their organisation from internal and external threats, is the organisation a direct target for attacks?, who is accountable for assessing and managing the risks posed by changes to the business strategy or technology?
Others are how effective is their system of internal control and being applied? how do they compare to competitions and how do we compare with our peers in the industry?
Tardigrade solution effectively addresses these concerns.
According to industry experts, organisations need a good handle on the cyber threats and risks their organisation may face. They also need to have a grasp of whether their system of internal control is effective, or basically, need to implement specific security controls from standards such NIST 800-53 or ISO 27001.
The Tardigrade assessment solution helps organisations to understand their cybersecurity and internal control risks so that they can implement appropriate mitigation controls to achieve a desired state of preparedness.
“Tardigrade Cybersecurity Assessment helps organisations identify their risks and determine their cybersecurity preparedness. The assessment solution provides businesses with repeatable and measurable processes to inform senior management of their organisations’ cybersecurity preparedness over time,” said Sola Koleowo, Chief Executive Officer of Nollysoft Limited on behalf of the company.
The ERA solution, Koleowo, said is based on best practice frameworks set by Federal Financial Institution Examination Council (FFIEC), Information Technology Examination Handbook (ITEH), National Institute of Standards and Technology (NIST), Cybersecurity Framework (CF)and International Standard Organisation (ISO 27001) and regulatory guidance.
According to him, the Tardigrade Internal Control solution enables organizations to understand deficiencies in their system of internal control to allow the creation of effective mitigating control to help achieve business objectives. It is based on industry standard and best practices framework – Committee of Sponsoring Organisations of the Treadway Commission (COSO).
On the security requirement traceability matrix, Koleowo said, “Tardigrade Security Requirement Traceability Matrix solution allows organisations to effectively select security controls from standards and regulations for implementation either as a part of a Secure Software Development Lifecycle (SSDLC) or regulatory mandate,” stressing that the solution currently supports 2 industry standards: NIST 800-53 R4 and ISO 27001-2013, and two regulations: Sarbanes-Oxley (SOX) and Monetary Association of Singapore (MAS).
The total cost of ownership (TCO) of Tardigrade solution is low. No CAPEX needed to acquire the solution. It is a Cloud-based solution and being offered as a service.
Last Line
Leveraging innovative enterprise risk assessment solution such as Tardigrade by organisations from private to public sectors of the economy will not only guarantee effective protection for user organisations but also help curb losses to the national economy. This is just as industry analysts say the arrival of Tardigrade will raise the bar of organisations’ protection against potential cyber threats and associated losses.
E-Business
Kaspersky Uncovers Cyber Threats Defining the First Half of 2026 in Nigeria, Others

Kaspersky’s Global Research & Analysis Team (GReAT) reveals key cyber threat trends for the first half of 2026 at the recent Cyber Security Weekend for the Middle East, Turkiye and Africa region (META).

As the cybersecurity landscape continues to evolve, cyberthreats are becoming increasingly diverse and sophisticated. The rapid adoption of artificial intelligence (AI), coupled with ongoing geopolitical and economic instability, is contributing to the rise of cybercrime and the growing complexity of cyberattacks.
According to Kaspersky’s telemetry, online threats exploiting vulnerabilities in websites, emails and web services continued to affect millions of users across the META region during the first half of 2026.
Specifically, Kaspersky detection systems stopped 1,6M attacks from various online resources in Nigeria. Turkiye recorded the highest percentage of users affected by web-based threats at 22.8%, followed by Kenya (21.2%), Qatar (19.3%), Nigeria (18.4%) and South Africa (17.2%). In contrast, Saudi Arabia, Jordan and Pakistan registered the lowest share of users targeted by web-borne attacks in the region.
AI is transforming attacker operations
Kaspersky experts report that threat actors are increasingly integrating AI into different stages of their operations. Large language models are already being used to generate phishing emails, malicious code and supporting operational content.
AI is also beginning to play a larger role in malware development. Modern language models are capable of generating substantial portions of malicious software, from initial code scaffolding to functional modules.
Researchers have already observed AI-assisted malware development in campaigns linked to the FunkSec group, which deployed Rust-based malware capable of data theft, encryption and process manipulation. Similarly, during the RevengeHotels campaign in 2025, threat actors used large language models to generate portions of the infector and downloader code.
“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” said Sergey Lozhkin, Head of Global Research and Analysis Team in APAC and META regions at Kaspersky. “By lowering the time and cost required to develop and adapt malicious tools, AI allows threat actors to iterate faster and scale their efforts. Defenders should be prepared for quicker shifts in tactics.”
Emerging trends shaping the cyber threat landscape
In addition to the growing use of AI by cybercriminals, Kaspersky experts identified several trends that organisations should monitor closely:
- AI-driven malware evolution: generative models can rewrite malware in different languages or architectures, making malicious code harder to detect, and faster to deploy at scale.
- Cloud-based data exfiltration: attackers increasingly route stolen data through legitimate cloud and file-sharing services to blend in with normal traffic.
- Ransomware targeting operations: some groups disrupt production and business processes, not just encrypt data, to increase pressure for payment.
- AI agents as persistence mechanisms: some AI agent solutions are granted broad or even full system access. If compromised, attackers could modify the system prompt or the agent’s configuration, for example, causing it to download a payload on every startup.
- Malicious AI skills become a new attack vector: as AI agents gain broader access to enterprise systems, attackers start to exploit compromised skills to manipulate agent behaviour, steal sensitive data, execute unauthorised actions, and establish persistent access. This creates a new layer of risk where trusted AI tools can be turned into powerful mechanisms for cyberattacks.
As cyberthreats continue to evolve alongside emerging technologies, Kaspersky recommends that organisations strengthen their cybersecurity posture through continuous vulnerability management, timely patching, employee awareness training, threat intelligence, and advanced security solutions like Kaspersky Next, capable of detecting sophisticated and AI-assisted attacks.
E-Business
Kaspersky Uncovers New Mirage Kitten Malware Used in Cyber-espionage Campaign Across Africa, Others
Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META).
![]()
The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.
The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.
The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.
It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network.
This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.
While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods.
The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.
“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa.
“Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts.
“Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.
E-Business
NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.
DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).
In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC, described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.
The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.
According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.
Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”
It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”
The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”
According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”
Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.
“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.
Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.
The commission warned that entities failing to comply with the registration requirement could face legal consequences.
“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.
Telecom3 days agoFact-Check: Elon Musk’s “Tesla Pi Phone” is Internet Rumor
E-Financial3 days agoMalpass, Ex World Bank Chief Raises Alarm over Nigeria’s Secretive Debt Structures
Telecom3 days agoHow and Why Apps Deplete Data – ALTON
News3 days agoCIBN, ACAMB Push for Financial Inclusion, Women Empowerment
E-Financial3 days agoS&P Global Acquires Agusto & Co. to Strengthen Credit Ratings Across Africa
Telecom3 days agoGalaxy Backbone Soft Launches Government Service Portal to Simplify Access to Public Services
E-Business3 days agoNDPC Directs DCPMIs to Register with Agency or Face Legal Consequences
Broadcasting3 days agoAfrica Prudential Posts N1.59bn Profit in H1 2026, Reaffirms Digital Growth Strategy














