E-Business
Securing Your Organization Against Ransomware Attacks

Nigerian businesses continue to reap immense gains from deploying contemporary digital technologies in the design and execution of their processes. But these tools aren’t always insulated from potential sabotage. Malicious actors may find vulnerabilities in those technologies, and exploit such weaknesses to wreak havoc on the organizations that use them.

One way that cybercriminals do this is by targeting their victims with ransomware. Over the past decade, cyberattacks involving ransomware have grown in number, and have become more sophisticated. These attacks hit SMEs and large corporations, and even public sector agencies, and costs them tens of millions of naira.
If you are a business or an institution in Nigeria, you should be concerned about ransomware and the damage it could cause you.
Ransomware: A Brief Introduction
Ransomware is a program that blocks access to its victim’s files until the victim pays a ransom. Cybercriminals infect a target’s computer with it, aiming to extort a specific amount of money from that target in return for restored access, in a manner akin to a kidnap-for-ransom.
Typically, the perpetrator would send ransomware disguised as a harmless file to victims. If the target downloads or opens the file, it infects their system. The program may be spread through email attachments, malicious URLs, remote desktop protocol, and even malicious advertising.
Newer ransomware types can self-propagate across a network, potentially infecting every system used in an organization. They are capable of shutting down entire businesses.
Ransomware Attacks Are Fairly Common
Reports on the state of IT and the contemporary business environment reveal that ransomware attacks are fairly common across the globe. Not surprisingly, they are usually concentrated on businesses.
In 2020 alone, there were an estimated 304 million ransomware attacks worldwide. This was up 62% on the previous year. According to the Singapore Computer Emergency Response Team, there was “a seven-fold jump” in the number of reported ransomware incidents in the first half of 2020.
Some of that spike in activity was attributed to cyber criminals trying to exploit lapse IT security during the COVID-19 pandemic; their targets were predominantly remote workforces. However, these incidents have numbered in the hundreds of millions per year since 2016.
Nigerian organizations have been affected. A report by the Sophos Group, a UK-based security software and hardware security firm, revealed that 53% of the Nigerian businesses it surveyed had been victims of ransomware in 2019.
Of the businesses hit, about 38% of them admitted to paying the attackers to regain access to their files. However, the Sophos report indicated that these payments didn’t always result in the victims recovering all their resources.
A Few Well-Known Ransomware Attacks
In 2019 and 2020, many companies worldwide were targeted by ransomware called Ryuk. It is spread via malicious emails that contain dubious links or attachments. If successfully deployed on an organization’s computers, it can request a ransom of more than $300,000. As of January 2021, cybercriminals had reaped more than $150 million from Ryuk.
Three years before this, another ransomware, Petya, began infecting computers in several countries. It denied users access to their Operating Systems and demanded a $300 ransom from them. A later version did not unlock the infected system even after the ransom was paid.
The most infamous ransomware attack to date involved the WannaCry program, which infected more than 200,000 computers in over 150 countries. In May 2017, it spread across the world fairly rapidly, affecting both businesses and public institutions. The global cost of the attack is believed to have exceeded $4 billion.
Since the first known ransomware was created in 1989, several more have been designed and deployed, to devastating effect.
Organizations Incur Significant Costs from Ransomware Attacks
The cost of recovering from a ransomware attack has doubled in the past year. The cumulative global cost was well over $1 billion in 2020 alone.
Sophos says that these incidents cost mid-sized businesses an average of $133,000 annually. Some companies incurred several million dollars in recovery costs. In many cases, this expenditure racks up from multiple incidents.
The most hard-hit sectors included media, IT and telecoms, and energy/oil and gas utilities. The public sector was the least frequently targeted. Regardless, organizations in these domains have spent large amounts of money on damages inflicted by ransomware.
Unfortunately, many SMEs are unable to bear the financial weight of recovery. At least 1 in 5 of these businesses shut down within a year of suffering an attack. Bigger companies are better able to cope, but they too aren’t immune from the burden that such events bring.
How to Protect Your Organization Against Ransomware
The threat of a ransomware attack is ever-present. You will do well to prepare for an attempted strike against you.
Map your assets and note the degrees to which each one is vulnerable to an attack. Work with your IT team to prepare a resilience plan, complete with data backup, business continuity, and recovery strategies.
Also, ensure that the latest Operating Systems patches are applied when they become available, and update critical software as soon as is possible. Carry out penetration tests to determine where the weak points are, and fix them.
Adopt enhanced passwords and multi-factor authentication for staff at your organization. Train them to verify emails and other messages before engaging with them, and not to open websites unless they have a URL that begins with ‘HTTPS’ (Hypertext Transfer Protocol). The last ‘s’ is crucial; it indicates a secure site.
A Partner You Can Trust
Ransomware attacks have grown more sophisticated and precise over time. If you have sensitive data to protect, you will want to work with IT security experts to set up a strong defense for your organization.
Layer3 provides this expertise through its cybersecurity services. With our IT risk vulnerability and management, email authentication, and network access solutions, you can build a strong buffer against various kinds of cyber threats, including ransomware.
To find out more about our IT security offerings, or the other services we provide, you can contact us here.
E-Business
Cyber Resilience a Critical Priority for Manufacturing Amid Rapid Digitalization – Report Shows

As 60% of manufacturers race toward full digitalisation, cyber risk is increasingly manifesting as a business risk, according to a new global report by Kaspersky and VDC Strategy.

This means cybersecurity is not merely a compliance function, it is a cornerstone of production assurance, safeguarding uptime, quality, and operational continuity.
Manufacturers are modernising to deliver safer, more consistent and more cost-effective production and digitalization is moving fast: just 9% of organisations describe themselves as fully digital today, but 60% expect to get there within two years, according to the joint report by Kaspersky and VDC, titled ‘Cyber Resilience, Built for Manufacturing’.
That shift links shop-floor equipment, production lines and site operations to platforms such as Manufacturing execution systems (MES), Supervisory control and data acquisition (SCADA) and historians, turning many plants into cyber-physical systems (CPS), where a digital disruption doesn’t stay digital. It can slow production lines, quarantine work in progress, invalidate traceability records, or halt production outright.
What’s driving manufacturing digitalization?
Manufacturers are digitising for measurable operational gains, not novelty. Survey respondents identified the primary drivers of their digital transformation strategy as:
- Improving production output or efficiency (24%)
- Reducing operational or production expenses (15%)
- Enabling new strategic opportunities (14%)
- Improving cyber resilience (13%)
The same connected systems that unlock these gains, including MES, IIoT sensors, automated material handling, remote engineering access, also become the systems that determine whether production can be trusted to keep running.
Cyber risk is now a business risk
Cyber risk has evolved from a mere IT concern to a direct threat to revenue generation, as environments transform into cyber-physical systems. In these integrated settings, digital disruptions like malware no longer just affect data, they can cause unsafe operations, scrapped batches, and halted production on the plant floor. This shift highlights the urgent need to treat cybersecurity as a key part of operational resilience.
According to the report, nearly 60% of manufacturing organisations estimate that cyber incidents cause damages exceeding $1 million per event, with an average disruption of 15.3 hours. The most significant losses often result from production halts, missed delivery commitments, and penalties, rather than just forensic costs.
In this context, downtime links cybersecurity risks to overall business performance. Cyber incidents can reduce Overall Equipment Effectiveness (OEE), strain staffing, and disrupt supply chains. Recovery involves more than system restore, it requires re-establishing confidence in process parameters, quality records, and traceability before resuming operations.
Mature cybersecurity programs now incorporate OT security into governance, focusing on metrics valued by production leaders such as time to restore, backup confidence, legacy asset coverage, and safe degraded operation. This alignment ensures cybersecurity supports continuous production and resilience, not just IT compliance.
However, challenges remain due to split ownership. While 59% of organisations’ IT departments manage security policies, these often overlook plant realities. Managing many security tools (44%) and OT patching issues (38%) show that cybersecurity must be embedded into daily routines of production, engineering, and quality teams. Only through such integration can cybersecurity effectively enhance operational reliability and defend against evolving threats.
“As manufacturing environments become increasingly interconnected, cybersecurity shifts focus from merely adding protective layers to ensuring the availability, resilience, and integrity of production processes. The goal is to minimise operational impact and speed up recovery, rather than solely preventing intrusions.
“Kaspersky offers a unified ecosystem that integrates IT, OT, and IIoT security, empowering manufacturers to pursue digital transformation securely. This strategy helps maintain operational continuity and reduces long-term cybersecurity costs,” comments Andrey Strelkov, Head of Industrial Cybersecurity Product Line at Kaspersky.
To implement this strategy, manufacturing companies can leverage solutions from the Kaspersky OT Cybersecurity Ecosystem, centered around Kaspersky Industrial CyberSecurity (KICS), a native Extended Detection and Response platform designed for critical infrastructure protection. KICS enables centralised detection and response to complex attacks across the entire industrial network, ensuring comprehensive visibility and security.
E-Business
NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.
Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.
The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.
According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.
The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.
It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.
Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.
The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.
The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.
The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.
E-Business
Microsoft to Unveil Next-generation AI Chip in September

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon as next month, The Information reported on Monday, citing people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and Amazon in scaling up its in-house chip efforts as it seeks to reduce its reliance on Nvidia’s costly processors.
Google began recognizing revenue from direct sales of its custom AI chips, called Tensor Processing Units, in the quarter ended June, while Amazon has also seen growing adoption of its processors, including its Trainium chips.
Microsoft has been in talks with chipmaker TSMC to secure manufacturing capacity for more than 300,000 units of the chip for delivery in 2027, according to the report. It is also looking to significantly ramp up production and persuade major cloud customers such as Anthropic to adopt the chip.
Microsoft ultimately aims to secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity negotiations with TSMC could constrain its plans, according to the report.
It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.
Microsoft packed the chip with a significant amount of SRAM, a type of memory that can provide speed advantages for AI systems handling large numbers of user requests.
News2 days agoMoove Achieves Unicorn Status With $250m Funding
Telecom2 days agoMTN Nigeria Clocks 25, Connects over 90m People
E-Financial2 days agoFG Suspends NAICOM’s N680m Insurance Recapitalisation Fees
Broadcasting2 days agoAffordable, Flexible Streaming Platforms May Kill PAYtv – Report
E-Business2 days agoMicrosoft to Unveil Next-generation AI Chip in September
Telecom2 days agoSubscribers to Seek Legal Redress if Poor Quality of Service Continue in September
E-Financial2 days agoSEC Moves to Recover Unclaimed Dividends, Inherited Investments Nationwide
Telecom2 days agoipNX Collaborates with ICT Stakeholders on the Future of Fibre-to-the-Home in Nigeria @ ATCON Forum















