E-Business
Cyber Attackers Getting More Undetected in Target Networks – Sophos Report

New report released by Sophos has revealed that Cyber attackers are not only becoming sophisticated now, they are even getting more time undetected in target networks.

John-Shier, Senior-Security-Advisor-at-Sophos
Sophos, a global leader in next-generation cybersecurity, which released the “Active Adversary Playbook 2021,” detailing attacker behaviors and the tools, techniques and procedures (TTPs) that Sophos’ frontline threat hunters and incident responders saw in the wild in 2020.
The TTP detection data also covers early 2021. The findings show that the median attacker dwell time before detection was 11 days – or 264 hours – with the longest undetected intrusion lasting 15 months.
Ransomware featured in 81% of incidents and 69% of attacks involved the use of the remote desktop protocol (RDP) for lateral movement inside the network.
The playbook is based on Sophos telemetry as well as 81 incident investigations and insight from the Sophos Managed Threat Response (MTR) team of threat hunters and analysts and the Sophos Rapid Response team of incident responders.
The aim is to help security teams understand what adversaries do during attacks and how to spot and defend against malicious activity on their network.
Key findings in the playbook include:
- The median attacker dwell time before detection was 11 days – To put this in context, 11 days potentially provide attackers with 264 hours for malicious activity, such as lateral movement, reconnaissance, credential dumping, data exfiltration, and more.
Considering that some of these activities can take just minutes or a few hours to implement – often taking place at night or outside standard working hours – 11 days offers attackers plenty of time to cause damage in an organization’s network.
It is also worth noting that ransomware attacks tend to have a shorter dwell time than “stealth” attacks, because they are all about destruction
- 90% of attacks seen involved the use of the Remote Desktop Protocol (RDP) – and in 69% of all cases, attackers used RDP for internal lateral movement – Security measures for RDP, such a VPNs and multi-factor authentication tend to focus on protecting external access.
However, these don’t work if the attacker is already inside the network. The use of RDP for internal lateral movement is increasingly common in active, hands-on-keyboard attacks such as those involving ransomware
- Interesting correlations emerge among the top five tools found in victim networks. For instance, when PowerShell is used in an attack, Cobalt Strike is seen in 58% of cases, PsExec in 49%, Mimikatz in 33%, and GMER in 19%.
Cobalt Strike and PsExec are used together in 27% of attacks, while Mimikatz and PsExec occur together in 31% of attacks. Lastly, the combination of Cobalt Strike, PowerShell and PsExec occurs in 12% of all attacks.
Such correlations are important because their detection can serve as an early warning of an impending attack or confirm the presence of an active attack
- Ransomware was involved in 81% of the attacks Sophos investigated. The release of ransomware is often the point at which an attack becomes visible to an IT security team. It is, therefore, not surprising that the vast majoirty of the incidents Sophos responded to involved ransomware.
Other attack types Sophos investigated included exfiltration only, cryptominers, banking trojans, wipers, droppers, pen test/attack tools, and more

“The threat landscape is becoming more crowded and complex, with attacks launched by adversaries with a wide range of skills and resources, from script kiddies to nation-state backed threat groups. This can make life challenging for defenders,” said the Senior Security Advisor at Sophos, John Shier. “Over the last year, our incident responders helped to neutralize attacks launched by more than 37 attack groups, using more than 400 different tools between them. Many of these tools are also used by IT administrators and security professionals for their everyday tasks and spotting the difference between benign and malicious activity isn’t always easy.
“With adversaries spending a median of 11 days in the network, implementing their attack while blending in with routine IT activity, it is critical that defenders understand the warning signs to look out for and investigate. One of the biggest red flags, for instance, is when a legitimate tool or activity is detected in an unexpected place. Most of all, defenders should remember that technology can do a great deal but, in today’s threat landscape, may not be enough by itself. Human experience and the ability to respond are a vital part of any security solution.”
Other topics covered in the playbook include the tactics and techniques most likely to signpost an active threat and warrant closer investigation, the earliest signs of attack, the most widely seen stagers, threat types and malicious artefacts, the most prevalent adversary groups seen, and more.


To learn more about attacker behaviors, tactics, techniques and procedures (TTPs) read the Sophos Active Adversary Playbook 2021 on Sophos News.
E-Business
82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals

At its recent Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region Kaspersky shared the results of a global study conducted by its internal research center which surveyed 1,800 IT and cybersecurity decision-makers and specialists from organisations across 18 countries and multiple industries.

The report shows that the pace of AI integration across organisations is rapid, despite associated risks. The company’s experts stressed that while AI adoption delivers clear efficiency gains, it must be accompanied by robust cybersecurity solutions, well-defined internal procedures, and comprehensive employee education programmes.
The report highlights a clear organisational preference for AI-enhanced technology: 68% of respondents said they would recommend a solution with AI features built in, while a mere 5% indicated they would prefer to avoid AI-enabled tools. This overwhelming endorsement underscores how deeply AI has embedded itself as a value driver across the modern enterprise.
AI has become a mainstream productivity tool spanning many business functions. The global survey findings confirm that employees across departments are already relying on AI tools for a wide range of everyday tasks, including: data analysis & visualisation (54%), project management (49%), search for information (47%), department-specific tasks (46%), text generation and editing (41%).
While organisations recognise the tangible benefits AI tools bring – including improved process efficiency and enhanced quality of deliverables – they also see the associated dangers. 82% of respondents voiced concerns about the risks AI poses to their organisation. These concerns are grounded in real-world experience.
Among the 87% of organisations worldwide that faced a cyber incident in the past year, 13% reported that they had experienced threats stemming specifically from AI-related vulnerabilities.
Notably, 74% of respondents believe that these risks can be effectively mitigated through employees’ responsible behaviour — pointing to the critical importance of security awareness and training in the AI era.
“The speed at which organisations are embracing AI is remarkable, but it must be matched with an equally strong commitment to security. We are already seeing a growing range of threats directly tied to AI adoption – whether it’s malware camouflaged as popular AI tools, vulnerabilities introduced through unsecure vibecoding, or leaked access credentials to corporate AI platforms and malicious skills by AI agents.
Managing these risks requires a holistic approach: the right technology, well-defined procedures, and a security-aware workforce,” comments Brandon Muller, senior security consultant for the META region at Kaspersky.
E-Business
How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

Malagasy Vanilla has transformed its decades-old wholesale business by embracing direct-to-consumer sales through Temu, enabling the family-run company to reach customers in 14 European markets while significantly reducing logistics costs.

For years, premium Madagascan vanilla supplier Malagasy Vanilla sold exclusively to restaurants, bakeries and wholesalers because the cost of shipping a single pack to individual customers often equalled the value of the product itself. That changed after the company joined Temu’s Local Seller Program in November 2025.
The Belgian-based business, which sources high-quality vanilla from Madagascar, has leveraged Temu’s logistics network to cut domestic shipping costs by nearly half through a partnership with Belgian postal operator Bnode. The move has enabled the company to enter the retail market for the first time and quadruple its sales within four months.
According to Belinda Rabenandrasana, co-Chief Executive Officer of Malagasy Vanilla, Temu has opened up an entirely new customer segment for the company.
“Temu opened a new avenue for us,” she said. “We were finally able to explore selling to individuals.”
The platform now contributes between five and 10 per cent of the company’s overall revenue.
Expansion into 14 European Markets
Malagasy Vanilla is among businesses participating in Temu’s Local Seller Program, launched in Europe in 2024 to help local merchants expand beyond their domestic markets.
Through partnerships with more than 150 logistics providers across Europe—including Bnode in Belgium, La Poste in France and DHL Group in Germany—Temu offers sellers access to affordable shipping and delivery infrastructure without requiring major investment in logistics.
After successfully establishing direct-to-consumer sales in Belgium, Malagasy Vanilla expanded into 14 European countries, including Germany, France, Spain and Poland.
Rabenandrasana said the logistics support, competitive shipping rates and seller assistance provided by Temu made the expansion possible.
“Without Temu and its partnership with Bnode, it would have been very difficult for a small business like ours to start selling directly to consumers,” she said.
She added that Temu also assists sellers in managing regulatory requirements such as the European Union’s Extended Producer Responsibility (EPR) compliance, making cross-border operations easier for small businesses.
Three Generations of Vanilla Expertise
Malagasy Vanilla traces its roots to three generations of the Rabenandrasana family in Madagascar’s vanilla industry.
Belinda’s grandfather began trading vanilla locally, while her father expanded operations across Madagascar. She launched the company’s international business in 2017, supplying premium Madagascan vanilla to European restaurants, pastry shops and food wholesalers before establishing operations in Belgium in 2023.
The company partners with growers and producer associations in Madagascar, where between 20 and 40 workers oversee the six- to 10-month curing process that transforms green vanilla pods into premium black vanilla.
Operations in Belgium focus on packaging, quality assurance and distribution.
Customer Reviews Drive Growth
Under its Lavani brand, Malagasy Vanilla sells gourmet-grade whole vanilla pods targeted at both professional chefs and home baking enthusiasts.
Rather than relying heavily on paid advertising, the company has benefited from Temu’s product discovery tools and customer reviews, helping the niche brand gain visibility organically.
According to Rabenandrasana, strong customer feedback has played a significant role in increasing traffic and boosting sales.
The brand currently maintains a customer review rating exceeding 99 per cent on the platform.
Future Plans
Looking ahead, Malagasy Vanilla plans to expand its European footprint further by establishing a warehouse in France and increasing sales across the continent.
The company is also developing new products, including vanilla extract and vanilla sugar, while planning to open a physical retail and production facility in Belgium later this year.
In addition, it intends to launch a social-impact initiative aimed at supporting vanilla-growing communities in Madagascar.
Reflecting on the company’s evolution, Rabenandrasana said the business continues to build on her family’s legacy.
“My grandfather worked locally, my father expanded nationally, and now we are building internationally,” she said.
E-Business
FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

Stakeholders in Nigeria’s digital economy have urged the Federal Government to review its partnership with global recruitment platform Hello.cv under the 3 Million Technical Talent (3MTT) programme, citing concerns over data security, digital sovereignty and the country’s “Nigeria First” policy.

3MTT
The concerns follow the Federal Ministry of Communications, Innovation and Digital Economy’s announcement on May 6 of a 10 million-dollar partnership with Hello.cv aimed at increasing the global visibility of Nigerian technology professionals.
Under the initiative, 20,000 selected 3MTT fellows will receive a global professional profile package, including an Artificial Intelligence (AI)-powered job search agent, a professional curriculum vitae (CV) writer and a personal .cv domain, valued at 500 dollars per participant.
While stakeholders acknowledged the programme’s potential to improve global employment opportunities for Nigerian tech talent, they expressed concerns about the implications of hosting participants’ digital identities and data on a foreign domain.
Chief Executive Officer of Cyberchain and Global Digital Economy Strategist, Engr. Jude Ozinegbe, said the arrangement raised important questions about data ownership and jurisdiction.
According to him, registering domains under an entity outside Nigeria gives that entity a degree of control over activities associated with the domain.
“When you register your domain under a different entity outside your jurisdiction, that entity will have access to whatever is happening within that domain.
“In the long run, the Nigeria Data Protection Commission (NDPC) may have to examine the agreement and assess the security implications of such domain ownership,” he said.
Ozinegbe urged the NDPC to review the security protocols employed by Hello.cv to ensure compliance with Nigeria’s data protection regulations.
Also speaking, Ugonma Egwuatu of ECAM Global Services, an information and communications technology and data protection firm, said the security of data belonging to 20,000 fellows should be of significant interest to regulators.
She noted that while the ministry had the authority to determine how the programme was implemented, there was a need for greater transparency regarding the handling of participants’ personal information.
“The NDPC requires its registered Data Protection Compliance Organisations (DPCOs) to subscribe to the .ng domain.
“If a government ministry permits trainees to operate on a foreign domain, then the commission should examine the arrangement because we are dealing with the data of 20,000 Nigerians,” she said.
Egwuatu also called for clarity on how data generated through the platform would be processed, stored and protected.
“There should be explanations regarding the backend. What are they doing with the data of people who visit these sites? Why use a foreign domain instead of the .ng domain? These are legitimate questions that deserve answers,” she said.
She added that government should ensure appropriate third-party agreements and safeguards were in place before implementing such initiatives.
On his part, Chief Executive Officer of DNS Africa, Dr. Adebunmi Adeola Akinbo, said the objectives of the programme could still have been achieved while leveraging Nigeria’s country code top-level domain.
According to him, Hello.cv could have registered a hello.cv.ng or hellocv.ng domain in collaboration with the Nigeria Internet Registration Association (NiRA).
“The .ng domain can conveniently accommodate such a platform. If Hello.cv intends to onboard millions of Nigerians, it can work with NiRA to create a local domain structure.
“That way, the investment remains within Nigeria, strengthens the digital economy and supports local internet infrastructure,” he said.
Akinbo argued that excluding the .ng domain from the initiative undermined Nigeria’s digital identity and sovereignty.
“As good as the programme may sound, leaving the .ng domain outside this engagement and taking Nigerian data outside the country’s digital jurisdiction is not the best approach,” he said.
Also commenting, Founder and Chief Executive Officer of Precise Financial Systems Ltd., Yele Okeremi, stressed the importance of ensuring that investments in Nigeria’s digital economy create long-term domestic value.
According to him, building a sustainable technology ecosystem requires more than developing skilled professionals.
“Investment, particularly in technology and the knowledge economy, is not just about having smart people.
“It is also about who owns the infrastructure and who ultimately benefits from the value created. Nigeria must ensure it retains as much of that value as possible,” he said.
Similarly, Chief Executive Officer of the Internet Exchange Point of Nigeria (IXPN), Muhammed Rudman, described the use of foreign domains for a government-sponsored initiative as inconsistent with efforts to promote Nigeria’s digital economy.
“I don’t know where this idea came from, but it is unpatriotic for Nigerian companies funded by Nigerian resources to adopt .cv domains instead of .ng.
“Global companies such as Google register country-specific domains like google.ng when operating locally. Registering 20,000 additional .ng domains would improve Nigeria’s online visibility and strengthen the local internet ecosystem,” he said.
Rudman urged the Federal Government to support indigenous digital infrastructure by encouraging the use of the .ng domain.
The 3 Million Technical Talent (3MTT) programme is a flagship initiative of the Federal Ministry of Communications, Innovation and Digital Economy aimed at equipping Nigerians with globally relevant digital skills.
The programme provides free training in areas including software development, artificial intelligence, cloud computing, cybersecurity, data analytics, machine learning, animation, DevOps and user interface/user experience design through a hybrid learning model.
Stakeholders maintained that while the partnership with Hello.cv could expand international employment opportunities for Nigerian technology professionals, greater attention should be paid to safeguarding the country’s digital assets, promoting local internet infrastructure and ensuring compliance with Nigeria’s data protection framework.
Broadcasting3 days agoDavido Shares Past Suicidal Thoughts, Drops Oriadé Album
E-Business3 days agoHow Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe
News3 days agoCisco Explores AI for Nigeria Farmers
General News3 days agoMTN Nigeria Posts N707.5bn H1 Profit, Declares N26 Interim Dividend
News3 days agoAfCFTA Urges Africa to Stop Exporting Raw Materials
E-Business3 days ago82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals
General News3 days agoGavi Okays $500m for Vaccines, PHCs in Nigeria
E-Business3 days agoFG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders



















