E-Business
Curbing N127bn Cybersecurity Annual Losses via Tardigrade’s ERA Roadmap
With cyber attacks on the rise, organisations across the globe are contending with loss of reputation, loss of customers, potential financial liabilities, regulatory notification requirements and sometimes, litigation.
To address this menace, however, Tardigrade, a Nollysoft’s Enterprise Risk Assessment (ERA) solution, has been identified by experts as a veritable roadmap that would provide a better understanding of the cybersecurity space and a good grasp of the internal control mechanisms to organisations towards cyber threats.
The greatest war that countries in the 21st Century currently face and which they must prepare to win headlong to actively participate in the global economy largely driven by the Internet is cyber warfare.
As such, the need for organisations to deploy a security solution that helps to identify factors contributing to and determining the organisation’s overall cyber risk; assess the organisation’s cybersecurity preparedness; evaluate whether the organisation’s cybersecurity preparedness is aligned with its risks; determine risk management practices and controls that are needed or need enhancement and actions to be taken to achieve the desired state and offers informed risk management strategies to organisations cannot be under-estimated.
Indeed, local and regional authorities, professional IT associations and various reports home and abroad have raised the sentiments around the danger posed by cyber threats and the need for each organisation to get its IT infrastructure weaponised through effective internal controls and security solutions.
Rising wave of concerns
For instance, the telecoms industry regulator in Nigeria, the Nigerian Communications Commission, has noted that cybersecurity has become an essential component of the human activity. This was the position of the Executive Vice Chairman of the Commission, Prof. Umar Danbatta, at a cybersecurity forum in Lagos,where he noted that cyber attacks’ high level of complexity requires action at different levels (both virtual and physical) and by different actors, including governments, private sector, civil society, intergovernmental organisations, among others.
According to him, the current scale and growth of ICT applications transcend all spheres of social and economic boundaries worldwide. “Whether it is broadcasting (digital TV) or social networking, e-Commerce (mobile banking and financial services), e-Governance (government services management, e-education, e-health, e-taxation, e-commerce), governments, institutions and the society, in general, are increasingly embracing these technologies and at the same time becoming exposed to vulnerabilities of cyber-attacks,” he said.
He, therefore, strongly advocated that technical measures such as theNollysoft’s Enterprise Risk Assessment (ERA) solution and appropriate legal instruments must be put in place to enhance the resilience of cybersecurity infrastructure and safeguard cyber technologies users.
In the same vein, Secretary-General of the Commonwealth Telecommunications Organisation (CTO), Mr. Shola Taylor, has also raised serious concerns about the dangers of cyber attacks and the need for a synergy by stakeholders to mitigate and, if possible, prevent their potential risks on organisations IT infrastructure.
According to Taylor, “Cyberspace contributes significantly to achieving countries’ national development goals, and so international organisations, national security services, operators, intelligence and data protection agencies, as well as citizens all, have a role to play in making cyberspace safer and more resilient,” he said, while sharing the CTO’s experience in developing national cybersecurity strategies for Commonwealth member countries as well as other countries, including Senegal last year.
Potential risks, exposures and losses
In Nigeria, over N127 billion is lost annually by mostly business organisations and ministries, departments and agencies (MDAs) of government, translating to 0.08 per cent loss in the `country’s annual Gross Domestic Product (GDP), according to the country’s Minister of Communications, Adebayo Shittu.
Also,62 per cent of firms are being attacked weekly, according to a 2017 International Data Corporation (IDC) InfoBriefsponsored by Splunk. In the report, it was noted that with malware becoming more advanced with encrypted ransomware, the security breach impacts on organisations may include loss of reputation, loss of customers, potential financial liabilities, regulatory notification requirements and sometimes litigation instigated by victim customers.
President, Cyber Secure Conference organised by the Cyber Security Experts Association of Nigeria (CSEAN), Mr. Remi Afon quoted another statistics, which puts the cost of cyber-crime globally at $700 billion per year.He said the loss is projected to rise to about $2 trillion by 2019, due to the rapid digitisation of consumer lives and company records. Breaches like these have steadily been on the rise as according to reports, the number of incidents has increased by more 38 per cent annually since 2015.
According to U.S. State of Cybercrime survey, Ponemon Institute, and Juniper research, cybersecurity events and costs are increasing, data breaches are expected to reach $2.1 trillion globally by 2019.
Thus, Afon argues that there is a need for Nigeria to implement the National Cyber Security Strategy and Policy and ensure effective implementation of the Cybercrime Act 2015 as well making organisations embrace the newest solution. One of such security solutions ready to tackle cyber attacks on organisations in the country is Tardigrade, a Nollysoft’s Enterprise Risk Assessment (ERA) solution.
This is instructive as industry experts have said organisations in Nigeria are in dire need of cyber experts that could help secure the cyberspace and one of the ways to boost protection is to embrace and deploy innovative solutions offered by security company/experts.
Tardigrade – an Enterprise Risk Assessment (ERA) solution to the rescue
In the industry today, Tardigrade, an Enterprise Risk Assessment (ERA) solution, introduced into Nigeria by Nollysoft, towers among other Risk assessment solutions present robust impact assessments and strategic security solutions to organisation by helping them to have in place processes that ensure they understand their gaps and state of preparedness to respond to cyber breaches. Senior Management and Board of organisations are often faced with the following key concerns among several: How protected is their organisation from internal and external threats, is the organisation a direct target for attacks?, who is accountable for assessing and managing the risks posed by changes to the business strategy or technology?
Others are how effective is their system of internal control and being applied? how do they compare to competitions and how do we compare with our peers in the industry?
Tardigrade solution effectively addresses these concerns.
According to industry experts, organisations need a good handle on the cyber threats and risks their organisation may face. They also need to have a grasp of whether their system of internal control is effective, or basically, need to implement specific security controls from standards such NIST 800-53 or ISO 27001.
The Tardigrade assessment solution helps organisations to understand their cybersecurity and internal control risks so that they can implement appropriate mitigation controls to achieve a desired state of preparedness.
“Tardigrade Cybersecurity Assessment helps organisations identify their risks and determine their cybersecurity preparedness. The assessment solution provides businesses with repeatable and measurable processes to inform senior management of their organisations’ cybersecurity preparedness over time,” said Sola Koleowo, Chief Executive Officer of Nollysoft Limited on behalf of the company.
The ERA solution, Koleowo, said is based on best practice frameworks set by Federal Financial Institution Examination Council (FFIEC), Information Technology Examination Handbook (ITEH), National Institute of Standards and Technology (NIST), Cybersecurity Framework (CF)and International Standard Organisation (ISO 27001) and regulatory guidance.
According to him, the Tardigrade Internal Control solution enables organizations to understand deficiencies in their system of internal control to allow the creation of effective mitigating control to help achieve business objectives. It is based on industry standard and best practices framework – Committee of Sponsoring Organisations of the Treadway Commission (COSO).
On the security requirement traceability matrix, Koleowo said, “Tardigrade Security Requirement Traceability Matrix solution allows organisations to effectively select security controls from standards and regulations for implementation either as a part of a Secure Software Development Lifecycle (SSDLC) or regulatory mandate,” stressing that the solution currently supports 2 industry standards: NIST 800-53 R4 and ISO 27001-2013, and two regulations: Sarbanes-Oxley (SOX) and Monetary Association of Singapore (MAS).
The total cost of ownership (TCO) of Tardigrade solution is low. No CAPEX needed to acquire the solution. It is a Cloud-based solution and being offered as a service.
Last Line
Leveraging innovative enterprise risk assessment solution such as Tardigrade by organisations from private to public sectors of the economy will not only guarantee effective protection for user organisations but also help curb losses to the national economy. This is just as industry analysts say the arrival of Tardigrade will raise the bar of organisations’ protection against potential cyber threats and associated losses.
E-Business
Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”
According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.
PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.
The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.
It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.
PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.
The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.
According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.
Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.
“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.
Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.
It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.
The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.
E-Business
Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.
It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.
In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.
One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.
Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.
The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.
“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.
E-Business
Firm to recruit over 100 professionals to boost NRS e-Invoicing compliance

Afri Invoice, one of Nigeria’s leading accredited e-invoicing service providers, has announced plans to recruit more than 100 professionals nationwide to strengthen support for the Nigeria Revenue Service’s (NRS) mandatory e-invoicing compliance programme.

The recruitment campaign, is aimed at expanding the company’s workforce to meet the growing demand for digital tax infrastructure and help businesses transition smoothly to the country’s evolving e-invoicing regime.
According to the company, the new positions will be spread across Nigeria’s six geopolitical zones to ensure businesses receive timely, localised support as they adapt to the new tax compliance framework.
The vacancies cut across several key departments, including Information Technology (IT), Marketing and Digital Marketing, Audit, Legal, Human Resources and multi-site office operations.
Afri Invoice said applicants are expected to possess relevant professional experience, particularly in managing operations across multiple locations and supporting organisational growth.
The company explained that the latest recruitment drive builds on a similar exercise conducted last year, which significantly expanded its operational reach and increased its capacity to onboard clients nationwide.
With the NRS intensifying the implementation of mandatory e-invoicing, Afri Invoice said it is investing in additional manpower to ensure uninterrupted service delivery, efficient client onboarding and expert technical support for businesses of all sizes.
Speaking on the expansion, the Founder and Chief Executive Officer of Afri Invoice, Mark Odenore, said the company remains committed to helping Nigerian businesses comply with the new tax regulations through innovative technology and professional support.
“As the national drive toward comprehensive e-invoicing gathers momentum under the Nigeria Revenue Service, our mission is to ensure that Nigerian businesses have a reliable, accredited partner to navigate this transition effortlessly,” Odenore said.
He added that recruiting more than 100 professionals across the country’s geopolitical zones would significantly strengthen the company’s ability to provide quality technology solutions and customer support nationwide.
Interested and qualified candidates have been encouraged to submit their applications through Afri Invoice’s official careers portal.
Afri Invoice is an accredited e-invoicing service provider that offers digital solutions designed to simplify financial processes, improve tax transparency and support businesses in complying with national tax regulations while enhancing supply chain and financial management.
E-Business3 days agoKaspersky Identifies Cyberespionage as a Growing Threat Across Africa, Others
Broadcasting3 days agoNBC Files Fresh Appeal against Judgment Barring it from Imposing Fines on Broadcast Stations
News3 days agoINTERPOL Report Shows AI Powers 55% of Cybercrimes in Africa Amid $484m Losses
E-Business2 days agoKaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
News3 days agoNigeria Expands Deep-tech Skills Pipeline
E-Financial3 days agoNigerians Lost N25.85Bn to Digital Payment Fraud in 2025 –CBN
Telecom3 days agoWhy Strong Institutions Remain Africa’s True Growth Engine
E-Business2 days agoCMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers














