E-Business
How Cybersecurity Readiness Prevents Small and Medium Businesses (SMBs) from Fuelling Supply Chain Attacks

By Pankaj Bhula
Supply chain attacks aren’t new. If the past couple of years have taught businesses anything, it’s that the impact of supply chain cyber attacks is now universal, from the fallout of the SolarWinds software breach to the exposed Apache Log4j vulnerability and Kaseya last year.

Unfortunately, when such supply chain attacks hit smaller businesses, who are usually the suppliers to larger enterprises, their impact is especially prohibitive.
For SMBs already feeling the prolonged impact of the pandemic, the added pressure of dealing with sophisticated and frequent cyber attacks in real time are a heavy burden, as they try to protect their business against financial, legal and reputational damage, as well as their own suppliers and larger clients’ security.
It is now more important than ever for SMBs to implement strict security hygiene and effective cybersecurity processes to ensure their business is prepared for the event of cyber attacks happening.
SMBs as an indirect avenue of cyber attacks
The ‘new normal’ opened the door to several new vulnerabilities; cyber attacks globally increased by 50% on average in 2021, compared to 2020.
Our Check Point Threat Intelligence report revealed that an organisation in South Africa experienced a cyberattack 1,675 times per week, compared to 1,117 attacks per organisation globally.
While security breaches are on the rise, the top threats impacting SMBs have remained the same. In Check Point’s Small and Medium Business Security Report from 2020/2021, we revealed phishing, malware, credential theft and ransomware to be the top four threats impacting these businesses. So, what does this mean for them?
The reality is threat actors have taken advantage not only of the now-entrenched remote working model to target organisations, but also the usual limits preventing SMBs from bulking up on their cyber security defences – mainly lack of budget and expertise. SMBs often do not have a dedicated IT or security department.
With no in-house security expertise and reduced focus on security patching, these companies are easier to socially engineer and infiltrate.
Adding to this, SMBs usually have employees doing multiple roles, and thus a wider access to valuable areas of the business and information is given to them, and so if breached, they pose a threat to multiple areas within the business.
In addition, the business IT infrastructure is often shared for personal use communication as well, such as social media and personal emails, allowing easier access to hackers as the data is often not secured.
Threat actors often target SMBs as low hanging fruit for their vital role in supply chains. This is especially so as such attacks wreak havoc on not only one organisation but entire businesses within the supply networks.
By leveraging tactics such as phishing, cybercriminals gain access to an organisation to launch a malware attack, steal data and credentials or instigate a ransomware.
Take for example, the attack against Target USA where hackers used stolen credentials from an SMB vendor that serviced the HVAC systems in Target stores, to gain access to the retailer’s network and then laterally move to the systems that kept customer payment information. As a result, the global retailer was breached and 40 million credit and debit cards details stolen.
The key factor to preventing cyberattacks is threat prevention. With minimal time and lack of cyber expertise or manpower, SMBs must adopt a prevention mindset to minimise potential cyber attacks and threats.
Why cybersecurity readiness is paramount for SMBs
Beyond the immediate financial impact and reputational blow as a trustworthy, reliable partner, SMBs can also face legal or regulatory repercussions, operational disruption, flow-on costs for system remediation and cyberattack response, customer churn, and the loss of competitive advantage that can make or break a smaller business.
In fact, a tarnished reputation as an avenue of attack can be even more detrimental to an SMB organisation, as the loss of trust with a larger organisation could mean a loss of potential business and revenue down the line with them or other new, potential customers.
With this in mind, budgetary constraints to keep computers and corporate networks protected should never be an excuse, as keeping sensitive data and information protected will bring many advantages and benefits to companies.
This can range from overall cost savings, compliance with data protection laws, gaining the trust of customers and suppliers, to protecting your documents and information to the maximum by preventing any type of data breach.
How SMBs can prevent supply chain attacks
By applying stronger cyber defences, SMBs are in a position to provide larger organisations with assurance that larger companies they supply to will not be compromised via the SMB partner or third-party vendor.
Whilst there are multiple means to prevent such supply chain attacks, the first step is to have good software capable of covering the entire company, protecting the company’s endpoints and devices, and supported by regular backups so that, in the event of a cyber attack, they have the possibility of restoring all the data.
Any device that connects to the network can become a security breach, so it is important to secure all endpoints. It is especially critical for remote or hybrid workforces to avoid security breaches and data compromise.
Also, all employees should be trained in cybersecurity so that they themselves become the first barrier to any attempted attack, such as phishing via email or SMS. Keep in mind that prevention is one of the best protection measures available.
A viable option for SMBs is to also consider engaging an experienced Managed Security Service Provider (MSSP), who will have the skilled resources, updated security software and experienced expertise to monitor for and analyse threats on behalf of the SMB player. This is especially useful for SMBs who have neither the time nor resources to adequately enforce threat detection and response.
Partnering with a cybersecurity expert equipped with best-in-class security and scalable solution such as Check Point Software can put SMBs in good stead to protect against the most sophisticated attacks and generate trust among larger potential players.
Ultimately, SMBs seek a simple plug-and-play solution with best-in-class threat protection, given their lack of financial funding and skills.
With an effective cybersecurity strategy, SMBs are better placed to demonstrate their credibility as secure partners to larger organisations, opening up more business opportunities.
Pankaj Bhula is Regional Director for Africa at Check Point Software
E-Business
UNN to Partner Firm on AI, Smart Mobility Innovation Centre

The University of Nigeria (UNN) is set to partner with The Roxettes Group to establish a research and innovation centre focused on artificial intelligence (AI), smart and green mobility, and digital technologies, in a move aimed at strengthening research, entrepreneurship and technology-driven industrial development.

Chairman of The Roxettes Group, Arc. Dr. Kaycee Orji-Kelechi, announced the proposed partnership while delivering his acceptance speech after receiving an Honorary Doctor of Business Administration (Honoris Causa) during the university’s convocation ceremony.
The proposed facility, to be known as the Dr. Kaycee Orji Centre for Artificial Intelligence, Smart/Green Mobility and Digital Innovation, is expected to provide a platform for research, innovation and collaboration between academia and industry, with a focus on developing commercially viable solutions to local and continental challenges.
Orji-Kelechi said the initiative was conceived as a long-term investment in human capital and technological advancement rather than simply another physical infrastructure project.
He said the vision was to position the University of Nigeria among Africa’s leading institutions in artificial intelligence, smart mobility and digital innovation through research, entrepreneurship and technology development.
According to him, the centre will house five specialised laboratories covering artificial intelligence and machine learning, smart and green mobility, robotics and the Internet of Things (IoT), digital finance and financial technology, as well as cloud computing and advanced data centre technologies.
He also announced plans for the proposed Kaycee Orji Founders Innovation Challenge, an annual programme intended to identify, mentor and support innovative ideas from students, researchers and academic staff with the potential to become scalable businesses.
“Every student of this University should know that a great idea conceived in a classroom should have a pathway to becoming a patent, a startup, a global enterprise, and a solution that transforms society,” he said.
Orji-Kelechi disclosed that preliminary conceptual work on the project had commenced, with architectural and engineering designs being prepared by K.KH Contractors Ltd., a subsidiary of The Roxettes Group.
He added that discussions with the university would begin on identifying a suitable site for the project, while a comprehensive proposal containing architectural drawings, engineering designs and an implementation framework would be submitted after completion of the design phase.
Reflecting on his career, Orji-Kelechi said Africa must move beyond consuming innovation to creating it through investment in manufacturing, technology and entrepreneurship.
“We have pursued one simple vision: that Nigeria and Africa must move from consumption to production; from importing innovation to creating it; and from waiting for opportunities to building them,” he said.
He urged graduating students to see their education as a foundation for solving societal challenges through innovation, leadership and enterprise, adding that he remained committed to promoting industrial development, youth empowerment and sustainable economic growth.
The proposed collaboration forms part of broader efforts to strengthen university-industry partnerships, which are increasingly seen as critical to improving research commercialisation, innovation capacity and technology-led economic development in Nigeria.
E-Business
NPC Opens 131 Births, Deaths Registration Centres in Anambra

National Population Commission (NPC) has announced commencement of full digital registration of births and deaths through the VitalReg platform, which became operational nationwide on July 1, 2026.

Chidi Ezeoke, federal commissioner representing Anambra, disclosed this in Awka during a press conference to announce commencement of full digital birth and death registration under the Electronic Civil Registration and Vital Statistics (E-CRVS) system and the marking of World Population Day commemorated every July 11.
He revealed that a total of 131 registration centres had been opened in the 21 local government headquarters and several communities in the state, adding that more centres would be opened later.
Ezeoke described the initiative as a major milestone in Nigeria’s Civil Registration and Vital Statistics (CRVS) system, to ensure every birth and death in the country was captured through a digitally enabled registration platform.
“It builds on the launch of the E-CRVS system and the inauguration of the National Coordination Committee on Civil Registration and Vital Statistics by President Bola Tinubu on Nov. 8, 2023.
“A total of 4,011 functional registration centres has been established across the 774 LGAs of the federation and the commission iswas working to expand the number to about 8,000.
“In Anambra, 131 registration centres have been opened in the 21 local government headquarters and several communities. More centres had been proposed for the state,” he said.
According to the Commissioner, the VitalReg platform would provide faster registration services, 24-hour online access, digital certificate issuance where applicable, reduced paperwork and waiting time, improved data validation and a more secure national CRVS database.
While noting that the platform would serve as a foundational database to support other national data systems and strengthen interoperability across Nigeria’s digital identity ecosystem, Ezeoke urged Nigerians and other stakeholders to support the initiative by ensuring prompt registration of all births and deaths.
Speaking on the 2026 World Population Day themed, “Realising the Hopes and Aspirations of Young People – Today and for the Future”, the Commissioner called for greater investment in education, healthcare, skills development, decent employment opportunities and youth participation in governance for sustainable national development.
Earlier, Mr Obiakonwa Okagwu, state director, NPC, said the occasion served as a reminder of great opportunities provided to harness young people’s capabilities, which he said would shape the future of the country when adequately harnessed.
He called on residents to take registration of births and deaths as national responsibility, just as he urged the media to take the message on civil registration to all parts of the State.
E-Business
Report Says Cybercriminals Deploy Malware to Hijack Crypto Wallets, Monitor Browsers Telegram

Cybersecurity researchers at Kaspersky have uncovered a sophisticated malware framework, dubbed OkoBot, that is targeting cryptocurrency users by stealing wallet recovery phrases, browser credentials and other sensitive information through a multi-stage attack campaign spanning more than 25 countries.

The researchers said the malware, active since April 2025, employs more than 20 malicious payloads and has evolved into an advanced cybercrime platform focused on compromising digital asset holders. According to Kaspersky’s Global Research and Analysis Team (GReAT), the campaign remains active and has already affected hundreds of users worldwide.
Kaspersky disclosed that one of the framework’s most dangerous components, known as SeedHunter, injects malicious code into legitimate cryptocurrency wallet applications, including Ledger Wallet, Ledger Live and Trezor Suite, before displaying fake recovery phrase prompts designed to trick victims into surrendering their seed phrases.
The security firm explained that once attackers obtain a victim’s recovery phrase, they gain complete control over the cryptocurrency wallet, enabling them to transfer digital assets with virtually no chance of recovery.
Commenting on the discovery, Dmitry Galov, security researcher at Kaspersky’s GReAT, said.
“This campaign has been running for more than a year and remains active. OkoBot is not just a single piece of malware but an extensible framework built primarily to compromise cryptocurrency users.”
Galov added that the malware is continuously maintained and enhanced, underscoring the attackers’ long-term focus on financial theft.
According to Kaspersky, victims are typically infected through ClickFix phishing attacks or malicious GitHub repositories masquerading as legitimate software downloads. In one instance, a fake Microsoft SQL Server Management Studio repository secretly installed a trojanized version of the Audacity audio editor embedded with malicious code.
Following the initial compromise, the attackers deploy a PowerShell downloader called TookPS,which establishes an encrypted SSH connection to attacker-controlled infrastructure.
The malware then harvests browser cookies, wallet files, stored credentials and system information before downloading additional malicious modules.
Among the additional payloads is OkoSpyware which monitors more than 100 applications, which includes cryptocurrency wallets and password managers—records user activity and captures keystrokes and video of application windows. Another module silently installs malicious browser extensions capable of stealing financial information and authentication tokens.
However, Kaspersky’s telemetry indicates that the largest concentrations of victims have been recorded in Brazil, Vietnam, Canada, Mexico and Türkiye, although the malware campaign has spread to users across more than 25 countries.
The cybersecurity firm advised cryptocurrency users never to enter wallet recovery phrases into prompts displayed by desktop applications or websites unless they have independently verified their authenticity.
Furthermore,It also urged users to download wallet software exclusively from official sources, enable multi-layered endpoint protection, and remain cautious of software offered through unofficial repositories or phishing websites.
Kaspersky noted that while hardware wallets themselves remain secure, attackers are increasingly exploiting the software that accompanies them, making user awareness a critical line of defence against evolving cryptocurrency-focused cyber threats.
E-Business2 days agoReport Says Cybercriminals Deploy Malware to Hijack Crypto Wallets, Monitor Browsers Telegram
Telecom2 days agoSubscribers, Telcos Warn FCCPC over Airtime Lending Enforcement
News2 days agoSee Verified 20 Countries Nigerian Passport Holders Can Travel Visa-Free
Telecom2 days agoNCC, REA Partner to Cut Telecom Costs with Renewable Energy
General News2 days agoAfDB, Nigeria Urge African Control of Mineral Resources
E-Business2 days agoNPC Opens 131 Births, Deaths Registration Centres in Anambra
General News2 days agoLagos Chamber Opposes 21 Percent Pension Contribution, Warns of Job Losses
Telecom2 days agoNigeria Pushes for United African Front Ahead of Global Telecoms Elections




















