E-Business
The Importance of Security Operations Centers to Contemporary Organizations

As organizations grow more dependent on IT solutions, they have also become potential subjects of cyber threats. These threats vary in terms of the risk they portend for their targets; the more lethal ones could inflict costly damage on their victims.

Businesses, public sector concerns, and other institutions have responded by taking proactive measures to prevent these threats from being actualized. In some cases, the creation of a Security Operations Center sits at the core of their strategy.
What Is a Security Operations Center?
A Security Operations Center (SOC) is a unit that’s built to tackle the security issues of an organization. It consists of the personnel, technologies, and processes that are required to maintain the organization’s security status.
The personnel at a Security Operations Center include members of the IT team who are adequately skilled at identifying and dealing with threats. The SOC’s processes involve monitoring, detecting, analyzing, and responding to threats.
Technologies used at a SOC are built to scour networks, servers, endpoints, websites, and databases for signs that such systems have been compromised. They also include tools that help with reporting such incidents.
In other words, the SOC serves as a point at which events logged throughout an institution are monitored. This setup works through the data and determines whether there are threats, and how to defend the organization against such threats where they exist.
The Functions of a Security Operations Center
As has already been hinted, a Security Operations Center needs to have visibility into the various aspects of the assets it is supposed to protect. It should also track the networked interaction between these assets, including software, endpoints, and servers.
Also part of the SOC’s mandate is preparation for possible attacks. To do this successfully, teams within the SOC will have to keep tabs on the latest developments in cybersecurity, such as emerging threats and best practices for defending systems against them. Vulnerabilities should be patched, firewalls updated, and applications secured.
Monitoring systems with tools such as Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) is standard practice for SOCs. The EDR continuously collects and analyzes activity data from endpoints throughout the organization, and provides automated responses to perceived irregularities within these data that may signal an imminent attack. SIEM similarly gives SOC personnel insights into activities in their IT environment.
In addition to these, the Security Operations Center also ranks security alerts, discerns genuine risks from false positives, responds to threats (by shutting down or isolating compromised endpoints, etc.), and carries out recovery and remediation following an attack.
The Structure of a Security Operations Center
Given its various duties, the SOC is ideally staffed with multiple IT security professionals, each playing a specific role within the setup.
A manager, who leads the team, should coordinate and oversee the processes ongoing within the SOC. They should also be able to fill any of the roles there. An analyst collects and analyzes past data or data generated after a breach has occurred.
Another role, the investigator, involves assessing a breach and answering questions about how and why the event occurred. They may also take on the role of the incidence responder, who takes action to minimize the impact of breaches.
One person could play multiple roles; it all depends on how big the organization affected is.
The structure of the SOC should be documented, with each role defined, and questions around responsibility and collaboration answered. Security processes that ought to be defined include monitoring, alerting, escalation, investigation, incident logging, compliance monitoring, and reporting.
Benefits of a Security Operations Center
An immediately perceivable benefit of the SOC is that knowledge is centralized. Personnel at the SOC gain a bird’s eye view of their organization’s networks and are better able to spot vulnerabilities. This setup lets them share vital information so that their work is more coordinated and ultimately effective.
This approach to security may reduce running costs as well. With the cybersecurity team and infrastructure in one location, resources are concentrated in one place at a given time. Because they are in a single location, organizations don’t have to spend more to maintain various offices across different locations.
Centralization may also help improve collaboration between members of the IT security team. They can leverage each other’s expertise and experience, and develop solutions that help their parent company in many ways.
With greater team collaboration comes improved response times. The use of advanced tools for threat detection and monitoring strengthens this benefit even more. With proactive network and endpoint monitoring tools, it’s even possible to protect against cyber threats before they materialize.
Finally, there’s the round-the-clock protection that SOC affords. Because attacks aren’t limited to working hours during weekdays, SOCs are built to monitor for potential vulnerabilities every hour of every day.
An Option Worth Considering: Managed Security Operations Center
Not all businesses are able to set up a functional SOC. The expertise, experience, tools, and space required to run it may constitute a drain on resources, besides forcing the business to take on additional tasks to its core operations.
Managed SOCs are a solution to this problem. Cybersecurity firms often offer this as a service to their client organizations. This means that businesses don’t need to have a large department dealing with security issues. Signing up with a reputable cybersecurity firm will allow them to have a SOC with that firm, and focus on their core operations.
Layer3 can help you manage your company’s IT security. We do this by leveraging the expertise and experience of our cybersecurity experts, and our knowledge of the present and emerging risks that enterprises face in today’s world. These, combined with our advanced threat detection and security intelligence tools and systems, will take care of the things you would typically assign to an in-house SOC. This guarantees cost savings for your organization and lets you devote more time and resources to your principal operations.
If you would like to learn more about our IT security service offerings, you can get in touch with us here.
E-Business
Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.
It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.
In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.
One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.
Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.
The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.
“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.
E-Business
PalmPay Targets Hong Kong IPO after $1Bn Valuation

PalmPay, one of Africa’s leading digital financial services companies, is considering a listing on the Hong Kong Stock Exchange after attaining a valuation of more than one billion dollars, according to a Bloomberg report.

PalmPay
The report, citing sources familiar with the matter, said the fintech company was also seeking to raise between 150 million dollars and 200 million dollars in fresh funding ahead of a potential Initial Public Offering (IPO).
According to the sources, the additional capital is expected to support PalmPay’s next phase of expansion across Africa and selected Asian markets.
If completed, the IPO would rank among the most significant public market debuts by an African fintech company and could encourage other technology firms on the continent to explore listings beyond the traditional financial centres of London and New York.
Founded in 2019, PalmPay has emerged as one of Africa’s fastest-growing consumer fintech platforms, providing digital payments, money transfers, savings, lending and merchant payment solutions.
The company has established its strongest market presence in Nigeria while expanding operations into Ghana, Tanzania and Bangladesh as part of its international growth strategy.
PalmPay says it currently serves more than 35 million registered users and supports over one million businesses and merchants, processing millions of transactions daily.
Its rapid growth has positioned it among Africa’s leading fintech firms, alongside companies such as Flutterwave, Moniepoint, OPay, Wave and Onafriq.
Unlike many technology startups that have prioritised rapid customer acquisition over profitability, PalmPay reportedly achieved profitability in 2025, a development analysts say could enhance investor confidence as the company prepares for another fundraising round and an eventual stock market listing.
The report noted that Hong Kong could offer strategic advantages for PalmPay due to its strong commercial ties with Asian investors and the company’s growing presence in emerging Asian markets.
PalmPay’s early investors include Transsion Holdings, the maker of the Tecno, Infinix and itel smartphone brands, as well as investors linked to NetEase and MediaTek.
Industry analysts believe these long-standing relationships could make Hong Kong a natural destination for PalmPay’s public listing while broadening access to investors already familiar with its business model.
The company’s IPO plans come as venture capital investment in African startups has slowed considerably since the record funding years of 2021 and 2022, prompting many technology firms to focus on profitability, stronger balance sheets and sustainable long-term growth.
Against that backdrop, PalmPay’s proposed fundraising and listing are expected to serve as an important test of international investor appetite for profitable African fintech companies.
The company’s valuation also underscores the resilience of Africa’s digital payments sector, driven by rising smartphone adoption, expanding internet access and increasing demand for cashless transactions across the continent.
Although PalmPay has yet to make a final decision on either the fundraising or the IPO timetable, the reported preparations indicate that the company is positioning itself for its next phase of growth.
Industry observers say a successful Hong Kong listing could provide fresh momentum for Africa’s technology sector and create an alternative pathway for high-growth startups seeking access to global capital markets.
E-Business
CMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers

CMS Transport Management (CMS T&M), one of Lagos’ longest-standing and most trusted transport operators, officially launches a new service known as TMO Rides.

This new initiative is designed to simplify the daily commute by introducing seamless cashless payments for passengers across its bus network.
For over 58 years, CMS T&M has played a significant role in moving millions of passengers daily along the CMS – Ajah routes through its fleet of high-capacity buses popularly.
The launch of TMO Rides marks another milestone in the company’s journey toward building a smarter, more efficient transport experience.
Through the initiative, passengers will have access to TMO Cards for a seamless transport. This is more exciting because TMO launches with 2 consecutive apps.
These apps help to eliminate the need for cash transactions while reducing boarding delays and create a more convenient experience for passengers.
Beyond introducing digital fare payments, the initiative reflects CMS T&M’s broader commitment to modernize public transportation through innovation, operational efficiency and improved customer experience.
CMS T&M operates within Nigeria’s regulated transport ecosystem as a registered member of the BRT Association of Nigeria (BRTAN), where it is also an equity stakeholder, reinforcing its commitment to a cooperative-driven transport system.
The company is equally registered with the Lagos Metropolitan Area Transport Authority (LAMATA), the agency responsible for planning, regulating and franchising public transportation in Lagos State, and is also a member of the National Union of Road Transport Workers (NURTW) that promotes safe and organized road transport operations.
Speaking on the launch, Andy, Managing Director of CMS T&M, said: “For nearly six decades, our focus has remained the same, which is moving people safely and efficiently.
“As the transportation needs of Lagos continue to evolve, we must evolve with them. TMOx Rider is about making everyday commuting easier by giving our passengers a faster, more convenient way to pay while improving the overall travel experience.
“This launch represents another important step in our commitment to building a smarter, more accessible transport system for everyone.”
The launch of TMO Rides forms part of CMS T&M’s long-term vision of embracing technology to improve public transportation without compromising the trust and consistency the passengers have relied on for generations.
The cashless payment infrastructure empowering TMO Rides is enabled by Treepz, whose mobility technology supports digital fare collection and operational efficiency.
By providing the technology behind the initiative, Treepz is helping CMS T&M expand access to modern, seamless transportation while advancing a shared vision of making everyday mobility more connected, convenient and accessible across Lagos.
Visit our website: https://www.cmstaxiandmotor.com/
News2 days agoAtte, Nigerian Develops AI Algorithm for Hair Transplants
News2 days agoFG to Abolish Subsidies in Power Sector in 2027 – Minister
E-Financial2 days agoCBN Exposes over 13,000 BVNs Tied to Fraud as Banks Tighten Security
E-Financial2 days agoFCT Court Awards Ex-Customers N15m against Stanbic IBTC over Data Privacy Breach
Telecom2 days agoStarbase Technologies Introduces Yolly, a Reward-Based Social Entertainment Platform
General News2 days agoDare Tackles Onaiyekan over Criticism of Tinubu, Says Economic is Working
General News2 days agoSERAP Asks Tinubu to Probe Alleged N6.79Bn Missing Police Funds, Firearms
Telecom2 days agoAdefolarin Ogunsanya and the Allegations of Shareholder Interference and Self-dealing @Pan African Towers




















