Nigeria's data protection regulator says the country records more than 4,000 cyberattacks every week. Most successful attacks use weak passwords and unpatched devices, which means most of them are preventable.
At the IoT West Africa 2026 conference in Lagos, the Nigeria Data Protection Commission (NDPC) said the country now records over 4,000 cyberattacks a week, with estimated losses of about ₦12 billion in 2024. In July, Dark Reading reported Check Point figures showing the average Nigerian organisation faced 4,361 attempted attacks a week in June 2026, placing Nigeria behind only Angola among the most attacked countries in Africa.
The NDPC itself has not been spared: it reported more than 1,500 attack attempts on its own network in a short period and shut the network down temporarily as a precaution. The commission has also issued an advisory following alleged breaches involving well known payment and banking platforms, which shows the problem reaches far beyond small shops.
The Nigeria Data Protection Act 2023 requires organisations that hold personal data to report a breach to the NDPC within 72 hours, and to tell affected people directly where the risk to them is high. The NDPC's advice to organisations includes appointing a trained Data Protection Officer, keeping a clear privacy policy, running data privacy impact assessments, and putting proper access controls in place. Failing to protect data can carry legal liability, so this is no longer only an IT matter.
If you are unsure whether the Act applies to you, speak to a data protection professional. If you keep customer records, staff files, payment details, or CCTV footage of identifiable people, assume you should be treating that data carefully.
CCTV systems are network devices like any other, and they are often the least maintained device in the building. A recorder with an unchanged password and an open port can be found and used within hours. We assess these as part of every security review, whether or not we installed the system.
Begin with a written picture of where you are exposed: what is on your network, which devices have weak settings, and what is reachable from the internet. Then fix the highest risks first. That is exactly what a security assessment gives you, in plain language, with each finding ranked.