HomeBlogCyberattacks 2026

Over 4,000 Cyberattacks a Week: What Nigerian Businesses Should Do Now

Nigeria's data protection regulator says the country records more than 4,000 cyberattacks every week. Most successful attacks use weak passwords and unpatched devices, which means most of them are preventable.

Digital shield illustration representing network and device security

The numbers

At the IoT West Africa 2026 conference in Lagos, the Nigeria Data Protection Commission (NDPC) said the country now records over 4,000 cyberattacks a week, with estimated losses of about ₦12 billion in 2024. In July, Dark Reading reported Check Point figures showing the average Nigerian organisation faced 4,361 attempted attacks a week in June 2026, placing Nigeria behind only Angola among the most attacked countries in Africa.

The NDPC itself has not been spared: it reported more than 1,500 attack attempts on its own network in a short period and shut the network down temporarily as a precaution. The commission has also issued an advisory following alleged breaches involving well known payment and banking platforms, which shows the problem reaches far beyond small shops.

What the law expects of you

The Nigeria Data Protection Act 2023 requires organisations that hold personal data to report a breach to the NDPC within 72 hours, and to tell affected people directly where the risk to them is high. The NDPC's advice to organisations includes appointing a trained Data Protection Officer, keeping a clear privacy policy, running data privacy impact assessments, and putting proper access controls in place. Failing to protect data can carry legal liability, so this is no longer only an IT matter.

If you are unsure whether the Act applies to you, speak to a data protection professional. If you keep customer records, staff files, payment details, or CCTV footage of identifiable people, assume you should be treating that data carefully.

Six fixes that close the most common gaps

  • Change every default password. Routers, DVRs, NVRs and cameras often ship with admin and a simple password that attackers try first.
  • Update firmware. Many attacks use flaws that were patched months ago. Schedule updates, do not wait for a problem.
  • Separate your networks. Keep cameras and security devices on their own network segment, away from office computers and guest Wi-Fi.
  • Close remote access you do not need. Switch off port forwarding, and use a secure login for live viewing instead of an open port.
  • Turn on two step login and keep backups. Protect email and cloud accounts, and keep a backup that is stored offline or separately.
  • Train your staff. A convincing phishing message gets past firewalls by getting a person to click. Short, practical sessions work.

Do not forget your cameras and recorders

CCTV systems are network devices like any other, and they are often the least maintained device in the building. A recorder with an unchanged password and an open port can be found and used within hours. We assess these as part of every security review, whether or not we installed the system.

Where to start

Begin with a written picture of where you are exposed: what is on your network, which devices have weak settings, and what is reachable from the internet. Then fix the highest risks first. That is exactly what a security assessment gives you, in plain language, with each finding ranked.

Sources

Book a security assessment Back to all articles