A school head asks for an audit after hearing about an attack at another school. The report runs to three pages. The administrative server's backup had run every night for a year, and nobody had ever tried to restore it. It did not work. Nothing sophisticated, nothing expensive to fix — simply invisible as long as nobody looked.

A trade of ranking

Any organisation, however small, can easily list thirty desirable security measures. The problem is not knowing them: it is that none gets implemented, because the list discourages people before they start.

A security professional's work therefore begins with sorting: which scenarios are genuinely plausible for this organisation, which would cost it most, and which measures cut the most risk for the least effort.

A useful report ranks and orders. You deal with what is critical, plan the rest, and consciously accept what you choose not to address. A document that puts everything on the same level produces no decision.

Nobody is too small

The objection comes up every time: "we are too small for anyone to bother with us". It rests on a false image, that of an attacker choosing targets.

Most common attacks are automated and select nothing: programs sweep whatever is exposed and exploit whatever has not been updated. A small organisation is not less targeted; it is simply less prepared, and often more vulnerable because it has neither a verified backup nor anyone whose job this is.

That reality changes the conversation. It is not about defending against a determined adversary, but about no longer being among the easy targets.

The audit: establishing what exists

You cannot protect what you do not know about. An audit therefore starts with an inventory, often more revealing than what follows: which machines, which servers, which online services, which accounts, who holds what, which data is stored where, which backups exist, and who could get in today without anyone noticing.

The most frequent findings are not technical. An administrator account shared between four people. A former employee whose access was never removed. Email without two-factor authentication. A server whose password nobody remembers. A backup never tested.

The debrief matters as much as the analysis. A manager has to understand what they are risking, in their own vocabulary, to decide for themselves what to fix first. A report nobody reads protects nothing.

A framework to organise the work

Disorder is the main enemy. A reference framework helps structure the approach without imposing a method.

The NIST Cybersecurity Framework, whose version 2.0 was published in February 2024, is among the most widely used. It aims to help organisations better understand and improve their management of cybersecurity risk, and addresses businesses and government alike. It organises expected outcomes into broad Functions — govern, identify, protect, detect, respond and recover — which gives a simple thread: who decides, what do we have, how do we protect it, how would we know something was happening, what do we do then, and how do we get back to normal.

One point deserves emphasis: this framework is voluntary guidance. It imposes nothing by itself, and adopting it relieves an organisation of no national legal obligation.

Access: the most profitable subject

If only one thing were to be dealt with, it would be this one, because it costs little and protects a great deal.

The principles are well known: one named account per person rather than a shared one, rights limited to what is genuinely necessary, stronger authentication switched on where available, immediate revocation when someone leaves the organisation or the project, and credentials stored in a tool made for it.

Three practices should be ruled out without discussion: a password shared in a group chat, an unprotected text file holding credentials, and the same password reused across every service. They cannot be corrected after the fact: the day one of them causes a problem, it is already too late.

Backups: the only measure that repairs

Every other measure reduces the probability of an incident. Backup is the only one that repairs its consequences.

It has to be a real backup, though. Synchronisation between machines is not one: a deletion synchronises, and a file encrypted by ransomware synchronises too. Five things need separating: live data, a copy kept separately, a synchronisation, a version history and an export usable elsewhere.

The principles come down to four points: copies genuinely separated from production, a frequency matched to what the organisation accepts losing, restricted access to those copies, and tested restores. No numbered scheme is a universal standard. What is closer to universal: a backup never restored is not a backup, it is an assumption.

Workstations and updates

Most common compromises exploit flaws the software publishers have already fixed. Applying updates to the operating system, the browsers and the business software remains the most ordinary and the most effective measure.

To that add simple habits: up-to-date antivirus, an active firewall, disk encryption on devices that leave the premises, and a clear rule on USB drives and personal devices. The detail depends on context and means, but the order of priority varies little.

Exposed applications

A site, a shop or an application reachable from the Internet needs particular attention, because it is permanently exposed.

The most widespread defensive reference is the OWASP Top 10, published by the OWASP Foundation. That awareness document, aimed at developers and web application security teams, sets out the most critical risk categories for web applications and presents itself as a first step towards more secure development. It is used as a checklist: it says what to watch, not how to attack.

On the operations side, it comes down to simple questions to put to whoever delivered the application: who applies updates to the platform and its components, how often, who holds the technical accounts, what is logged, and where the backups are.

Awareness rather than prohibition

A large share of incidents starts with an ordinary human act: a link opened, an attachment viewed, a password given to someone who seemed legitimate.

A well-run awareness session changes habits more than one more piece of software. It is concrete: what the fraudulent messages actually received in this organisation look like, what to do when in doubt, whom to report to, and above all how to report without fear of blame. A team that dares not say it clicked loses the hours that matter most.

Personal data and regional frameworks

An organisation handling data about customers, pupils, patients or staff must know what it holds, where, who has access and for how long. Minimisation — collecting only what is used — remains the cheapest security measure in existence.

Two African regional texts frame this subject, with different statuses. The African Union Convention on Cyber Security and Personal Data Protection, adopted on 27 June 2014 in Malabo, covers electronic transactions, personal data protection and cybersecurity; like any treaty, it produces effects only in the States that have ratified it, through their national laws. The African Union Data Policy Framework, published on 28 July 2022, aims to strengthen and harmonise data governance in Africa in order to create a shared data space serving an inclusive digital economy; it is guidance, not binding legislation.

The obligations that actually apply to a given organisation therefore flow from its national law and, where relevant, from its data protection authority. That is where to check, and nowhere else.

Responding to an incident

An incident is handled better when the course of action was written down beforehand, at a time when nobody was under pressure.

The pattern is stable: detect, characterise what is happening and what is affected, contain to stop it spreading, tell the people concerned, correct, verify the correction holds, document what happened, then deal with the cause so it does not recur.

Two things vary by country: some regulations require notifying a data breach to an authority or to the people concerned, within timeframes and in forms that differ. That is checked locally, calmly, and not on the day of the incident.

In African contexts

Working conditions differ sharply from one country and one city to another, and there is no single African context.

On the regulatory side the picture is uneven: some States have ratified the Malabo Convention, others have not; some have an operational data protection authority, some a statute without an authority, others no specific framework at all. The African Union Data Policy Framework is aimed precisely at reducing that dispersion, without replacing national law. A professional therefore first checks what applies where their client operates.

On the operational side, several constraints recur in some contexts without being peculiar to the continent: power cuts that make automatic backups irregular, connections billed by volume that discourage remote backup, phones serving as the main working device, heavy use of instant messaging for business exchanges, estates made up of personal devices. Each is addressed with suitable measures — an encrypted local backup alongside a remote copy, awareness work focused on messages received by phone, separation of business and personal accounts — and none is deduced from a supposed continental reality.

Finally, the availability of security skills varies greatly between cities. Where they are scarce, the right strategy is often to make the organisation self-sufficient on a few essential habits rather than installing a system nobody will be able to maintain.

What a security professional does not promise

No specialist guarantees that no incident will occur. Absolute security does not exist, and a provider who promises it is describing a product that does not exist.

Nor do they guarantee that deleted data will be recovered, that ransomware will be decrypted, that a compromised account will be returned, or that a third-party supplier will stay available. They do not sell legal compliance: that depends on national law and is established, not purchased.

What they do commit to can be checked: a real inventory, ranked and explained risks, proportionate measures, backups restored in front of the client, access put back in order, teams made aware, a written course of action for incidents, and documentation the organisation keeps.

Artificial intelligence can help draft a report, triage alerts or prepare an awareness session. It can be wrong, produce an inaccurate reference, and must receive no sensitive data without precaution; the decision and the responsibility remain the professional's.

Finally, this article describes a trade; it replaces neither an audit nor legal advice, and the obligations mentioned vary from country to country.