Why the Digital Skills Gap in African Governments Is Now a National Security Issue
African governments have spent the past decade moving identity records, tax collection, treasury operations, and public services onto digital systems. Many of those services are faster and easier to reach as a result. They are also exposed to attackers who can strike from anywhere, and that exposure has grown faster than the number of trained people available to defend it.
Attacks are reaching the core of the state
Senegal is the latest case. The government confirmed in May that an incident had disrupted IT systems at the Public Treasury, the third attack on a public institution in under six months, according to reporting by RFI. Earlier targets included the tax authority, where an extortion group claimed to have taken nearly a terabyte of data. Another target was an Interior Ministry department that issues identity cards, where hackers claimed to hold a database covering the entire population, including biometric records. Those figures are the attackers’ own claims.
Kenya shows the same pattern. On 18 July, hackers defaced the president’s official website and demanded five bitcoins, about $330,000. The ICT Authority activated its incident response protocols, and the government said it had found no evidence that sensitive data was accessed. The attack followed a July 2023 disruption of the eCitizen platform and a coordinated attack on several government websites in November 2025.
In South Africa, the Land and Agricultural Development Bank received a $3.1 million ransom demand in January and refused to pay. Its systems were only restored in April.
The broader numbers point to the same trend. Check Point research cited by RFI puts the average African organisation at 2,940 attacks a week, roughly 700 above the global average. Government is among the most targeted sectors.
The people to respond are not there
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that at least 63 percent of organisations in Sub-Saharan Africa lack adequate cybersecurity professionals. In Nigeria, the director general of the National Information Technology Development Agency (NITDA) has put the cybersecurity workforce gap at 90.6 percent, with only 25,760 professionals for a population above 220 million.
In South Africa, research cited by MiDO Academy found that 56 percent of organisations struggle to recruit cybersecurity staff. Kenya’s Communications Authority recorded more than 3.3 billion cyber threat events in the first quarter of 2026, with government agencies among the targets.
Why this is a security question, not only a staffing one
Governments hold the records and systems a state cannot function without: who its citizens are, what it collects and what it spends. When the staff who can detect an intrusion, contain it and rebuild afterwards are missing, attacks last longer and cost more. The Land Bank’s recovery, which ran from January to April, is one illustration.
The gap also reaches beyond specialists. NITDA‘s director general has said, citing the World Economic Forum, that more than 95 percent of breaches result from human error. That makes the ordinary civil servant, and the official who signs off on a new system, part of the defence.
Gérard Joseph Francisco Dacosta, a Dakar-based cyber defence specialist quoted by RFI, argues that the test for any government is whether it can detect an attack quickly, limit the damage and recover. He notes that Morocco and Rwanda already use tools such as endpoint detection and security event monitoring. Many other states do not.
Nigeria: broad training, thin specialist depth
Nigeria has moved on the general skills side. NITDA and the Office of the Head of the Civil Service have trained more than 53,000 civil servants in digital skills. The National Digital Literacy Framework behind the programme lists digital safety among its six core competencies.
In July, NITDA also convened ministries, departments and agencies for a cybersecurity workshop. Its director general said defacements, ransomware and data breaches against government platforms had become more frequent and more disruptive. As of mid-2025, the Office of the National Security Adviser had secured presidential approval to designate IT systems as critical national infrastructure, while the National Assembly reviewed cybersecurity legislation.
Teaching tens of thousands of civil servants the basics is worthwhile, but it is a different task from producing incident responders and security engineers. The 25,760 figure shows how far that second task has to go.
What closing the gap would take
Dacosta calls for national emergency response teams, security operations centres that detect attacks in real time, and large-scale training, rather than reliance on imported tools alone.
Procurement matters here too. Nigeria’s National Digital Cloud Policy tries to ensure that foreign investment contributes to domestic skills and does not simply add foreign-owned capacity. It divides responsibility among NITDA, Galaxy Backbone and the Bureau of Public Procurement.
Regional cooperation has also shown results. Interpol’s Operation Serengeti 2.0 brought together 18 African countries, led to 1,209 arrests and recovered $97.4 million.
None of these measures is cheap or quick. That is the point of treating the skills gap as a security matter, since a national security threat is normally funded and staffed accordingly. Nigeria’s critical infrastructure designation suggests governments are starting to describe cyber risk in those terms. Headcount, salaries and training budgets will show whether the description is matched by action. Until the specialist workforce grows, every new digital service adds to what a small number of people must protect.


