Cybersecurity is now one of the biggest challenges of Africa’s digital transformation. As businesses, banks, hospitals and government agencies move more of their work online, the cost of getting it wrong keeps rising. According to INTERPOL’s 2025 Africa Cyberthreat Assessment, cyber-related crime already makes up more than 30% of all reported crime in parts of West and East Africa. By 2026, INTERPOL reported that financial losses from cybercrime across the continent had more than doubled since 2024, reaching an estimated $484 million, and that more than half of these attacks now involve artificial intelligence.
Yet one problem gets far less attention than it deserves: the cost of cybersecurity itself.
For many African organisations, especially small and medium-sized enterprises (SMEs), good cybersecurity can feel completely out of reach. The standard advice is to buy several security tools, build detailed control systems, hire specialist staff and chase certifications, all based on frameworks designed for large, well-funded companies. The numbers make the gap clear: African SMEs spend roughly $23 per employee a year on security, compared with $189 at bigger firms, according to industry research compiled by Tech In Africa.
The result is discouraging. A business owner understands that cybersecurity matters but concludes that real protection is simply unaffordable.
I believe that conclusion is wrong.
The question should not be, “How much cybersecurity can we afford?” It should be: “What is the minimum level of security we must have to protect what matters most?”
That is the thinking behind what I call Minimum Viable Security (MVS).

Source: Total Assure – Cost of Cybersecurity for small businesses.
Cybersecurity programmes often grow by accident rather than design. A company buys a new system. A new threat appears. A regulator adds a rule. An auditor flags a gap. Someone buys another tool. Over time, security becomes a pile of technologies, policies, and requirements that don’t always work together.
More controls do not automatically mean better protection. In fact, poorly planned security can become expensive without becoming much more effective, a problem that hits African SMEs hardest, where one person often handles IT, cybersecurity, compliance and business continuity all at once.
The answer isn’t to tell these businesses to spend more. It’s to help them prioritise better.
Start With Risk, Not Products
A practical cybersecurity programme starts by asking what actually needs protecting. What information would cause real harm if stolen? Which systems would stop the business if they went down? Which services matter most to customers? What rules must the business follow? Which threats are most relevant to how it actually operates?
Once these questions are answered, money can go where it reduces the most risk. This sounds obvious, but it’s a real shift from how security is often built, starting with a shopping list of tools instead of starting with risk.
A small business doesn’t need the security setup of a multinational bank. But that doesn’t mean it needs no security setup at all; it needs the right one for its size and its risk.
“Minimum” Doesn’t Mean “Weak”
The word “minimum” can be misleading. Minimum Viable Security doesn’t mean buying the cheapest tools or accepting unacceptable risk. It means building the smallest set of protections needed for a defensible baseline, given the business’s risk, its regulatory obligations, its most important assets, and what it can actually afford.
For one business, that baseline might include strong password and access controls, multi-factor authentication, secure backups, basic endpoint protection, an incident-response plan and staff awareness training. For another, more controls may be essential because of how sensitive its data is, or how it’s regulated.
Context matters here. IBM’s Cost of a Data Breach Report puts South Africa’s average breach cost at $2.37 million in 2025, the only African country IBM tracks in the study, and still a figure that would sink most SMEs on the continent outright.
So the MVS principle isn’t “do less security.” It’s “do the security that matters most, on purpose.”
Governance Is the Equaliser
This is where governance becomes critical. A well-funded organisation can sometimes cover poor decisions by buying more tools and hiring bigger teams. Resource-constrained businesses don’t have that option; they have to make better decisions instead.
Good governance is how that happens. Leadership needs to understand its risk appetite, know its critical processes, decide what level of risk it can live with, and choose deliberately where security spending goes, then write those decisions down.
That last part gets skipped too often. A business might decide not to implement a certain control because the risk is low, the control doesn’t fit the business, or another control already covers it. That can be a legitimate call — but it shouldn’t stay an unwritten conversation. A documented risk assessment and rationale turn “we can’t afford this” into a defensible, risk-based decision. That’s a very different thing.
Let Frameworks Guide, Not Overwhelm
International frameworks like ISO/IEC 27001, NIST and SOC 2 are genuinely useful for managing risk. The trouble starts when businesses treat them as shopping lists instead of guides.
A framework should help a business understand and manage its risk, not force it to adopt every possible control regardless of context. This matters especially in Africa. Businesses here shouldn’t feel they need to copy a Fortune 500 company’s security setup to look mature.
Instead, ask: Which parts of the framework actually apply to our risk? Which controls handle our biggest exposures? Where do requirements overlap, and can they be combined? What proof do we need that our controls actually work? These questions move cybersecurity away from a compliance checkbox exercise and toward real assurance.
Africa Can Build It Differently
Africa’s digital transformation is a genuine opportunity. Many organisations here are young, building digital systems and governance structures at the same time. That’s a challenge, but also an advantage: there’s no need to carry decades of old technology and duplicated controls.
Security can be designed intentionally from day one. Instead of asking how to copy security models built for resource-rich environments, African organisations can ask a better question: what does effective cybersecurity look like where resources are limited but digital dependence is growing fast? By 2025, Africa already had more than 1.1 billion mobile subscribers, according to INTERPOL’s 2026 assessment, and that number keeps climbing.
The answer isn’t a smaller copy of an enterprise programme. It’s a risk-optimised one, built around the business, focused on its most important assets, covering the essentials, documenting its decisions, and able to grow as the organisation does.
From Maximum Security to Sufficient Security
The future of cybersecurity shouldn’t be measured by how many controls a business has, how many tools it owns, or how big its security budget is. The better question is: does the organisation understand its risks, and has it done enough to manage the ones that matter most?
That’s the conversation Minimum Viable Security is meant to start. For businesses with limited money, cybersecurity doesn’t have to be all-or-nothing. There’s a middle ground, and that’s where risk-based decisions, prioritised controls and disciplined execution matter most.
Africa’s cybersecurity challenge is real, but our response shouldn’t be defined only by limited resources. We can build security programmes that are practical, defensible, and able to grow with our businesses.
The goal isn’t maximum security at any cost. It’s sufficient security, built deliberately around risk.
That may be one of the most important lessons coming out of Africa’s digital transformation.
AUTHOR
Charles Fiifi Hagan | Cybersecurity governance, risk, and compliance professional | Founder, Chayil SecureX | Member, IIPGH
For comments, email: hagancharles14@gmail.com