Skip to main content

Africa and the Global Politics of Cybersecurity Governance

Page 1

Policy Brief No. 243 — August 2026

Africa and the Global Politics of Cybersecurity Governance Samuel Edem Assisi

Key Points → The global cyberspace governance field has expanded beyond state-centric models to include other non-state actors such as civil society, private-sector tech giants and multi-stakeholder fora. Nonetheless, the West/non-West binary has largely dominated cyberspace governance. → While uptake of the Malabo Convention remains uneven and slow, its ratification in 2023 signals a growing recognition among African countries of cybersecurity governance as a core pillar of digital sovereignty and regional stability. → Intensifying geopolitical rivalries and emerging threats to information integrity associated with the proliferation of generative artificial intelligence (AI) present new challenges. African states must strengthen cybersecurity governance and regulatory capacity to manage these threats. → Increased investment in cybersecurity infrastructure and capabilities, strengthening legal frameworks, enhancing international cooperation, promoting digital literacy and participating in global initiatives create a robust cybersecurity ecosystem.

Introduction Africa’s progress toward regulating its cyberspace was set during the twenty-third Assembly of the African Union Heads of State and Government, held in Malabo, Equatorial Guinea, in 2014, culminating in the adoption of the African Union Convention on Cyber Security and Personal Data Protection. Also known as the “Malabo Convention,” this agreement captures the continent’s goals for the governance of African cyberspace. While progress toward the ratification of the convention has been slow — it took nearly a decade for it to finally come into force in 2023 following ratification by the fifteenth member state — various initiatives by individual states acting separately to consolidate and build cybersecurity capabilities and frameworks have also been carried out. Noteworthy among these are the Regional Cybersecurity Summit for Africa in 2023, organized by the Uganda Communications Commission and the Uganda Computer Emergency Response Team, with support from AfricaCERT under the global leadership of the International Telecommunication Union (ITU) (2023), and the African Cybersecurity Summit held in Lomé, Togo, in 2022. In spite of these efforts, African states are deeply susceptible to cybercrime and other cyber vulnerabilities and have also been involved for nearly a decade in efforts to improve their security. However, relatively little has improved as evidenced by the growing prevalence of losses. This begs the


About the Author

question: What challenges do African states face in improving their cybersecurity protections? These challenges not only emanate domestically but also from regional and international sources.

Samuel Edem Assisi is a development and project management consultant with more than 15 years of experience in the nongovernmental sector. Edem has previously served as a special assistant and research assistant to the deputy minister in charge of the environment secretariat at the Ministry of Environment, Science, Technology and Innovation and the Parliament of Ghana for eight years. A trained teacher by profession, he holds a B.Ed. degree in social studies and economics from the University of Education, Winneba, and an M.A. in international affairs from the University of Ghana, Legon. Edem is currently pursuing his Ph.D. in international affairs at the Legon Center for International Affairs and Diplomacy, University of Ghana. He is also a research assistant on the Negotiating Africa’s Digital Partnerships policy research project supported by the Centre for International Governance Innovation and hosted at the Blavatnik School of Government, University of Oxford. His research interests include gender, international political economy, cybersecurity and foreign policy.

Global cyberspace governance and regulation have, for a long time, been characterized by the West-versus-the-non-West discourse, to the disadvantage of emerging cyber powers outside the two blocs. Several non-Western nations — notably, emerging cyber powers such as Brazil, China, Russia and South Africa — have questioned the Western-centric approach to cyber governance (Rebello 2017). Proponents of the Western-centric approach, including Australia, New Zealand, the United States and other nations, mostly in Europe, favour the open multilateral and normative regulatory approach whereby the private sector plays a significant role. This approach goes against the closed multilateral model championed by China, Egypt and Russia, for instance, which favours greater state involvement. These nonWestern nations contend that the current global cyber governance framework disadvantages newcomers. For instance, some nations, such as Ethiopia, Ghana, Nigeria and South Africa, to name a few, have declined to ratify the Council of Europe’s Convention on Cybercrime (Budapest Convention) (Ifeanyi-Ajufo 2023). These nations claim that the convention violates their right to state sovereignty in cyberspace. In the face of ongoing efforts, key states — such as Egypt, Ethiopia, Kenya, Morocco, Nigeria and South Africa — are still absent from the list of countries that have ratified the Malabo Convention. This is a testament to the slow pace of cybersecurity commitment, governance and regulation in Africa. Yet the Malabo Convention constitutes a critical pillar for the continent to establish its own norms around the regulation and governance of cyberspace. The added challenge is that amid competing external norms and discourses, African states must develop their own cyber norms at both the national and subregional levels to ensure their adaptability to the African context and alignment with the Agenda 20631 framework. Although African countries actively engage in global discussions on cybersecurity

1

2

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi

Agenda 2063 is the African Union’s 50-year strategic blueprint to build an integrated, prosperous and peaceful Africa by 2063. It sets out seven continent-wide aspirations, flagship programs and rolling 10-year implementation plans.


governance through myriad fora and institutions, their representation remains limited due to being part of the least digitalized continent (ibid.). This policy brief aims to provide an overview of the global politics of cybersecurity in Africa. It begins with an examination of the significance of cybersecurity governance in Africa, compares and analyzes various African approaches to regulation and governance, and discusses how these interact with the effects of geopolitical rivalries and compounding socioeconomic challenges unique to the continent. It concludes by offering recommendations on the path forward for African states.

The Malabo Convention: The Linchpin in Africa’s Cybersecurity Strategy The Malabo Convention represents a significant step toward establishing a comprehensive legal framework for cybersecurity and data protection across Africa. Adopted in 2014, the convention aims to address the growing challenges of cybercrime and data privacy on the continent, which are increasingly interconnected through digital technologies. In terms of scope, the convention consists of a broad document that focuses on cybercrime, privacy and data protection. The convention covers a wide range of issues, including cybersecurity, personal data protection and electronic transactions, making it one of the most comprehensive frameworks in Africa (Eno-Akpa 2016). Additionally, the convention prohibits various forms of cybercrime, including identity theft and spam, and addresses the use of encryption in cybercrime (ibid.). It further adopts strong privacy principles such as those in Europe, requiring the establishment of data protection authorities and addressing data export complexities (Greenleaf and Georges 2014). Recent reports indicate that less than half of the countries on the continent have ratified the convention, hampering its full impact. Others have also bemoaned the lack of legal, enforcement and institutional capacity on the continent (Eyitayo 2025; Onomrerhinor 2022; Ndubuisi 2023). Meanwhile, experts have recommended the convention’s integration with the African Continental Free Trade Agreement, its

alignment with other international frameworks and strong multi-stakeholder collaboration. While the Malabo Convention is a pivotal step toward enhancing cybersecurity and data protection in Africa, its success largely depends on widespread ratification and effective implementation. The convention’s potential to harmonize cybersecurity laws across the continent could significantly reduce cybercrime and enhance data privacy.

Examining African Positions in Global Cybersecurity As internet usage, including the use of AI tools, grows on the continent, African nations are now more exposed and vulnerable to cyberthreats. Malicious actors who are becoming increasingly organized use more advanced malware to attack and damage critical infrastructure; steal private data from businesses, politicians, citizens and activists throughout the continent; and cause annual losses amounting to billions of dollars. Nearly every African nation has experienced a widely reported disinformation campaign, often linked to external parties (Adu-Amanfoh and Allen 2023). Despite the continent’s relatively low digital infrastructural development, Africa is not spared from the growing costs of cybercrime and attacks worldwide. Official figures are limited, as many countries lack the infrastructure for precise reporting and the regulatory frameworks to mandate disclosure. Figures from Serianu’s 2017 Africa Cyber Security Report show that cybercrime cost Africa more than US$3.5 billion in losses that year (cited by Maphosa 2024, 5). More recent figures from the United Nations Economic Commission for Africa (2025) now put that number at US$20 billion — a significant increase. Recent figures, according to Ugwu Jovita Nnenna and Ugwuanyi Ifeoma Perpetua (2024), put the cost of cybercrime to Africa at US$4 billion in annual losses. Many African nations still lack comprehensive cybersecurity policies to counter these threats (Adu-Amanfoh and Allen 2023). They have yet to establish dedicated agencies; pass the prerequisite accompanying regulations, such as data protection laws; and build the necessary infrastructure to effectively monitor, detect and Africa and the Global Politics of Cybersecurity Governance

3


Table 1: Cybersecurity Policies by Country Region

Country

Cybersecurity Strategy

Kenya

National cybersecurity strategy 2025–2029 (second strategy)

Rwanda

National cybersecurity policy and strategy

Tanzania

National cybersecurity strategy

Uganda

National cybersecurity strategy

Côte d’Ivoire

National cybersecurity strategy

Ghana

National cybersecurity policy and strategy (2022)

Nigeria

National cybersecurity policy and strategy (2021)

Senegal

National cybersecurity strategy

Botswana

National cybersecurity strategy

Mauritius

National cybersecurity strategy

South Africa

National Cybersecurity Policy Framework (2015), Cybercrimes Act (2020)

Zambia

National cybersecurity strategy

Zimbabwe

National cybersecurity policy

Algeria

National cybersecurity strategy

Egypt

National cybersecurity strategy

Morocco

National cybersecurity strategy

Tunisia

National cybersecurity strategy

Cameroon

National cybersecurity strategy

Gabon

National cybersecurity policy

East Africa

West Africa

Southern Africa

North Africa

Central Africa

Source: See National Cybersecurity Strategies Repository (www.itu.int/en/ITU-D/Cybersecurity/ pages/national-strategies-repository.aspx).

4

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi


respond to large-scale cybersecurity incidents (Musoni, Karkare and Teevan 2024). Table 1 indicates the countries that currently have cybersecurity policies in place and the type of policies. Furthermore, experts bemoan the lack of preparedness in some African countries, as cybersecurity is not a priority for many African governments, especially those in low-income or conflict-prone countries (Ifeanyi-Ajufo 2023). However, the promotion of security and stability in the cyber ecosystem can be strengthened by implementing suitable regulations and constructing cooperative measures that may support effective cyber governance. In a borderless cyberspace, cooperative approaches foster shared accountability among governments, making cooperation essential for efficient cyber governance (Mueller 2020). Cyberspace regulation has gone through several phases of evolution and continues to unfold in many ways. The pace of transformation of Africa’s cyberspace has not been uniform. Countries with stable, democratic and peaceful governance structures, such as Benin, Ghana, Kenya, Mauritius, Nigeria, Senegal, South Africa and Togo, have made significant progress. Most of the countries with a stable outlook have cybersecurity laws in place, accompanied by the needed infractructure and enforcement mechanisms — though amid challenges. The countries with an unstable outlook generally lack the necessary laws and infrastructure needed to ensure cybersecurity. For instance, in addition to the countries named above, Sierra Leon has made significant strides in enacting laws, but many other countries on the continent have yet to enact laws — let alone talk of infrastructure — all of which complicates their cybersecurity readiness and heightens their threat levels (Nylander 2025; Tambo and Adama 2017).

The Role of Great-Power Rivalry in Cybersecurity Governance Most African states consider their national interest in dealing with foreign partners. The way that African governments understand and carry out cybersecurity governance is impacted by this alignment. African governments typically approach

diplomacy with compromises and varying degrees of reciprocity. African nations have, on several occasions, sided with China and Russia (IfeanyiAjufo 2023). This was demonstrated, for example, when Russia prominently spoke during the UN Convention against Cybercrime discussions on behalf of some African nations, such as Burkina Faso (ibid.; Global Economic Governance Programme 2023c). African nations tend to align more with China and Russia on cybersecurity and cyberspace governance, primarily due to shared preferences for state-centric digital sovereignty models that prioritize governmental control over information flows and national security over individual liberties. The institutional approach to cyber power demonstrated in the comparative analysis above reveals that “different political systems approach cybersecurity governance” in fundamentally distinct ways, with authoritarian and hybrid regimes emphasizing centralized control mechanisms (Boztosun Çalışkan 2025, 3). China’s concept of “cyber sovereignty” and Russia’s integrated information operations strategy resonate with many African governments seeking to manage political dissent, protect regime stability and assert territorial control over digital spaces within their borders. As there is a strong positive correlation between political stability and cybersecurity expenditure, nations prioritizing regime security naturally gravitate toward governance models that subordinate individual digital rights to state authority (ibid.). Furthermore, it is theorized that “strategic cultures shape the securitization of cyber threats across different national contexts” (ibid., 3), indicating that African nations’ alignment reflects deeper institutional preferences rather than purely technical considerations. Beyond governance philosophy, African nations’ alignment with China and Russia reflects pragmatic economic and geopolitical interests, including resistance to Western-dominated internet governance structures and pursuit of developmental partnerships that do not impose political conditionalities. Esra Merve Boztosun Çalışkan (ibid., 7) offers a compelling discussion on how “competing visions of cyber sovereignty influence international cooperation and conflict in cyberspace,” highlighting the fundamental divide between Western models emphasizing multistakeholder governance and alternative approaches favouring state control. China and Russia offer African nations technological infrastructure, cybersecurity capacity-building assistance and

Africa and the Global Politics of Cybersecurity Governance

5


diplomatic support without the human rights requirements typically attached to Western partnerships, creating attractive alternatives for governments prioritizing developmental autonomy. Boztosun Çalışkan (ibid., 16) noted that “institutional factors — particularly political stability…and corruption levels” are not conditionalities for China and Russia, suggesting that African nations facing governance challenges may view Chinese and Russian models as more compatible with their institutional realities. The Convention on Cybercrime (Budapest Convention), signed in November 2001, is a major international agreement addressing cybercrime and electronic evidence (Buçaj and Idrizaj 2024). It was developed through cooperation among the Council of Europe, Canada, Japan, South Africa and the United States. The convention offers a legal framework to promote international collaboration and standardize responses to cybercrime. It emphasizes the need for effective strategies across legal systems and encourages public-private cooperation in investigations. Only about 13 African nations have ratified the Budapest Convention (Ifeanyi-Ajufo 2025), but 32 African nations voted in favour of the resolution supported by Russia in December 2018 that mandated the UN Secretary-General to gather opinions from nations regarding cybercrime. Additionally, more than 30 African nations supported UN General Assembly (UNGA) Resolution 32, inspired by Russia, and sought to establish a new cybercrime pact in December 2019. This inclination toward Russia and China is further demonstrated by the disparity between the large support for the resolution to launch the Budapest Convention, which Russia spearheaded, and the small number of African nations that have ratified it.

To What Extent Is Africa Forging Its Own Path? African countries have actively engaged in international discussions on cybersecurity through various fora, such as the United Nations, the ITU and regional organizations. This was evident at the onset of the Group of Governmental Experts (GGE), established by the United Nations in 2004, which lasted until 2021, and the Open-Ended Working

6

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi

Group (OEWG), which was also established in 2018 but concluded its work in 2021, with another term extending from 2021 to 2025 in which African nations were represented, although in a limited way (Ifeanyi-Ajufo 2023; Kim 2022; Teleanu and Kurbalija 2022, 99–102). The GGE’s first meeting in 2004 had 25 members, out of which only two were from Africa, Mali and South Africa. Subsequently, the number of African members increased to include Egypt, Ghana, Kenya, Mauritius, Morocco and Senegal (Teleanu and Kurbalija 2022, 99). Sixteen African nations (Algeria, Botswana, Cameroon, Côte d’Ivoire, Egypt, Ethiopia, Ghana, Kenya, Malawi, Mauritius, Morocco, Mozambique, Nigeria, South Africa, Uganda and Zimbabwe) participated in the OEWG in 2019–2021. Out of 719 interventions, 69 were made by these 16 countries. The following five target countries have made contributions to OEWG work: Côte d’Ivoire, Ghana, Kenya, Nigeria and South Africa. Out of 719 interventions, these five countries made 27 interventions (ibid., 100). Many African nations have expressed support for multilateral approaches to cybersecurity governance, which entails creating cyber norms for states. The First Committee of the UNGA oversees most of the cybersecurity initiatives. Under a new UN GGE on developments in the field of information and telecommunications in the context of international security, previous efforts to define and operationalize cyber norms are still ongoing. Concurrently, a second OEWG was established by the UNGA, although with a more inclusive mandate for interested member states (Ruhl et al. 2020). Three competing forms of cyber governance exist: the open multi-stakeholder, the repressive multilateral and the open multilateral (Glen 2014). The United States has chosen the open multi-stakeholder model, which is the most open form of governance in terms of actors and aims. Encompassing civil society, governments, corporate entities and non-governmental organizations, this model addresses values such as transparency and neutrality on the internet (ibid.). In contrast, the repressive multilateral model uses the internet for domestic security and strengthens state control over cyber governance. Governments are viewed as the primary actors in both the open multilateral and the repressive multilateral models, yet their goals set them apart. The repressive multilateral is reflected in the


positions taken by countries such as Algeria, China, Egypt, Russia, Saudi Arabia and Sudan (ibid.).

Examples of Success A preliminary examination of Ghana’s methodology regarding cybersecurity highlights the country’s use of a multi-stakeholder framework (Adu-Amanfoh and Allen 2023). The Ministry of Communication, Digital Technology and Innovations leads the country’s efforts, working closely with key actors through the Joint Cybersecurity Committee, which includes stakeholders from the Ministry of Foreign Affairs and Regional Integration, the Ministry of the Interior, the National Communications Authority and various civil society groups. Ghana has also established a modern data centre and a robust identification system and is pushing digitalization across all sectors (ibid.). According to senior officials, Ghana’s cyber governance negotiation teams typically include representatives from the government, the private sector, academia and civil society. Officials interviewed by the author also confirmed that cybersecurity has been a major focus in recent years, with the Global Conference on Cyber Capacity Building — hosted in 2024 by the Government of Ghana in Accra — noted as especially relevant. The situation is not too different in other countries. For instance, Togo’s Ministry of Digital Economy and Digital Transformation has spearheaded engagements and collaborations with the private sector to establish its first national Computer Emergency Response Team and Security Operations Centre, two fundamental elements of the country’s cybersecurity apparatus (Soulé 2024, 7–9). Likewise, in Senegal, the Ministry of Communication, Telecommunications and Digital Affairs collaborates with Sénégal Numérique SA, whose role is to lead private-public partnerships. Another example is that of Niger Telecoms, the national telecommunications operator, which is owned and run by the Government of Niger. At every level of the telecom industry, the national telecom operator is present, and the leverage of its infrastructure is needed to build fibre networks in Niger (ibid., 31–33). Increasing investment in cybersecurity infrastructure and capabilities, strengthening legal frameworks, enhancing international cooperation,

promoting digital literacy and participating in global initiatives are crucial for establishing a robust cybersecurity ecosystem. These strategies collectively address the multifaceted nature of cyberthreats, ensuring a comprehensive defence mechanism against evolving digital risks. By integrating these elements, nations can create a resilient digital environment that safeguards critical infrastructure, protects data privacy and fosters economic growth (Thakur and Raut 2024). Investing in cybersecurity infrastructure is essential for developing advanced technologies and systems to detect, respond to and mitigate cyberthreats. This includes the implementation of encryption, firewalls and intrusion detection systems (ibid.). Robust legal frameworks, such as the European Union’s General Data Protection Regulation (GDPR), establish accountability and compliance with national and international regulations (Bhange 2025); harmonizing cyber laws and enhancing enforcement mechanisms are vital for addressing cross-border cybercrimes and ensuring data protection (Karvatska, Manyk and Stroich 2025). In Ghana, for instance, there is a data protection law and infrastructure in place alongside the cybercrime unit for law enforcement. Additionally, enhancing international cooperation is crucial for combatting transnational cybercrime. Countries such as India engage in bilateral and multilateral partnerships to harmonize cyber laws and participate in information-sharing networks (Pratap 2025). Likewise, countries such as Ghana, Nigeria, Senegal and Togo, among others, are cooperating and sharing information. Global initiatives, such as the Budapest Convention, aim to harmonize national legislation and strengthen international cooperation (Karvatska, Manyk and Stroich 2025). All these are vital lessons for African countries to learn from and to bring them closer to ratifying the Malabo Convention, which is largely seen as the panacea for cybercrimes. Similarly, promotion of digital literacy and cybersecurity awareness at all organizational and societal levels is essential for building a strong defence against cyberthreats (Sendjaja et al. 2024). Awareness programs and digital literacy initiatives help individuals and organizations understand and mitigate cyber risks (Bhange 2025). Participation in global, regional and subregional initiatives such as those led by international organizations (for example, the International

Africa and the Global Politics of Cybersecurity Governance

7


Criminal Police Organization and the UN Office on Drugs and Crimes) enhances a nation’s ability to respond to cyberthreats (Pratap 2025). Regional initiatives, such as those in Europe, focus on harmonizing regulatory approaches and enhancing interstate coordination, and may also suggest models for adoption within African countries (Vivchar, Postel’zhuk and Valiukh 2025).

Challenges Africa’s overreliance on foreign suppliers of technological infrastructure and equipment is a major source of cybersecurity vulnerability (Allen 2024). Several key structural barriers hinder the development and implementation of effective cybersecurity policies (Basit et al. 2023). Legal complexities, such as constitutional and jurisdictional issues, prevent the free exchange of cyberthreat information, limiting collaboration and delaying the timely adoption of cybersecurity measures. Technological interoperability is also a significant challenge, with disparate systems across sectors and countries creating fragmented cybersecurity efforts. To address these issues, it is recommended that countries strengthen legal frameworks, invest in universal cybersecurity standards and foster public-private partnerships to improve collaboration. Additionally, enhancing data governance and addressing the shortage of cybersecurity professionals are crucial for overcoming these barriers. Poor data management and the inadequate enforcement of cybersecurity policies undermine efforts to create secure digital environments. Governments must therefore prioritize developing robust data governance frameworks to protect sensitive information and ensure compliance with international standards. The shortage of skilled cybersecurity professionals is another critical concern, which to address requires substantial investments in education and training programs. These solutions provide a pathway for governments and organizations to build more resilient and effective cybersecurity infrastructures. African countries have frequently highlighted the digital divide as a crucial issue in global cybersecurity discussions. The phenomenon of the digital divide encapsulates multiple dimensions that significantly contribute to inequities in both

8

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi

access to and use of digital technologies. Four pivotal dimensions — infrastructure, skills, devices and platforms — exert substantial influence on the formulation of digital equity. Grasping these dimensions is imperative for tackling the obstacles presented by the digital divide (ibid.). First, regarding infrastructure, the literature indicates that many regions in Africa, particularly rural areas, lack essential infrastructure, such as reliable electricity and internet connectivity, which hinders access to digital resources (Jibrin, Oyinvwi and Ibrahim 2024). The disparity in infrastructure is often exacerbated by socioeconomic factors, leading to unequal access to educational technologies and online resources (Kuteesa, Akpuokwe and Udeh 2024). The skills dimension relates to digital literacy, which remains a significant barrier, as many individuals lack the necessary skills to use digital technologies effectively (Leaning and Averweg 2021). Educational institutions often face challenges in providing adequate training, which limits the ability of citizens to engage with digital platforms and tools (Jibrin, Oyinvwi and Ibrahim 2024). In relation to devices, access to technologies such as computers and smartphones is uneven, with many individuals unable to afford or obtain them (Mutsvairo and Ragnedda 2019). The rise of mobile telephony has improved access to some extent, but disparities based on socio-economic status and geographical location persist (ibid.). The platforms dimension echoes the availability and accessibility of digital platforms, which vary widely, with many communities lacking access to essential online services and educational resources (Kuteesa, Akpuokwe and Udeh 2024). Innovative solutions, such as mobile learning programs, are being implemented to bridge these gaps, yet challenges remain in widespread adoption (Jibrin, Oyinvwi and Ibrahim 2024). The rapid emergence of AI, especially regarding content creation, disinformation and misinformation, poses significant cybersecurity challenges in Africa. AI’s ability to generate realistic fake content, such as deepfakes, and its use in spreading disinformation can destabilize political landscapes and undermine democratic processes. The sophistication of AI technologies makes it difficult to distinguish between real and fake content, posing a threat to public trust and national security. AI technologies enable the creation of fake content that can be used to manipulate public


opinion and spread misinformation (Effoduh 2025). It is asserted that some of these disinformation campaigns can be personalized and targeted, making them more effective and harder to detect (Mazurczyk, Lee and Vlachos 2023). AI-driven disinformation poses a significant threat to cybersecurity by exploiting algorithmic vulnerabilities and through its use in influence operations. The rapid dissemination of false information can disrupt trust in digital ecosystems and manipulate public perception (Bangalore Ghouse Khan 2025). African countries face peculiar challenges in establishing effective supranational instruments to combat cyberattacks, which hinders their ability to address these threats collectively (Pantserev 2022). Addressing these gaps is essential to ensuring that all nations, regardless of their level of development, can effectively participate in the digital economy and protect themselves against cyberthreats. In Africa, data protection is much less uniform and is governed by the Malabo Convention, which was only ratified by a small number of nations. As of 2025/2026, of the 55 countries on the continent, 21 have signed the agreement, while 16 have ratified it (African Union 2024). In contrast, data protection in the European Union is governed and safeguarded under the GDPR. An estimated 700 data centres are expected to spring up across the continent in the coming years (Soulé 2024, 71–76). The lack of basic infrastructure needed to propel the development of cyberspace-dependent infrastructure, such as a stable supply of electricity, is a major challenge. Across the continent, most African nations are still grappling with access to reliable electricity. In a similar fashion, there has been little or no investment in digital infrastructure in most countries where poverty and political instability are prevalent. African nations often emphasize the need for capacity-building initiatives to enhance their ability to prevent, detect and respond to cyberthreats. These include support for training programs, technology transfer and knowledge sharing. The issues of capacity building and transfer of knowledge have been major determinants in Africa’s desire for cybersecurity governance. In the field of education and research, the West and Central African Research and Education Network promotes synergies between countries on higher education research matters (Soulé 2024, 19–21).

In Ghana, the main challenges being confronted, as recorded by senior-level officials from the Ministry of Communications, Digital Technology and Innovations, include the transnational nature of cyberthreats, legal requirements and legislation, rapid technological developments in the field, limited capacity in the legislature to deal with these threats, limited resources and varied interests among stakeholders. Another challenge is the varying adherence to norms by governments, businesses, proxy actors and other stakeholders. The inherent characteristics of the cyber domain, in particular the low barrier to entry to building and employing cyber capabilities, create challenges for multi-stakeholder collaboration. Similar to the above, the lack of transparency regarding state action makes it difficult to gauge norm adherence, to distinguish between “aspirational norms” and real “norms,” and to evaluate the degree of conformance between crucial players in the sector. Another key challenge is the lack of explicit incentives for internalizing norms, such as stating the costs associated with not adopting and implementing one or more cyber standards, or the specific advantages of doing so.

Recommendations African nations must further develop a cyber governance agenda as discussions about digital transformation become more and more crucial on the continent. A comprehensive framework for cyber governance is needed, and a coordinated strategy would be beneficial. The adoption of the Malabo Convention by African member states may be the solution for a unified continent with common norms, standards and values. This would lay the groundwork for a regional approach to cyber governance. The rapid emergence of AI, along with its sophistication in relation to content creation, disinformation and misinformation, is another area of concern for the African continent. AI-generated propaganda has been associated with electoral manipulation in countries such as Mali and Nigeria, as sophisticated AI tools have made it easy to generate convincing messages before and during elections, thereby raising the stakes involved (Okolo 2024). AI can also be leveraged to enhance cybersecurity, by detecting and neutralizing

Africa and the Global Politics of Cybersecurity Governance

9


disinformation through machine-learning classifiers and network analysis (Bangalore Ghouse Khan 2025). However, the integration of AI into cybersecurity practices is not without challenges, such as adversarial attacks and algorithmic bias (Grover and Malhotra 2023). There is a need for robust frameworks and ethical considerations in the development and deployment of AI technologies to ensure they are used responsibly (Aiwekhoe 2024). African governments must improve national regulatory frameworks to include AI-detection security features and public awareness, as well as incorporate fact-checking tools into programs. These discussions should also include how to manage the proliferation of generative AI and mitigate the destabilizing effects that its misuse (for example, in disinformation campaigns) can cause, especially ahead of and during elections. Major African nations, especially middle-income ones such as Egypt, Ghana, Mauritius, Morocco and South Africa, could also take the lead and mentor others. The Malabo Convention, which is already in effect, may provide a framework for harmonizing strategies and modifying specific provisions to better meet regional requirements, if carried out in a transparent and accountable manner. To unlock the full potential of the Malabo Convention, major cyber powers on the continent that have yet to ratify the convention, such as Egypt, Kenya, Nigeria and South Africa, must ratify it too. Other recommendations include: → increasing investment in cybersecurity infrastructure and capabilities; → strengthening legal frameworks and enforcement mechanisms; → enhancing international cooperation and information sharing; → promoting digital literacy cybersecurity awareness; and → actively participating in global, regional and subregional initiatives to shape cyberspace norms and regulations. With regard to cyber governance, subregional African organizations are pursuing independent strategies and have lacked explicit or enforceable obligation to the African Union Commission as far back as 2011, when the Economic Community of

10

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi

West African States was seeking harmonization of cybersecurity laws, and 2012, when the Southern African Development Community made decisions regarding the adoption or prioritization of any cyber governance strategy, even though this may be a positive development reflecting broader subregional integration and cooperation in Africa (Ifeanyi-Ajufo 2023). Each subregional entity is autonomous. This seeming autonomy could either be positive or negative for norm adoption, hence the need to harmonize all norms at the continental level.

AI Disclosure AI Tools: QuillBot, SciSpace, Google Scholar and Microsoft Copilot were used; Data Analysis: Microsoft Copilot was used to verify identified themes from open-ended responses; Privacy and Security: No data was shared with any site nor any AI tool used during the writing process; Writing — Review & Editing: SciSpace and QuillBot were used in the literature review and for paraphrasing.


Works Cited Adu-Amanfoh, Kenneth and Nate D. F. Allen. 2023. “Learning from Ghana’s Multistakeholder Approach to Cyber Security.” Africa Center for Strategic Studies, January 3. https://africacenter.org/spotlight/ ghana-multistakeholder-cyber-security/.

Eyitayo, Afifoluwa. 2025. “Pre-Service Teachers’ Digital Competence and Readiness for Innovative Pedagogies in Teacher Education Programmes.” Journal of Learning and Educational Nexus 1 (1): 8–15. https://jolenexus.com/ index.php/jolenexus/article/view/3/2.

African Union. 2024. “List of countries which have signed, ratified/acceded to the African Union Convention on Cyber Security and Personal Data Protection.” July 8. https://au.int/sites/default/files/treaties/29560-slAFRICAN_UNION_CONVENTION_ON_CYBER_ SECURITY_AND_PERSONAL_DATA_PROTECTION.pdf.

Glen, Carol M. 2014. “Internet Governance: Territorializing Cyberspace?” Politics & Policy 42 (5): 635–57. https://doi.org/10.1111/polp.12093.

Aiwekhoe, Philip. 2024. “The Future of Artificial Intelligence and Cybersecurity.” Advances in Multidisciplinary and Scientific Research Journal 3 (1): 91–96. https://doi.org/10.22624/aims/csean-smart2024p9. Allen, Nate. 2024. “Demystifying External Actor Influence in Africa’s Technology Sector.” Africa Center for Strategic Studies, November 12. https://africacenter.org/spotlight/ external-actor-influence-africa-technology-sector/. Bangalore Ghouse Khan, Ummer Khan Asif. 2025. “Disinformation Security at the Nexus of Cybersecurity and AI: Defending digital ecosystems against automated deception.” World Journal of Advanced Engineering Technology and Sciences 15 (2): 2618–25. https://doi.org/10.30574/wjaets.2025.15.2.0813. Basit, Abdul, Tehmina Fiaz Qazi, Abdul Aziz Khan Niazi and Ifra Aziz Khan Niazi. 2023. “Structural Analysis of the Barriers to Address Cyber Security Challenges.” Journal of Policy Research 9 (1): 221–36. https://doi.org/10.5281/zenodo.7908753. Bhange, Baliram M. 2025. “Understanding Cyber Law and Security.” Gurukul International Multidisciplinary Research Journal 3 (13): 41–44. https://doi.org/10.69758/gimrj/2503i3iivxiiip0007. Boztosun Çalışkan, Esra Merve. 2025. “Institutional Foundations of Cyber Power: Comparative Security Governance in the US, China, Russia, and Turkey.” Preprint, Research Square, June 30. https://doi.org/10.21203/rs.3.rs-6682417/v1.

Greenleaf, Graham and Marie Georges. 2014. “The African Union’s Data Privacy Convention: A Major Step Toward Global Consistency?” Privacy Laws & Business International Report 131: 18–21. https://papers.ssrn.com/ sol3/papers.cfm?abstract_id=2546652. Grover, Tarun and Harmeet Malhotra. 2023. “Artificial Intelligence in Cyber Security: Review Paper on Current Challenges Faced by the Industry.” International Journal of Science and Research 12 (12): 741–47. https://doi.org/10.21275/sr231206140043. Ifeanyi-Ajufo, Nnenna. 2023. “Cyber governance in Africa: at the crossroads of politics, sovereignty and cooperation.” Policy Design and Practice 6 (2): 146–59. https://doi.org/10.1080/25741292.2023.2199960. ———. 2025. “The AU can help African countries adopt the UN cybercrime convention. But the challenges are significant.” Chatham House, October 31. www.chathamhouse. org/2025/10/au-can-help-african-countries-adoptun-cybercrime-convention-challenges-are-significant. ITU. 2023. “Regional Cybersecurity Summit for Africa.” November 20–23. www.itu.int/en/ITU-T/ Workshops-and-Seminars/2023/1120/Pages/default.aspx. Jibrin, Mohammed Ahmed, U. V. Oyinvwi and Akwaden Joshua Ibrahim. 2024. “Innovative Educational Technologies for Africa: Bridging the Digital Divide.” International Journal of Educational Research and Library Science 6 (8): 97–107. https://doi.org/10.70382/tijerls.v06i8.008.

Buçaj, Enver and Kenan Idrizaj. 2024. “The need for cybercrime regulation on a global scale by the international law and cyber convention.” Multidisciplinary Reviews 8 (1): 2025024. https://doi.org/10.31893/multirev.2025024.

Karvatskа, Svitlana, А. Z. Manyk and M. I. Stroich. 2025. “Cyber security: current challenges and international legal framework for data protection.” [In Ukrainian.] Naukovij Vìsnik Užgorods‘kogo Nacìonal’nogo Unìversitetu 4 (87): 251–56. https://doi.org/10.24144/2307-3322.2025.87.4.39.

Effoduh, Okechukwu (Jake). 2025. “The Role and Potential of Artificial Intelligence in Extremist Fuelled Election Misinformation in Africa.” February 10. Toronto Metropolitan University. https://doi.org/10.32920/28382090.

Kim, Saeme. 2022. “Roles and Limitations of Middle Powers in Shaping Global Cyber Governance.” The International Spectator 57 (3): 31–47. https://doi.org/10.1080/03932729.2022.2097807.

Eno-Akpa, Rene Nkongho. 2016. “The Case for an African Solution to Cybercrime: A Critical Assessment of the African Union Convention on Security in Cyberspace and Personal Data Protection.” Mtafiti Mwafrika (African Researcher) Monography Series No. 31. https://ir.umu.ac.ug/ items/8824ce44-395a-4285-9f06-d2b6547c6191.

Kuteesa, Kevin Namiiro, Chidiogo Uzoamaka Akpuokwe and Chioma Ann Udeh. 2024. “Theoretical Perspectives on Digital Divide and ICT Access: Comparative Study of Rural Communities in Africa and the United States.” Computer Science & IT Research Journal 5 (4): 839–49. https://doi.org/10.51594/csitrj.v5i4.1045.

Africa and the Global Politics of Cybersecurity Governance

11


Leaning, Marcus and Udo Richard Averweg. 2021. “Dimensions of the Digital Divide.” In Encyclopedia of Information Science and Technology, 5th ed., edited by Mehdi Khosrow-Pour, 1672–82. Hershey, PA: IGI Global Scientific. https://doi.org/10.4018/978-1-7998-3479-3. Maphosa, Vusumuzi. 2024. “An overview of cybersecurity in Zimbabwe’s financial services sector.” F1000Research 12: 1251. https://f1000research.com/articles/12-1251. Mazurczyk, Wojciech, Dongwon Lee and Andreas Vlachos. 2023. “Disinformation 2.0 in the Age of AI: A Cybersecurity Perspective.” Preprint, arXiv, June 8. https://arxiv.org/abs/2306.05569. Mueller, Milton L. 2020. “Against Sovereignty in Cyberspace.” International Studies Review 22 (4): 779–801. https://doi.org/10.1093/isr/viz044. Musoni, Melody, Poorva Karkare and Chloe Teevan. 2024. “Crossborder data flows in Africa: Continental ambitions and political realities.” Discussion Paper No. 379. Maastricht, Netherlands: ECDPM. https://ecdpm.org/work/cross-border-dataflows-africa-continental-ambitions-and-political-realities. Mutsvairo, Bruce and Massimo Ragnedda, eds. 2019. Mapping the Digital Divide in Africa: A Mediated Analysis. 1st ed. Amsterdam, Netherlands: Amsterdam University Press. https://doi.org/10.5040/9789048561476. Ndubuisi, Amarachi Francisca. 2023. “The impact of international cybersecurity treaties on domestic cybercrime control and national critical infrastructure protection.” World Journal of Advanced Research and Reviews 20 (3): 2285–304. https://doi.org/10.30574/wjarr.2023.20.3.2549. Nnenna, Ugwu Jovita and Ugwuanyi Ifeoma Perpetua. 2024. “Addressing the Escalating Threat of Cybercrime in African Nations: Strategies for Legislation, Governance, and Capacity Building.” International Digital Organization for Scientific Research Journal of Communication and English 9 (1): 8–10. https://doi.org/10.59298/IDOSR/JCE/91.810.202411. Nylander, Joseph. 2025. “The New Frontier of Peace: Integrating Cybersecurity into Sierra Leone’s Security Sector Reform.” International Journal of Innovative Science and Research Technology 10 (9): 97–102. https://doi.org/10.38124/ijisrt/25sep125.

Rebello, Katarina. 2017. “Building Walls with ‘BRICS’? Rethinking Internet Governance and Normative Change in a Multipolar World.” In Rising Powers and Global Governance: Opportunities, Challenges, and Change, 25–40. CGC Junior Scholar Working Paper Series 1 (1). Centre for Global Constitutionalism, University of St. Andrews. Ruhl, Christian, Duncan B. Hollis, Wyatt Hoffman and Tim Maurer. 2020. Cyberspace and Geopolitics: Assessing Global Cybersecurity Norm Processes at a Crossroads. February 26. Washington, DC: Carnegie Endowment for International Peace. https://carnegieendowment.org/ research/2020/02/cyberspace-and-geopolitics-assessingglobal-cybersecurity-norm-processes-at-a-crossroads. Sendjaja, Theodorus, Irwandi, Erwan Prastiawan, Yunita Suryani and Endang Fatmawati. 2024. “Cybersecurity In The Digital Age: Developing Robust Strategies To Protect Against Evolving Global Digital Threats And Cyber Attacks.” International Journal of Science and Society 6 (1): 1008–19. https://doi.org/10.54783/ijsoc.v6i1.1098. Soulé, Folashadé. 2024. Negotiating Africa’s Digital Partnerships amid Geopolitical Competition. Special Report. Waterloo, ON: CIGI. www.cigionline.org/publications/negotiatingafricas-digital-partnerships-amid-geopolitical-competition/. Tambo, Ernest and Kazienga Adama. 2017. “Promoting cybersecurity awareness and resilience approaches, capabilities and actions plans against cybercrimes and frauds in Africa.” International Journal of Cyber-Security and Digital Forensics 6 (3): 126–38. Teleanu, Sorina and Jovan Kurbalija. 2022. Stronger digital voices from Africa: Building African digital foreign policy and diplomacy. November. DiploFoundation. www.diplomacy.edu/wp-content/uploads/2022/11/ Stronger-digital-voices-from-Africa.pdf. Thakur, Rajani Manoj and Neha Mahesh Raut. 2024. “Cyber Security.” International Journal of Science and Research 13 (1): 440–44. https://doi.org/10.21275/mr231228122722.

Okolo, Chinasa T. 2024. “African Democracy in the Era of Generative Disinformation: Challenges and Countermeasures against AI-Generated Propaganda.” Preprint, arXiv, July 10. https://doi.org/10.48550/ARXIV.2407.07695.

United Nations Economic Commission for Africa. 2025. Cybersecurity for Development in the Fourth Industrial Revolution. Addis Ababa, Ethiopia: United Nations Economic Commission for Africa. https://africarenewal.un.org/sites/ default/files/documents/cybersecurity-developmentfourth-industrial-revolution-research-report.pdf.

Onomrerhinor, Flora Alohan. 2022. “Eliminating Safe Havens for Transnational Cybercrimes in the African Continental Free Trade Area.” Journal of Intellectual Property and Information Technology Law 2 (1): 49–81. https://doi.org/10.52907/jipit.v2i1.206.

Vivchar, Іnna, Oleksandr Postel’zhuk and Lyudmila Valiukh. 2025. “Cybersecurity as a Sphere of International Cooperation During the Global Security Crisis.” [In Ukrainian.] Vìsnik Nacìonal’noï Ûridičnoj Akademìï Ukraïni Ìmenì Âroslava Mudrogo 2 (65): 122–43. https://doi.org/10.21564/2663-5704.65.331787.

Pantserev, Konstantin A. 2022. “Malicious Use of Artificial Intelligence in Sub-Saharan Africa: Challenges for Pan-African Cybersecurity.” Vestnik RUDN. International Relations 22 (2): 288–302. https://doi.org/10.22363/ 2313-0660-2022-22-2-288-302.

12

Pratap, Ajay. 2025. “Strengthening Global Cybersecurity: India’s Engagement in International Cybercrime Control.” Stallion Journal for Multidisciplinary Associated Research Studies 4 (2): 315–19. https://doi.org/10.55544/sjmars.4.2.21.

Policy Brief No. 243 — August 2026 • Samuel Edem Assisi


About CIGI

Credits

The Centre for International Governance Innovation (CIGI) is an independent, non-partisan think tank whose peer-reviewed research and trusted analysis influence policy makers to innovate. Our global network of multidisciplinary researchers and strategic partnerships provide policy solutions for the digital era with one goal: to improve people’s lives everywhere. Headquartered in Waterloo, Canada, CIGI has received support from the Government of Canada, the Government of Ontario and founder Jim Balsillie.

Director, Programs Dianna H. English

À propos du CIGI Le Centre pour l’innovation dans la gouvernance internationale (CIGI) est un groupe de réflexion indépendant et non partisan dont les recherches évaluées par des pairs et les analyses fiables incitent les décideurs à innover. Grâce à son réseau mondial de chercheurs pluridisciplinaires et de partenariats stratégiques, le CIGI offre des solutions politiques adaptées à l’ère numérique dans le seul but d’améliorer la vie des gens du monde entier. Le CIGI, dont le siège se trouve à Waterloo, au Canada, bénéficie du soutien du gouvernement du Canada, du gouvernement de l’Ontario et de son fondateur, Jim Balsillie.

This publication’s analysis was developed and approved by the named human authors under documented review controls; AI assistance was judicious, disclosed and verified.

Copyright © 2026 by the Centre for International Governance Innovation The opinions expressed in this publication are those of the author and do not necessarily reflect the views of the Centre for International Governance Innovation or its Board of Directors. For publications enquiries, please contact publications@cigionline.org.

The text of this work is licensed under CC BY 4.0. To view a copy of this licence, visit http://creativecommons.org/licenses/by/4.0/. For reuse or distribution, please include this copyright notice. This work may contain content (including but not limited to graphics, charts and photographs) used or reproduced under licence or with permission from third parties. Permission to reproduce this content must be obtained from third parties directly. Centre for International Governance Innovation and CIGI are registered trademarks. 67 Erb Street West Waterloo, ON, Canada N2L 6C2 cigionline.org

Senior Program Manager Ifeoluwa Olorunnipa Publications Editor Susan Bubak Graphic Designer Sami Chouhdary


Turn static files into dynamic content formats.

Create a flipbook
Africa and the Global Politics of Cybersecurity Governance by Centre for International Governance Innovation - Issuu