Latest Headlines
SECURING THE 2027 ELECTIONS
This requires a convergence of physical and cyber defences, argues KABIR ADAMU
Securing Nigeria’s 2027 elections will require a convergence of physical and cybersecurity defences capable of mitigating threat elements to the elections that span both physical and cyber domains. While physical security has traditionally been the focus of election planning, the digital domain is now equally critical, and the two must be integrated if Nigeria is to maintain a mature level of security preparedness for the elections. Current threat estimates show both physical and cyber threats to be at varying assessed levels that if not adequately mitigated will affect the Independent National Electoral Commission’s ability to conduct free, fair and credible elections in Nigeria come January and February, 2027.
The physical security challenges are complex and multifaceted and include terrorism and insurgency, banditry, gang violence and cultism, armed ethnic militia among others. According to data from Beacon Security and Innovations Limited (BSIL) a company I founded and run, and the international platform, Armed Conflict and Event Location Data (ACLED) from January – September, 2026 an average of 700 people are killed and another 500 abducted monthly across Nigeria, despite ongoing security forces operations that have successfully targeted and killed a significant number of the leadership of the violent actor groups operating in Nigeria. This is even as livelihoods continue to be destroyed by this threat actors with huge humanitarian and development consequences for communities where they remain active.
Similarly, Nigeria’s cyberspace has a multitude of institutional and structural challenges that manifest in diverse threats as the country increasingly digitizes its election infrastructure for the scheduled January and February 2027 national elections.
Nigeria is currently facing an average of 4,906 cyberattacks per organisation every week, more than twice the global average of 2,422, and a 45 per cent year-on-year increase, according to Check Point Research’s August 2026 threat intelligence. That volume eased only slightly from 4,975 weekly attacks in July, and leaves Nigeria second only to Angola among the African markets tracked. Across the continent, INTERPOL’s 2026 African Cyberthreat Assessment estimates at least $5 billion in direct economic damage from cybercrime in 2025, with reported losses more than doubling from $192 million in 2024 to $484 million. The measurable losses are concentrated in payments: banks and customers lost ₦52.26 billion to fraud in 2024 and ₦25.85 billion in 2025, for a cumulative ₦134.48 billion between 2020 and 2025 (CBN/NIBSS). An earlier multi-sector estimate put losses at about ₦1.1 trillion between 2017 and 2023 across banking, telecommunications and government. Nigeria also recorded 5,822 ransomware detections in 2025, including an August 2025 attack on the Nigeria Customs Service that froze cargo clearance and generated an estimated $18 million in storage costs. Critical digital infrastructure is increasingly being probed by state-aligned Advanced Persistent Threats. ngCERT and NCC-CSIRT have flagged SideWinder against maritime, government, telecommunications and financial targets, and a wider espionage pattern, including the UNC2814/GRIDTIDE campaign against telecom and government networks, aimed at long-term access to telecommunications backbones rather than immediate financial gain.
In the aftermath of the 2023 elections, the then Ministry of Communications and Digital Economy issued a statement where it indicated that in the lead up to the 2023 General Elections, its monitoring of threat intelligence revealed what it described as “an astronomical increase in cyber threats to Nigerian cyberspace”. The Ministry noted that “threats to public websites and portals averaged around 1,550,000 daily” and that “this skyrocketed to 6,997,277 on Presidential Election Day”.
These statistics are a glaring warning about the fragility of Nigeria’s physical and digital borders. But as we look toward the 2027 General Elections, the stakes are existential to our democracy. A significant effort has already been achieved in physical election security risk management. INEC has internal capabilities for election risk management. It also has the Inter-Agency Consultative Committee on Election Security, which comprises several security sector players and supports election security functions.
However, the cyber security function is not so mature compared to the physical security functions despite our democratic infrastructure now being almost entirely digitised. The Bimodal Voter Accreditation System (BVAS), the Result Viewing Portal (IReV), the National Register of Voters, and the vast digital communication networks used by political parties and the media are platforms that add additional exposure points and the new battlegrounds. We are no longer just looking at the risk of financial theft; we are looking at the very real potential for state-sponsored disruption, voter data manipulation, and AI-driven disinformation campaigns designed to undermine public trust in the electoral process.
Yet, as a nation, we are still flying with a fragmented radar. Currently, our cybersecurity capabilities and evaluations are trapped in regulatory silos. The Central Bank of Nigeria (CBN) mandates rigorous assessments for banks; the MCIDE supports several initiatives for securing the Nigerian cyberspace, including Cybersecurity Centers such as National Information Technology (NITDA)’s Computer Emergency Readiness and Response Team (CERRT), the Nigerian Communications Commission (NCC)’s Computer Security Incident Response Team (CSIRT), and Galaxy Backbone (GBB)’s Security Operations Centre (SOC).
It is worth noting that in the while these sector-specific efforts are commendable, they do not provide a consolidated, holistic view of our national cyber posture. More critically, there is no unified framework mapping the cross-sector, national threat to our democratic infrastructure.
We cannot secure what we do not comprehensively measure. It is time to institutionalise a unified National Cyber Threat Assessment (NCTA) and specifically tailor our national cyber capabilities to protect the 2027 elections. This requires the Office of the National Security Adviser (ONSA), the Independent National Electoral Commission (INEC), and the Federal Ministry of Communications, Innovation and Digital Economy to take the lead and advance a unified capability effort. Ad-hoc task forces and post-incident reactions will not suffice. Here is what intentional, institutionalised action must look like:
First, ONSA must institutionalise the NCTA for electoral security. ONSA, through the National Cybersecurity Coordination Centre (NCCC), must lead the development of an annual National Cyber Threat Assessment that specifically models the threat landscape for our electoral infrastructure. This should utilise a “dual-report” model: a public, unclassified guide to help political parties, media, and civil society combat disinformation, and a classified annex detailing state-sponsored APT tactics for the security architecture.
Second, INEC must elevate electoral technology to Critical National Information Infrastructure (CNII) status. Following the President’s landmark 2024 CNII Order, INEC must treat the BVAS, IReV, and the voter register with the same uncompromising rigor applied to the banking sector. This means mandating continuous, independent red-teaming of electoral systems, enforcing zero-trust architecture, and ensuring that the entire electoral technology supply chain is completely vetted against foreign compromise. It must also set up a similar interagency consultative committee to manage cyber security functions. There must also be a pathway for the two functions to support a secure electoral space in Nigeria.
Third, the Ministry of Communications, Innovation and Digital Economy must harden the underlying digital infrastructure and lead the counter-narrative. The Ministry holds the critical mandate for Nigeria’s digital economy and cybersecurity policy. It must ensure that the foundational digital infrastructure supporting the elections, including broadband networks, data centres, and cloud hosting environments, is structurally resilient and insulated from sabotage. Working in tandem with the Ministry of Information and National Orientation, the Ministry must spearhead a national counter-disinformation framework. This involves deploying AI-detection tools to combat deepfakes, coordinating a unified public communication strategy to maintain voter trust, and ensuring that a dedicated portion of the National Cybersecurity Levy is strategically deployed to fund these electoral tech defences.
Fourth, ONSA, INEC, and the Ministries must establish a dedicated Electoral Cyber Defence Node. Breaking down silos is non-negotiable. ngCERT, INEC, and the relevant ministries must establish a joint, real-time threat intelligence-sharing node specifically for the electoral cycle. This node should actively monitor for infrastructure probing and coordinated bot-network disinformation, sharing anonymised telemetry with telecommunications companies and civil society organisations in real-time to neutralise threats before they reach the public.
National security is economic security, but in 2027, a convergence of physical and cybersecurity will be electoral security. If we do not intentionally secure the physical and security and digital pipes of our democracy, we leave the next general elections vulnerable to the very syndicates and state-sponsored actors currently probing our physical and cyber networks.
Nigeria possesses the talent, the legal frameworks, and the institutional architecture to get this right and ONSA, INEC, the Ministry of Communications, Innovation and Digital Economy, and our entire national security architecture should move from reactive posturing to proactive, unified defence. The time to build the shield that protects our democratic mandate is now, as the threat vectors have already been deployed.
Dr. Adamu is the Managing Director of Beacon Security and Innovations Limited.






