Cybersecurity for small businesses in Nigeria: where to start
Cyber Elias Academy
Team CEA
You do not need a big budget to meaningfully improve your security. Here is a practical starting point.
Most small businesses in Nigeria operate with minimal cybersecurity. Not because the owners do not care, but because security feels expensive, technical, and abstract until something goes wrong.
The good news is that the highest-impact security improvements are not the most expensive. Start with the basics: make sure every account has multi-factor authentication. Back up your critical data and test that you can actually restore it.
Next, think about your people. Most security incidents start with someone clicking something they should not. Regular, short training sessions work better than annual compliance lectures.
Start with the threats that actually hit Nigerian small businesses, because you cannot defend against everything at once. Business email compromise is number one by a wide margin: a fraudster impersonates your MD or a supplier and redirects a payment. One wrong transfer can wipe out months of revenue, and recovery is nearly impossible once funds leave the country through mule accounts. Phishing that harvests your banking credentials comes second. Ransomware is rising but still rarer here than abroad; data theft and invoice fraud are your real daily opponents.
Now the controls, in strict order of return on investment. First, enable two-factor authentication on everything — email, banking, your ERP, social media. This single step blocks the overwhelming majority of account-takeover attempts, and it is free. Second, buy a custom domain for email if you have not; running your business from a free Gmail address both looks unprofessional and makes impersonation trivially easy for fraudsters who register lookalike domains. Third, set up payment verification as policy: any change to supplier bank details, or any urgent transfer request, must be confirmed by phone call to a number you already have — never one from the email itself.
Fourth, patch ruthlessly but simply. Turn on automatic updates on every computer, and replace any machine still running Windows 7 or older — those machines are open doors sitting in your office. Fifth, back up properly using the 3-2-1 pattern: three copies of critical data, two different media, one copy offline or in cloud storage like Google Workspace or Microsoft 365 where version history lets you roll back ransomware-style encryption. Test the restore before you need it.
Your people need training, but keep it practical and short. Twenty minutes monthly beats an annual all-day seminar. Show real examples of phishing emails targeting Nigerian businesses — fake CBN circulars, spoofed supplier invoices, tax-refund lures from FIRS-lookalike domains. Run a simple drill: send your own staff a mock phishing email and see who clicks, then use it as a teaching moment, not punishment.
Know your regulatory position too. If you handle personal data of more than 1,000 data subjects, the NDPA applies to you, and the Nigeria Data Protection Commission has begun enforcing against SMEs, not just telcos. The obligations at this scale are modest: appoint someone accountable for data protection, keep basic records of what personal data you hold and why, and report significant breaches within 72 hours. Compliance here overlaps heavily with good security practice anyway.
Finally, write it down. A two-page document saying who approves transfers, how backups run, what staff must do when they spot a suspicious email turns intentions into habits. When an incident happens — and eventually something will — that document is the difference between a bad afternoon and an existential crisis. Security for a small business is not about buying the right logo sticker for your office door; it is about a handful of boring habits executed consistently.
At CEA, we train security teams for exactly this kind of practical, budget-conscious security. Start with the basics and build from there.