
Across Africa, organisations are increasing their investments in infrastructure and systems to curb cybersecurity breaches, with available data showing that in 2024/25, the continent invested an estimated $15.3 billion in cybersecurity.
More recently, Kenya for instance, unveiled a new Sh468 million ($3.6 million) 36-month Kenya Cyber Resilience (KCR) Project backed by the European Union, designed to strengthen the country’s cyber resilience.
These rising investments are taking place against the backdrop of an attendant and relentless growth in cyber threats, attacks and losses. The ITU Global Cybersecurity Index recorded a 22-point average score increase for African countries between 2021 and 2024, halving the gap with the global average, reflecting a continent building capacity at pace.
Banks have built security operations centres. Telecoms have invested in threat monitoring. Regulators have introduced increasingly demanding requirements. Businesses run penetration tests, buy cyber insurance and invest in business continuity.
Artificial intelligence is now accelerating this investment further, letting security teams analyse threats and automate response at unprecedented speed.
More organisations have more cybersecurity technology, specialists and dashboards than at any point in their history.Yet a simple question remains difficult for many executives and boards to answer: why are they still vulnerable?
The answer lies in the depth and breadth of technology integration used to deliver the entire customer value and experience, in both the public and private sectors. And how the leaders are approaching the management of the entire cybersecurity problem.
The reality is that technology is inseparable from creating and delivering value to customers and the general public. For instance, a bank cannot serve customers when digital channels fail. A retailer depends on digital payments.
A logistics company depends on connected platforms and data to move goods. Governments depend on digital infrastructure to deliver public services.
But there is new thinking that states it is time for us to move from cybersecurity management to resilience. In a research paper titled ‘From cybersecurity to cyber resilience: a systemic and scalable approach for improving resilience and adaptive capacity, Ryan Hilger points out that the rising complexity, impact and intensity of cybersecurity threats call for more interdisciplinarity that results in holistic organisational governance.
His thesis supports the notion of a cybersecurity management paradox where an organisation can hold enormous amounts of information and still struggle to understand its actual resilience.
To understand the shift, one needs to see how the practice has evolved. Over the past decade or so, cybersecurity has grown into specialist disciplines: risk, technology, security operations, compliance, audit, continuity, insurance.
Each understands its own slice extremely well. Cybersecurity developed vertically. No single capability tells management whether the organisation, as a whole, is resilient. Resilience must be understood horizontally, because it runs across all of them.
We are not advocating abandoning cyber risk management. Strong cybersecurity operations remain essential, but sit inside a larger management challenge.
Cyber risk management tells us what could happen. Resilience management asks harder questions: if this event occurs, would we detect it, contain it, keep operating, recover quickly, and know what we stood to lose? Critically, who is accountable for those decisions?
Making that shared accountability work requires better intelligence. Leaders need a common view that connects cyber risk, threats, controls, vulnerabilities, recovery capability, and potential loss to business consequence.
The purpose is not another cybersecurity dashboard; it is to give different decision-makers enough shared evidence to make informed resilience decisions.
This emerging capability can be thought of as resilience intelligence, which translates fragmented cybersecurity evidence into the business understanding needed to manage resilience.
It means that the Chief Information Officer, Chief Risk Officer, Chief Finance Officer, Chief Executive Officer, and the board of directors are all accountable. Cyber resilience is a system of shared accountability, not a delegated technical function.
The writer is the founder and CEO, Serianu Limited