By Chimezie Godfrey
The National Information Technology Development Agency (NITDA) on Tuesday commenced a two-day capacity-building workshop for Ministries, Departments and Agencies (MDAs), warning that the growing wave of cyber attacks on government digital infrastructure demands stronger collaboration and improved cyber resilience across the public sector.
Speaking at the opening of the workshop in Abuja with the theme “Securing Government Digital Infrastructure Through Capacity Building,” the Director-General of NITDA, Kashifu Inuwa Abdullahi, represented by Dr. Ayode Bakare, Assistant Director in the Agency’s Cybersecurity Department, said recent cyber attacks have exposed the vulnerability of government digital systems.
According to Bakare, government websites have suffered defacements, hijackings, phishing attacks and data breaches, with sensitive information finding its way onto the dark web.
”We’ve witnessed lots and lots of defacement, hijacking of government websites. We’ve also experienced phishing and lots of data exfiltration from government platforms onto the dark web,” he said.
He explained that Nigeria’s expanding digital economy, driven by over 160 million internet users, rapid fintech growth and increasing government adoption of Artificial Intelligence (AI), has significantly enlarged the country’s cyber attack surface.
”It is a paradox because while we are improving in terms of digital transformation, we are also being attacked. This is why government must implement preventive, detective and resilience controls to improve Nigeria’s cybersecurity,” he stated.
Delivering the Director-General’s keynote remarks, Bakare said cyber attacks against government institutions have become more organised and sophisticated.
”We have watched websites of government organisations defaced, hijacked and redirected to gambling sites. We have seen ransomware attacks shut down major government portals and cyber attacks leading to data exfiltration onto the dark web,” he said.
Citing findings from the United Nations Office on Drugs and Crime (UNODC), he noted that Nigeria ranks among Africa’s three most targeted countries for cyber attacks, while the Lloyd Nigeria Cybersecurity Outlook 2026 estimated losses exceeding $3 billion between 2019 and 2025 due to cybercrime.
”The threat is no longer from lone opportunists. We are contending with organised, financially motivated and politically driven actors. A weakness in one MDA becomes a doorway into another, and that is why cybersecurity in government must never be fragmented,” the DG stressed.
He described cybersecurity as “a shared national obligation,” urging MDAs to strengthen preventive measures through cyber risk assessments, policy implementation, continuous awareness, incident response planning and workforce capacity development.
He also announced that participants at the workshop would be the first external stakeholders to review and contribute to NITDA’s draft Government Information Security Management Regulatory Guidelines before they are subjected to broader consultations.
”This is not going to be a regular training. It is an opportunity for multidirectional discussion and intelligence exchange on improving Nigeria’s cyber readiness and resilience,” he said.
Meanwhile, Coordinator of Whitehat.ng, Hamzat Lekan, who facilitated the opening technical session, identified ransomware, Advanced Persistent Threat (APT) groups, politically motivated cyber activists and foreign attackers as some of the emerging threats confronting Nigeria’s digital ecosystem.
”We’ve seen ransomware, advanced persistent threat actors and digital activists attacking government infrastructure. Recently, we’ve also seen foreigners interfere by attempting to take down government portals and facilities,” Lekan said.
He said the workshop would expose participants to practical cybersecurity exercises, including evaluating the security posture of their organisations and adopting measures to strengthen resilience.
On outsourcing government digital infrastructure projects, Lekan said engaging contractors remained necessary but warned that cybersecurity requirements must be embedded in procurement processes.
”They should ensure cybersecurity responsibilities are included in every contract so that systems are built with adequate controls that will not expose government data or infrastructure,” he said.
He added that building a secure digital ecosystem requires every government institution to play its part because weaknesses in one organisation could threaten the security of interconnected government platforms.

