Report | African Perspectives on Cyber Security, 2024

Report | African Perspectives on Cyber Security, 2024

Cyber Security Report for the first 10 months of 2024. This report is designed to shed light on the unique challenges and evolving threats faced by key sectors in Africa.

Report | African Perspectives on Cyber Security, 2024

A FRIC A N PERSPEC T I V E S ON C Y BER SEC URI T Y

2024

2CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

Y O U D E S E R V E T H E B E S T S E C U R I T Y

3CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

06 08 11 14

C O N T E N T S

CHAPTER 1 INTRODUCTION

CHAPTER 2 EXECUTIVE SUMMARY

CHAPTER 3 PARTNER COMMENTS - WESTCON

CHAPTER 4 COUNTRY-SPECIFIC ANALYSIS

South Africa’s Digital Future: Country Manager Report

South Africa – sophisticated cyberattacks

1. South African Government Sector

2. Case Study: Ransomware Attack on South African Government

3. South African Education Sector

4. South African Finance Sector

Kenya – East Africa’s Technological Hub: Country Manager Report

Kenya’s rapid growing digital economy

5. Kenyan Government Sector

6. Case Study: DDoS Attack on Kenyan Government Websites

7. Kenyan Education Sector

8. Kenyan Finance Sector

Partner Comments- Sales and Marketing Director at inq. South Africa

13

19

15

21

15

21

16

22

16

23

16

24

25

4CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

39

C O N T E N T S

CHAPTER 5 REGIONAL COMPARISONS

Nigeria – Africa’s Largest Economy: Country Manager Report

Increased attacks as Nigeria goes digital

9. Nigerian Government Sector

10. Nigerian Education Sector

11. Nigerian Finance Sector

12. Case Study: Banking Trojan Attack on a Nigerian Bank

Morocco – Emerging North Africa Digital Leader: Country Manager Report

One of Africa’s most targeted countries

13. Moroccan Government Sector

14. Case Study: State-Sponsored Cyber-Attack on Moroccan Ministries

15. Moroccan Education Sector

16. Moroccan Finance Sector

27

33

29

34

40

29

35

40

30

35

40

30

36

32

37

1. Government Sector

2. Education Sector

3. Finance Sector

5CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

41

46

52 49

C O N T E N T S

CHAPTER 6 CYBER SECURITY RECOMMENDATIONS

CHAPTER 7 CONCLUSIONS

CHAPTER 8 ABOUT

CHAPTER 9 CYBER TRENDS 2025

1. General

2. Sector-specific

3. The Role of Generative AI

1. About Check Point Software Technologies Ltd.

2. About Check Point Research

Partner Comment - VP Sales Engineer at DataGroupIT

42

53

42

53

43

48

6CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

1 0

INTRODUCTION

C H A P T E R 1

I S S A M E L H A D D I O U I Head of Security Sales Engineering:

Africa, Check Point Software Technologies

7CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SHEDDING LIGHT ON AFRICA'S CYBER SECURITY CHALLENGES It is with great interest and growing concern that Check Point presents the 2024 African Perspectives on Cyber Security Report for the first 10 months of 2024. As we navigate an increasingly digital world, the cyber security landscape across Africa has become a critical area of focus. This report is designed to shed light on the unique challenges and evolving threats faced by key sectors in Africa, particularly Government, Education, and Finance.

In the past year, we have observed a significant increase in cyberattacks targeting these sectors, with threats becoming more sophisticated and widespread. From ransomware attacks that have crippled critical infrastructure to state-sponsored hacktivism that threatens national security, the landscape is rapidly changing.

Our report provides an analysis of these trends across South Africa, Kenya, Nigeria, and Morocco. These markets - extremely diverse from another – are where Check Point has long established points of presence. Each offers unique insights that are crucial for developing robust cyber security strategies.

As you delve into the findings, I encourage you to consider the recommendations provided, which are designed to help organisations and governments across Africa strengthen their cyber security posture. The road ahead is challenging, but with a proactive approach and a commitment to collaboration, I believe we can secure our digital future.

Issam El Haddioui Head of Security Sales Engineering: Africa Check Point Software Technologies

C H A P T E R 1

8CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

2 0

EXECUTIVE SUMMARY

C H A P T E R 2

9CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

Cyber security threats in Africa have reached new heights in 2024, driven by the rapid digitalisation of key sectors such as Government, Education, and Finance. This Check Point report provides an analysis of the threat landscape across South Africa, Kenya, Nigeria, and Morocco.

Check Point’s Q3 2024 Report, reveals a global average of 1,876 cyber attacks per organisation was recorded, marking a 75% increase compared to the same period in 2023 and a 15% rise from the previous quarter. Africa, in contrast, faced the highest average of attacks at 3,370 per week (+90% YoY). This surge underscores the trend that virtual threats are becoming more frequent and sophisticated.

This report offers actionable insights and recommendations to help organisations across the continent bolster their cyber security defences.

OVERVIEW OF AFRICAN CYBER SECURITY THREAT LANDSCAPE Africa's digital expansion has been accompanied by a corresponding rise in cyber threats. In 2024, the continent saw a significant increase in cyberattacks, particularly in sectors critical to national security and economic stability. The most prevalent threats include ransomware, state-sponsored cyber activities, and a surge in malware attacks targeting network infrastructure such as routers and VPNs.

RANSOMWARE EVOLUTION Ransomware remains one of the most formidable cyber threats in Africa. The continent has witnessed a 90% increase in ransomware attacks over the past year, with more than 5,000 victims reported in 2023 alone. These attacks often exploit zero-day vulnerabilities, enabling cybercriminals to compromise numerous organisations simultaneously. The high costs associated with these vulnerabilities highlight the lucrative nature of ransomware operations.

C H A P T E R 2

10CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

EXPANDING ATTACK SURFACE The digital transformation across Africa has broadened the attack surface, making network devices, including routers and VPN hardware, prime targets for cyberattacks. The frequency of these attacks underscores the urgent need for robust protection measures, particularly in sectors where sensitive data and critical infrastructure are at risk.

STATE-AFFILIATED HACKTIVISM Nation states are increasingly engaging in cyber offensives, often under the guise of hacktivism. These attacks are typically aimed at destabilising government operations or influencing political outcomes. The rise of state-affiliated cyber activities in Africa reflects the growing intersection between cyber security and geopolitics.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 2

11CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

3 0

PARTNER COMMENTS

WESTCON DIRECTOR

C H A P T E R 3

C O L L I N S E M A D A U Westcon Director - Rest of Africa

12CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

EUROPE'S NIS2 TO IMPACT AFRICA'S TRADING PARTNERSHIPS NIS2 (Network and Information Security Directive 2) is an updated European Union (EU) cyber security directive aimed at strengthening the cyber security framework across the EU. It builds on the original NIS Directive, which was adopted in 2016, and sets more stringent requirements for member states and critical sectors to protect essential services and infrastructures against cyber threats. By implication, African businesses must act now to comply with the EU’s NIS2 Directive or risk losing valuable revenue streams through their European trading partners.

The EU remains the largest trading partner for Africa, with over 18 Economic Partnership Agreements and trade worth billions annually. African businesses, especially in sectors like Energy, Banking, Transport, and Manufacturing, are key partners in the EU’s supply chains. To continue doing business with EU companies, African organisations must comply with NIS2, which mandates strict cyber security measures to protect critical infrastructure and supply chains.

NIS2 is clear: companies doing business with European entities must implement enhanced cyber security measures, including encryption and multi-factor authentication, to safeguard data.

The responsibility lies with European partners to ensure their African suppliers comply with these new standards, but the onus is also on African businesses to assess and upgrade their security infrastructure. Non-compliance means being locked out of crucial partnerships, which

C H A P T E R 3

13CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

could devastate organisations relying on European trade. To prepare, African entities should immediately conduct baseline cyber security assessments, focusing on risk management, business continuity, and corporate accountability. Organisations must take personal responsibility at the executive level to secure data and report on their readiness.

NIS2 is not just a bureaucratic hurdle; it represents a minimum global standard for cyber security, and African businesses cannot afford to fall behind. The window for compliance is closing quickly, with initial reporting expected by early 2025, and penalties for failure could be severe. African businesses need to take these steps seriously, as the stakes are high in safeguarding both their operations and their European partnerships

Collins Emadau Westcon Director – Rest of Africa

C H A P T E R 3

14CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

4 0

COUNTRY- SPECIFIC

ANALYSIS

C H A P T E R 4

L I O N E L D A R T N A L L Country Manager (Acting), South Africa

Check Point Software Technologies

15CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SOUTH AFRICA’S DIGITAL FUTURE COUNTRY MANAGER REPORT: This briefing has stirred up a sense of accomplishment and unease. This year has been marked by significant developments in the field of cyber security across our continent, and South Africa continues to be a focal point for both innovation in its digital transformation and heightened security risks.

The cyber security landscape in South Africa reflects the broader challenges facing Africa. With increasing digital transformation in critical sectors such as finance, education, and government, we are also witnessing a sharp rise in sophisticated cyber threats.

Check Point’s focus in 2024 has been on enhancing incident response strategies, leveraging AI to bridge the cyber security skills gap, and strengthening cloud security measures in the wake of escalating digital migrations.

At Check Point, we believe that a multi-layered approach to cyber security is no longer a luxury but a necessity. The rapid evolution of threats such as ransomware, phishing, and data loss through unregulated AI usage demands urgent attention from both public and private sectors. Our commitment is to help organisations not only to defend against these threats but also prepare for and mitigate the impact of cyberattacks when they occur.

C H A P T E R 4

16CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

The financial sector has shown commendable progress in elevating cyber security to a board-level priority, but other sectors such as government and education must follow suit. The recent ransomware attacks targeting South African institutions such as the National Health Laboratory Services (NHLS) and the Department of Public Works and Infrastructure underscore the urgency of this issue.

The dire shortage of cyber security professionals in the country is reflective of the continent as a whole, which, according to the World Economic Forum has only 20 000 skilled individuals able to serve over 1,4-billion inhabitants. In this respect we believe AI’s capabilities can assist to run end-to-end solutions within organisations. However, on the flip side, with AI comes the need for stringent regulation in the face of machine learning and the loss of big data, within seemingly innocent services such as ChatGPT, OpenAI etc.

In the light of rising cyber attacks across all industries and organisations, clearly more budget needs to be allocated to safeguard organisational systems if we are to come anywhere near addressing our cyber security needs effectively.

As we move forward, our goal is to collaborate closely with local organisations to enhance their security postures and ensure that South Africa remains resilient in the face of emerging threats. I encourage all stakeholders to act decisively, prioritise security investments, and take advantage of the Check Point posture assessments provided as a value added service to enterprises as well as its end-to-end cutting-edge solutions, tried and tested by over 100 000 organisations around the globe.

Together, we can secure South Africa’s digital future and protect the critical infrastructures that drive our nation's growth.

Lionel Dartnall Country Manager (Acting), South Africa

C H A P T E R 4

https://www.weforum.org/stories/2024/04/cybersecurity-industry-talent-shortage-new-report/

17CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SOUTH AFRICA – SOPHISTICATED CYBERATTACKS South Africa is at the forefront of the continent’s digital transformation. However, this progress has made

it a focal point for sophisticated cyber-attacks, particularly in the Government, Education, and Finance

sectors.

SOUTH AFRICA GOVERNMENT SECTOR

• Overview: The South African government manages the country’s administration, policy-making, and national security, making it a prime target for cybercriminals.

• Attack Frequency: Government organisations in South Africa face an average of 3,312 attacks per week.

• Top Malware Threats: The sector is heavily targeted by botnets and ransomware, with FakeUpdates being the most prevalent malware.

• Vulnerabilities: Information Disclosure is the most common vulnerability exploited, impacting 73% of government organisations.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

18CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

CASE STUDY: RANSOMWARE ATTACK ON THE SOUTH AFRICAN GOVERNMENT

INCIDENT OVERVIEW In July 2024, multiple South African government agencies were simultaneously targeted in a coordinated

ransomware attack. The attack exploited a zero-day vulnerability in a widely used software platform,

allowing the attackers to encrypt critical government data and disrupt operations across several

departments. The ransomware used in this attack was identified as a variant of the notorious Ryuk

ransomware, known for its ability to target large organisations and demand substantial ransoms.

IMPACT The ransomware attacks crippled government operations for several days. Key services, including the

processing of social grants and the administration of public health services, were severely disrupted. The

attackers demanded a ransom of 10 million USD in Bitcoin, threatening to release sensitive data to the

public if their demands were not met.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

19CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SOUTH AFRICA EDUCATION SECTOR

• Overview: South Africa’s education sector is crucial for the nation’s development,

particularly in higher education and research.

• Attack Frequency: Educational institutions experience an average of 1,729 attacks per week.

• Top Threats: Botnets and information stealers are the most common malware targeting the

education sector.

• Vulnerabilities: Phishing remains a significant threat, with increased targeting of academic

email systems.

RESPONSE The South African government, with the assistance of local and international cybersecurity experts,

launched an immediate incident response. Despite the advanced nature of the attack, the government

refused to pay the ransom. Instead, they focused on restoring systems from backups and strengthening

their cyber security defences. The recovery process took over a week, during which time alternative

methods were employed to continue critical services.

LESSONS LEARNED This attack highlighted the importance of regular software updates and the need for robust backup

and recovery systems. The incident also underscored the necessity of having a comprehensive incident

response plan in place, particularly for critical government functions.

C H A P T E R 4

20CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

Short Case Study: A prominent university suffered a data breach in April 2024, leading to the

exposure of sensitive student and research data. The breach was traced back to a phishing attack that

compromised an administrator’s credentials.

Graphs & Data: The education sector across the globe saw consistent threats throughout the year, with a

peak in ransomware activities in May 2024.

SOUTH AFRICA FINANCE SECTOR

• Overview: The finance sector is vital to South Africa’s economy, encompassing banking, insurance, and

financial services.

• Attack Frequency: The finance sector faces an average of 999 attacks per week, with a significant

spike in June 2024.

• Top Threats: Financial institutions are primarily targeted by InfoStealer and Banking Trojans.

• Vulnerabilities: Weaknesses in outdated financial systems and inadequate encryption practices are

frequently exploited.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

J O H N P A U L O N Y A N G O Country Manager, East Africa

Check Point Software Technologies

21CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

KENYA – EAST AFRICA’S TECHNOLOGICAL HUB COUNTRY MANAGER REPORT: The cyber security landscape in Kenya has evolved significantly, driven by both increasing digital transformation and rising threats. This report highlights the growing sophistication of attacks, particularly against government institutions and critical infrastructure. Kenya, in recent years, has witnessed a rapid increase in cyber incidents, emphasizing the urgent need for robust cyber security measures.

Kenya’s technological advancements, especially in mobile payments and cloud adoption, have made it a leader in innovation across Africa. However, this also comes with a heightened responsibility to safeguard sensitive data and systems. The government’s proactive steps, such as involving leading cloud security solutions partners and launching new RFPs to enhance cyber security, show a commitment to addressing these challenges. The wake-up call from the Anonymous Sudan DDoS attacks in 2023 targeting Government e-portals has sparked significant efforts to strengthen the nation’s defences, and we are now witnessing a surge in tenders aimed at bolstering Kenya's cyber security posture.

C H A P T E R 4

22CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

As a hub for technological growth, Kenya’s path forward in cyber security lies in maintaining vigilance, integrating the latest AI-driven tools, and ensuring that security is a key focus alongside innovation. While progress has been made, it is critical that organisations across both the public and private sectors continue to prioritise security at all levels to protect against the evolving threats we face today. At Check Point, we remain committed to supporting Kenya in this journey by offering comprehensive solutions to safeguard its digital future.

John Paul Onyango Country Manager, East Africa Check Point Software Technologies

C H A P T E R 4

23CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

KENYA’S RAPID GROWING DIGITAL ECONOMY Kenya is establishing itself as a technological hub in East Africa, with a rapidly growing digital economy.

However, this growth has attracted cyber adversaries, particularly in the Utilities, Government and

Finance sectors.

KENYA GOVERNMENT SECTOR

• Overview: The Kenyan government is responsible for national policy and security, making it a prime target for cyber-attacks.

• Attack Frequency: The government sector in Kenya faces an average of 4719 attacks per week.

• Top Threats: FakeUpdates and Joker malware are the most common threats.

• Vulnerabilities: A significant portion of attacks exploit Information Disclosure vulnerabilities.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

24CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

CASE STUDY: RANSOMWARE ATTACK ON KENYAN GOVERNMENT

INCIDENT OVERVIEW In August 2023, a significant Distributed Denial of Service (DDoS) attack targeted multiple websites of the

Kenyan government. The attack was attributed to a state-sponsored hacking group Anonymous from a

neighbouring country, aiming to disrupt the digital infrastructure of Kenya during a period of heightened

political tension. The DDoS attack flooded government servers with traffic, rendering online public

services inaccessible for nearly 48 hours.

IMPACT The attack caused widespread disruption to online government services, including the issuance of identity

documents, tax services, and public information portals. The attack not only disrupted daily operations but

also caused a loss of public confidence in the government’s ability to protect its digital infrastructure. The

financial impact was significant, with estimates of lost revenue and mitigation costs exceeding 5 million USD.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

25CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

RESPONSE The Kenyan government responded by activating its National Computer Emergency Response Team (KE-

CIRT), which worked around the clock to mitigate the attack. They employed advanced traffic filtering

techniques and collaborated with international cyber security agencies to trace the origin of the attack.

Within 48 hours, normal service was restored, but the incident has led to a broader review of Kenya’s cyber

security policies and infrastructure.

LESSONS LEARNED The DDoS attack pinpointed the need for a resilient network infrastructure capable of withstanding large-

scale attacks. It also highlighted the importance of regional cooperation in cyber security, as threats often

transcend national borders.

KENYA EDUCATION SECTOR

• Overview: Kenya’s education sector, particularly its universities and research institutions, is essential for the country’s economic and social development.

• Attack Frequency: The education sector in Kenya faces an average of 1,728 attacks per week.

• Top Threats: Phishing attacks and malware infections, particularly botnets and information stealers, are prevalent.

• Vulnerabilities: Poorly secured online learning platforms and email systems are frequently targeted.

C H A P T E R 4

26CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

KENYA FINANCE SECTOR

• Overview: The finance sector in Kenya is a major driver of the country’s economy, with banks and financial institutions being key targets for cybercriminals.

• Attack Frequency: Financial institutions in Kenya are targeted by an average of 2,602 attacks per week.

• Top Threats: Banking malware and InfoStealer are the most common threats.

• Vulnerabilities: Inadequate authentication measures and outdated software are key vulnerabilities.

C H A P T E R 4

27CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

As cyber threats across Africa, particularly from state- affiliated hacktivists and financially motivated criminals, grow more sophisticated, it’s critical for businesses to adopt a multi-layered defence approach. At inq. South Africa, in partnership with Check Point, we focus on deploying AI-driven tools such as Extended Detection and Response (XDR) and Network Detection and Response (NDR) to provide continuous monitoring and rapid threat identification. By integrating these solutions across our clients’ infrastructures, especially in high-risk sectors like finance and government, we ensure real-time threat mitigation, while maintaining operational resilience. Staying ahead in this evolving landscape requires constant adaptation, a comprehensive security posture, and a focus on intelligence-driven solutions.

R A L P H B E R N D T Sales and Marketing Director at

inq. South Africa

C H A P T E R 4

K I N G S L E Y O S E G H A L E Country Manager, West Africa

Check Point Software Technologies

28CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

NIGERIA – AFRICA’S LARGEST ECONOMY COUNTRY MANAGER REPORT: Nigeria continues to face one of the highest frequencies of cyber-attacks in Africa, with organisations being attacked on average 3,759 times per week. This alarming statistic highlights the urgent need for robust cyber security measures to protect critical sectors, especially finance, government, and healthcare.

In 2024, ransomware has become the most significant cyber threat in Nigeria, with attacks exploiting zero-day vulnerabilities and causing widespread damage to both public and private entities. Additionally, botnets, information stealers, and banking malware remain persistent threats, with attackers increasingly targeting network infrastructure and financial data.

Despite these challenges, we are seeing growing awareness and efforts among Nigerian organisations to bolster their defences. The Central Bank of Nigeria (CBN) earlier this year attempted to impose a 0.5 per cent cyber security levy on electronic transfers as part of efforts to combat cyber threats and enhance the security of online transactions. This was retracted following public protests, and has since been reduced to 0,005 per cent per transaction.

C H A P T E R 4

29CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

The increasing adoption of advanced AI-driven solutions, such as those offered by Check Point, are playing a pivotal role in closing the cyber security gaps. However, with the rapid digitisation of our economy, we must remain vigilant and continue to push for greater investment in cybersecurity infrastructure to safeguard Nigeria’s digital future.

Kingsley Oseghale Country Manager, West Africa Check Point Software Technologies

C H A P T E R 4

30CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

INCREASED ATTACKS AS NIGERIA GOES DIGITAL Nigeria, Africa’s largest economy, has seen a substantial increase in cyberattacks in 2024, particularly in

its Government and Finance sectors. As the country continues to digitise, its cyber security defences are

being increasingly tested.

NIGERIA GOVERNMENT SECTOR

• Overview: The Nigerian government plays a crucial role in managing one of Africa’s largest economies, making it a high-profile target for cyberattacks.

• Attack Frequency: The government sector in Nigeria faces an average of 1,791 attacks per week.

• Top Threats: Ransomware and botnets are the primary threats, with ransomware accounting for 9.7% of attacks.

• Vulnerabilities: Exploited vulnerabilities often include Remote Code Execution and Information Disclosure.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

31CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

NIGERIAN EDUCATION SECTOR

• Overview: Nigeria’s education sector is vital for the country’s development, with a focus on higher education and innovation.

• Attack Frequency: Educational institutions in Nigeria face an average of 1,682 attacks per week.

• Top Threats: Phishing attacks and information stealers are the most common threats.

• Vulnerabilities: Inadequate cybersecurity training for staff and students is a major vulnerability.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

32CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

NIGERIAN FINANCE SECTOR

• Overview: Nigeria’s finance sector is one of the most significant in Africa, making it a top target for cybercriminals.

• Attack Frequency: The finance sector in Nigeria faces an average of 4,718 attacks per week.

• Top Threats: InfoStealer and Banking Trojans are the predominant malware types.

• Vulnerabilities: Weak multi-factor authentication and outdated banking systems are key vulnerabilities.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

33CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

CASE STUDY: BANKING TROJAN ATTACK ON A NIGERIAN BANK

INCIDENT OVERVIEW In March 2024, a leading Nigerian bank fell victim to a sophisticated cyber-attack involving a Banking

Trojan known as Emotet. The attack began with a well-crafted phishing campaign that targeted the bank’s

employees. The phishing emails contained malicious attachments that, when opened, installed the Emotet

Trojan on the bank’s network. Once inside, the Trojan harvested login credentials and propagated to other

systems within the bank.

IMPACT The Banking Trojan allowed the attackers to gain unauthorised access to critical financial systems,

leading to the theft of millions of naira from customer accounts. The bank’s internal investigation revealed

that over 10,000 customer accounts were compromised, and the total financial loss was estimated at

approximately 3 million USD. The attack caused significant reputational damage to the bank, leading to a

loss of customer trust and a sharp decline in stock prices.

RESPONSE Upon discovering the breach, the bank immediately shut down affected systems and launched a full-

scale forensic investigation. The bank worked closely with Nigeria’s Cybercrime Prevention Unit

and international cybersecurity firms to contain the breach and recover stolen funds. The bank also

implemented a comprehensive review of its security protocols, including the introduction of multi-factor

authentication and enhanced employee training programs.

LESSONS LEARNT This case underscores the critical importance of employee awareness and training in preventing phishing

attacks. It also highlights the need for financial institutions to implement strong authentication measures

and to monitor for unusual activity across their networks.

C H A P T E R 4

M H A M M E D D I N I A Country Manager, Francophone and North Africa

Check Point Software Technologies

34CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

MOROCCO – EMERGING NORTH AFRICA DIGITAL LEADER COUNTRY MANAGER REPORT:

With organisations being attacked on average 3,113 times per week, Morocco remains a prime target for cybercriminals. The most prevalent threats faced include botnets, ransomware, and information stealers, which have increasingly targeted critical sectors such as finance and government.

Over the past year, Morocco has seen a significant rise in ransomware attacks that exploit zero-day vulnerabilities, making it clear that robust protection measures are essential. The widespread use of botnets, like Phorpiex, and other sophisticated malware highlights the need for advanced security solutions to protect sensitive data and infrastructure.

However, I am optimistic about the steps being taken to mitigate these risks. Organisations in Morocco are increasingly turning to innovative cyber security solutions to address these evolving threats, with a strong focus on securing cloud assets and critical infrastructure. At Check Point, we are committed to helping businesses in Morocco strengthen their security posture and build a more resilient digital ecosystem. Mhammed Dinia Country Manager, Francophone and North Africa Check Point Software Technologies

C H A P T E R 4

35CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

ONE OF AFRICA’S MOST TARGETED COUNTRIES Morocco is emerging as a digital leader in North Africa, but with its rapid digitalisation comes increased

exposure to cyber threats. In 2024, the country has become one of the most targeted in Africa,

particularly in the Government and Finance sectors.

MOROCCAN GOVERNMENT SECTOR

• Overview: The Moroccan government is a critical institution for national governance, making it a significant target for cyber threats.

• Attack Frequency: The government sector in Morocco faces an average of 8,733 attacks per week.

• Top Threats: Botnets and ransomware are the primary threats, with botnets accounting for 11.7% of attacks.

• Vulnerabilities: Common vulnerabilities include Denial of Service and Information Disclosure.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

36CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

CASE STUDY: STATE-SPONSORED CYBER ATTACK ON MOROCCAN MINISTRIES

INCIDENT OVERVIEW

In May 2024, a coordinated cyberattack, believed to be state-sponsored, targeted several key ministries

within the Moroccan government. The attackers used a combination of spear-phishing emails and

advanced persistent threats (APTs) to gain access to internal networks. The primary targets were the

Ministry of Foreign Affairs, the Ministry of Defence, and the Ministry of Finance.

IMPACT The attack led to the compromise of sensitive government communications and classified documents. The

breach was significant, with attackers remaining undetected within the network for several weeks, during

which time they exfiltrated a large volume of data. The leaked information included confidential diplomatic

communications and internal defence strategies, causing a national security crisis.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

37CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

RESPONSE Upon detecting the breach, the Moroccan government declared a national cyber security emergency.

All affected ministries were taken offline to contain the attack, and a task force comprising national

and international cyber security experts was assembled to investigate and mitigate the breach. The

government also initiated a diplomatic response, engaging with international allies to address the

suspected state sponsorship behind the attack.

LESSONS LEARNED This incident highlighted the vulnerabilities within Morocco’s governmental cyber security infrastructure,

particularly in the handling of sensitive information. The case underscored the need for continuous

monitoring, threat intelligence sharing, and the adoption of more robust cyber security frameworks to

protect against sophisticated state-sponsored attacks.

MOROCCAN EDUCATION SECTOR

• Overview: Morocco’s education sector is essential for national development, but it has become increasingly targeted by cybercriminals.

• Attack Frequency: Educational institutions in Morocco face an average of 2,568 attacks per week.

• Top Threats: Phishing and ransomware are the most common threats.

• Vulnerabilities: Outdated software and weak password policies are significant vulnerabilities.

C H A P T E R 4

38CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

MOROCCAN FINANCE SECTOR

• Overview: The finance sector in Morocco is vital to the country’s economic stability and growth.

• Attack Frequency: Financial institutions in Morocco face an average of 2,647 attacks per week.

• Top Threats: InfoStealer and Banking Trojans are the predominant malware types.

• Vulnerabilities: Insufficient encryption and outdated financial software are common weaknesses.

Banking attacks in Morocco are significantly higher than the global average throughout the year so far.

SOURCE: CHECK POINT THRE AT INTELLIGENCE REPORT

C H A P T E R 4

39CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

5 0

REGIONAL COMPARISONS

C H A P T E R 5

40CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

GOVERNMENT SECTOR COMPARISON Attack Frequency

Morocco has the highest frequency of attack of government organisations with an average of 8733 attacks

per week, followed by South Africa (3312), Nigeria (1791), and Kenya (1 756)

Top Threats

Ransomware and botnets are the most common threats across all countries, with Morocco seeing the

highest percentage of botnet-related attacks at 11.7%.

EDUCATION SECTOR COMPARISON Vulnerability

The education sectors in Nigeria and Kenya show higher vulnerability to cyberattacks, with weekly

attack frequencies averaging 1,682 and 1,728, respectively. Morocco’s education sector faces the highest

average of 2,568 attacks per week.

Threat Types

Phishing and ransomware are prevalent across all countries, with a notable increase in phishing attacks

in Kenya and Nigeria.

FINANCE SECTOR COMPARISON Attack Severity

Nigerian financial institutions face the most severe cyber threats, with an average of 4,718 attacks per

week. Morocco follows closely with 2,647 weekly attacks on its finance sector.

Common Threats

InfoStealer and Banking Trojans are the most common malware types affecting the finance sector across

these countries, with Nigeria and Morocco experiencing the highest incidence of these attacks.

C H A P T E R 5

41CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

6 0

CYBER SECURITY RECOMMENDATIONS

C H A P T E R 6

42CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

Enhance Cyber security Measures: Governments and organisations across Africa should

prioritise cyber security, particularly in critical sectors like Government, Education, and Finance.

Adopt Advanced Security Solutions: Invest in advanced security technologies such as AI-driven

threat detection, endpoint protection, and secure access controls.

Promote Cyber Security Awareness: Conduct regular training and awareness programs for

employees, particularly in the Education and Finance sectors, to mitigate human error risks.

SECTOR-SPECIFIC RECOMMENDATIONS

Government Sector: Implement stringent access controls, regular security audits, and

continuous monitoring of network activity to protect sensitive government data.

Education Sector: Enhance cyber security in educational institutions by adopting advanced threat

detection systems and promoting cyber security awareness among students and staff.

Finance Sector: Financial institutions should prioritise the protection of sensitive financial data

through encryption, multi-factor authentication, and regular security assessments.

GENERAL RECOMMENDATIONS

C H A P T E R 6

H E N D R I K D E B R U I N Head of SADC Security Consulting

Check Point Software Technologies

43CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

GENERATIVE AI A DOUBLE-EDGED SWORD In the first half of 2024 we saw an increased adoption of commercial Generative AI technologies such as ChatGPT, Copilot, and DALL-E across Africa. Although information on the adoption of AI in Africa is difficult to come by, recent research specifically into Kenya’s adoption rates gives some indication of how the continent’s citizens are using AI.

The research, undertaken by Brookings, shows that 27% of Kenyans use ChatGPT daily, putting Kenya third behind India and Pakistan. Google search trends also show a 270% increase in searches related to AI compared to 2023 across Africa.

There are numerous uses of Generative AI, for both individuals and businesses alike. Some of the most common being grammar and spell checking, code generation and enhancement and general research.

Unfortunately, cyber criminals also use Generative AI for the same reasons, only they check the spelling and grammar of their phishing emails, generate or enhance their malicious code or gather information on potential targets.

AI enhances the sophistication and success of cybersecurity attacks

The adoption of AI by cybercriminals has not only had an impact on the volume of attacks due to lowered barriers of entry, but also on the sophistication and success of these attacks.

C H A P T E R 6

https://www.brookings.edu/articles/how-ai-is-impacting-policy-processes-and-outcomes-in-africa/

44CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

While businesses across Africa fend off an onslaught of AI enhanced traditional cyberattacks, the wide scale adoption of GenAI, has also opened up a whole new set of risks.

This pertains to the leaking of sensitive information from the use of Generative AI solutions. Although copying text from an email to your favourite GenAI service to check spelling and grammar may appear to be a smart move, there’s often no guarantees on how the specific AI service may use the information you just supplied.

The prompt or the information presented may be logged, or perhaps even ingested and presented to third parties. This problem is amplified by the fact that organisations across Africa often lack critical security controls such as Data Loss Prevention which can detect when these technologies are used, how they are used and even prevent sensitive information from being used in GenAI Prompts.

Benefits despite the risks

Despite introducing various new risks to both individuals and businesses across the continent, AI has also brought significant opportunities from which the continent can benefit.

Cyber security providers such as Check Point Software have used AI and Machine Learning for many years to assist customers with the prevention and detection of threats. Now a number of new AI engines have been introduced under the ThreatCloud banner, which inspect over 2,8-billion files and websites daily for threats. This feat is only possible using AI technology.

AI narrows cybersecurity skills gap

Africa has a severe shortage of cyber security skills - only 20 000 professionals among a population of 1,4-billion, according to the World Economic Forum. By embedding AI assistants within cyber security administration interfaces many of the difficulties associated with the skills gap can be addressed.

This prevention-first approach is powered by ThreatCloud AI, the brain behind all of Check Point’s products. ThreatCloud combines the latest AI technologies with big data threat intelligence to prevent the most advanced attacks while reducing false positives. Furthermore it aggregates and analyses big data telemetry and millions of Indicators of compromise (IoCs) every day, fed by over 150,000 connected networks and millions of endpoint devices, as well as Check Point Research (CPR) and dozens of external feeds.

C H A P T E R 6

https://www.weforum.org/stories/2024/04/cybersecurity-industry-talent-shortage-new-report/

45CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

This intelligence on newly revealed threats and protections is updated in real-time across Check Point’s entire security stack. Check Point AI Threatcloud has 40+ AI engines providing real-time threat intelligence and blocking 2.5 billion attacks every year.

It makes two billion security decisions daily, gathering intelligence from two billion websites and files, 73 million emails, 30 million file emulations, 20 million potential IoT devices, two million malicious indicators, one and a half million mobile applications and over one million online forms.

In 2024 Check Point introduced Infinity AI Copilot, an AI Assistant for security administrators. By simply prompting the AI Copilot, security administrators can gain immediate insight into a device or user’s security posture.

The possibility then also exists to use the same prompt and natural language to change the security posture of an individual or device, such as providing or preventing access to a resource.

The ability to use natural language to prompt a platform about the security posture of a specific user or device without having to understand the technical intricacies and controls that dictate that posture, is a game changer.

Extending the above functionality with the ability to use natural language prompts to manipulate sophisticated security controls to achieve a specific outcome lowers the barriers to entry even more.

The opportunities presented to the African continent by adopting AI is vast, however it must be done carefully.

2023 may have been the year widespread AI adoption officially kicked off, but 2024 is the year where we started to feel its impact.

It is critical for businesses across Africa to realise that AI will have an impact and appropriate measures must be taken to mitigate the threats it poses, and so enable its safe adoption.

Hendrik de Bruin Head of SADC Security Consulting Check Point Software Technologies

C H A P T E R 6

46CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

7 0

CONCLUSION

C H A P T E R 7

47CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

SWIFT ACTION TO ASSESS AND IMPROVE CYBER SECURITY POSTURE

This report highlights the urgent need for improved cyber security across the Government, Education, and Finance sectors, in particular, in Africa. All sectors are in fact vulnerable. By addressing the unique challenges faced by each sector and adopting robust security measures, organisations can better protect themselves against the ever-evolving cyber threats.

As African organisations increasingly adopt hybrid and multi-cloud environments, they face greater risks associated with data loss, compliance drift, and unauthorised access. The NIS2 Directive from the EU establishes a global cyber security standard that African businesses must meet to safeguard key European trade partnerships.

Findings from the Check Point Africa Cloud Security Readiness Report further highlight the necessity for continuous monitoring and incident response to handle the complexities of cloud security. Investment in AI-driven threat detection and multi-layered defense strategies is critical in order to stay ahead of emerging threats. Despite budget constraints, organisations must adopt a proactive stance and ensure adherence to stringent compliance measures to mitigate risks.

Failure to act will increase Africa's vulnerability to cyberattacks and jeopardise vital European revenue streams. African businesses must take swift action to assess and improve their cyber security posture, aligning with global standards to secure the continent's digital future and support economic growth.

C H A P T E R 7

https://www.checkpoint.com/resources/items/check-point-and-cxo-priorities-africa-cloud-security-readiness-reportpdf

48CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

In Africa, Interpol's 2021 Africa Cyberthreat Assessment Report estimated the financial impact of cybercrime in the region to exceed $4 billion USD, representing approximately 10 percent of Africa’s total GDP. The challenge has only grown in volume, impact, and complexity since then.

As cyber threats grow—driven by digital transformation, internet penetration, and reliance on cloud and mobile technologies— businesses must go beyond reacting to threats and adopt proactive, predictive security measures that can outpace attackers.

Despite the urgency, African companies spend only 0.05% of their revenue on cyber security, far below the global average of 0.3- 0.5%. This underinvestment leaves them vulnerable. As cloud adoption accelerates, the complexity of securing data also rises. Adopting frameworks like Zero Trust is essential to safeguarding increasingly distributed environments.

Additionally, Africa faces a significant skills gap in cyber security, presenting both a challenge and an opportunity. By fostering strong partnerships between the public and private sectors and investing in local talent, Africa can bridge this gap. Programs like DataGroupIT’s internship initiative aim to create jobs and develop a cyber security workforce capable of setting new global standards.

C H I B U Z O M B U K A VP Sales Engineering,

DataGroupIT

C H A P T E R 7

https://research.checkpoint.com/

49CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

8 0

CYBER TRENDS 2025

C H A P T E R 8

50CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

The Rise of AI-Powered Attacks: AI will become a core enabler of cybercrime in 2025. Threat actors will use AI to generate highly personalised phishing attacks and adaptive malware that can learn from real-time data to avoid detection. Smaller hacker groups will also use AI tools to launch large-scale operations without needing advanced expertise, democratising cybercrime.

Ransomware Hits Supply Chains Hard: Ransomware will grow even more targeted and automated, with attacks on critical supply chains, with possibly large-scale attacks becoming more common, affecting entire industries, with attackers using AI- enhanced phishing emails and deepfake impersonations to bypass defences.

Improper AI Usage Increases Data Breaches: With AI tools like ChatGPT becoming integral to business processes, accidental data exposure will become a key concern. Employees may inadvertently share sensitive data with external AI platforms, causing unintentional breaches. Organisations will need to establish governance frameworks to monitor AI usage and ensure data privacy.

Quantum Computing Poses New Threats to Encryption: Quantum computing will soon challenge existing encryption methods. Although large-scale quantum attacks are still years away, industries like finance and healthcare must begin adopting quantum-safe encryption to stay ahead of this looming threat.

Social Media Exploitation and Deepfakes Become Commonplace: Cybercriminals will increasingly target social media platforms, using personal data for targeted scams and impersonations. AI-powered deepfakes will become more convincing, posing threats to financial transactions and corporate security. Detecting and countering these sophisticated attacks will require real-time AI defences.

AI-Driven SOC Co-Pilots Revolutionise Security Operations: Security Operations Centres (SOCs) will use AI co-pilots to process large volumes of data and prioritise threats, enabling faster response times. These AI-driven tools will help automate threat detection and reduce false positives, boosting the efficiency of security teams.

Key highlights from the Check Point 2025 global cyber security predictions report include:

Predictions for cyber security in 2025 highlight several key trends for which organisations must prepare for as they face increasingly complex digital threat:

C H A P T E R 8

https://blog.checkpoint.com/security/2025-cyber-security-predictions-the-rise-of-ai-driven-attacks-quantum-threats-and-social-media-exploitation/ https://blog.checkpoint.com/security/2025-cyber-security-predictions-the-rise-of-ai-driven-attacks-quantum-threats-and-social-media-exploitation/

51CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

CIO and CISO Roles Converge as AI Adoption Grows: As businesses adopt AI and hybrid-cloud environments, the roles of CIO and CISO will converge, shifting towards integrated risk management. The report predicts that CIOs will increasingly oversee cyber security operations, fostering tighter alignment between IT and security functions.

Cloud Security Platforms Dominate the Landscape: Organisations will migrate towards integrated cloud security platforms, leveraging tools like CNAPP to monitor and secure multi-cloud environments. AI will play a crucial role in automating threat prevention, shifting the focus from reactive security to proactive defences.

IoT Expansion Increases Attack Surface: With 32 billion IoT devices expected by 2025, securing these interconnected systems will become critical. Attackers will exploit poorly secured IoT devices to breach cloud networks. To mitigate these risks, organisations must adopt Zero Trust architectures and AI-powered threat detection tools.

52CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

9 0

ABOUT

C H A P T E R 9

53CHECK POINT SOF T WARE | SECURIT Y REPORT 2024

ABOUT CHECK POINT SOFTWARE TECHNOLOGIES LTD. Check Point Software Technologies Ltd. is a leading AI-powered, cloud-delivered cyber security

platform provider protecting over 100,000 organisations worldwide. Check Point leverages the power

of AI everywhere to enhance cyber security efficiency and accuracy through its Infinity Platform, with

industry-leading catch rates enabling proactive threat anticipation and smarter, faster response times.

The comprehensive platform includes cloud-delivered technologies consisting of Check Point Harmony to

secure the workspace, Check Point CloudGuard to secure the cloud, Check Point Quantum to secure the

network, and Check Point Infinity Platform Services for collaborative security operations and services.

ABOUT CHECK POINT RESEARCH Check Point Research provides leading cyber threat intelligence to Check Point Software customers and

the greater intelligence community. The research team collects and analyzes global cyber-attack data

stored on ThreatCloud to keep hackers at bay, while ensuring all Check Point products are updated with

the latest protections. The research team consists of over 100 analysts and researchers cooperating with

other security vendors, law enforcement and various CERTs.

C H A P T E R 9

https://protect.checkpoint.com/v2/___http:/www.checkpoint.com___.YzJlOmNwYWxsOmM6bzozNTMzYWE3ZGQ4NWY4ZmYwMmI3MjMwYTY0NzliMzU5Mjo2OmU1ODI6ZjMyMmM2NjkyYzU0ZmU3NWRmZDlkNjcwMmQ5YjliNmVlZTliNmIyZmI0Y2QwM2UwODU0YjhkZDY4YjhhMmFjZjpwOkY6Tg https://research.checkpoint.com/

CONTACT US AFRICAN OFFICES

KENYA OFFICE Check Point Software Technologies

Regus Center, Vienna Court, State house Road Nairobi Kenya

NIGERIA OFFICE Check Point Software Technologies

Sterling Virtual Offices 2 Turnbull street , Banana Island

Lagos Nigeria

SOUTH AFRICA OFFICE Check Point Software Technologies, Unit 2C, Cedar Office Park,

Stinkwood Cl, Fourways, Sandton, 2055, South Africa

UNDER ATTACK? Contact our Incident Response Team:

emergency-response@checkpoint.com

WWW.CHECKPOINT.COM

© 1994-2024 Check Point Software Technologies Ltd. All Rights Reserved.

http://WWW.CHECKPOINT.COM


Item Type: pdf