I have spent more than a decade working inside IT systems at a regional level supporting multi-branch infrastructure across a regulated financial services environment in Nigeria, and more recently in a technology-led organization in the UK. In that time, I have seen the same preventable failures repeat themselves across sectors and geographies: shared user credentials, unpatched systems that should have been retired years earlier, and staff who have never been trained to recognize a phishing email.
It did not look like much at first
While monitoring routine support incidents during my time in Nigerian banking IT, I noticed something that did not quite fit, repeated login attempts outside normal working hours, spread across multiple user accounts. My first instinct was that it was a standard credential issue, the kind of thing you see regularly in large, multi-branch environments. But the pattern felt too coordinated to dismiss. I escalated it.
When the security team investigated, what came back confirmed my concern. The analysis pointed to early indicators of a credential-based attack, most likely enabled by weak password practices and inconsistent enforcement of multi-factor authentication. No major breach occurred. But it easily could have. One small gap in everyday access management practice had nearly opened the door to unauthorised access to sensitive financial and customer data, potential regulatory breaches, and serious operational disruption.
That incident stayed with me. Not because it was dramatic, it wasn’t. But because of what it revealed: that the most dangerous cybersecurity risks are often not the sophisticated ones. They are the quiet, routine failures that nobody has got around to fixing yet.
When I look at how Nigeria’s healthcare sector is now digitising and at the pace it is moving, I see those same quiet failures starting to take shape. And that worries me.
The Digital Push Is Real and It Is Moving Fast
Nigeria’s healthcare sector is adopting digital infrastructure at a pace that would have seemed unlikely a decade ago. Electronic medical record platforms, hospital management software, telemedicine applications, and AI-assisted tools are now active in some of our largest institutions. The International Finance Corporation has projected that Africa’s digital economy could contribute approximately $180 billion to GDP by 2025, and healthcare digitisation is one of its fastest-growing components.
This matters enormously. The World Health Organisation estimates that Africa carries close to 24% of the global disease burden while having access to roughly 3% of the world’s healthcare workforce. In that context, technology is not a luxury; it is a structural necessity. AI-assisted triage, digital patient records, and telemedicine platforms can genuinely extend the reach of an overstretched system.
But technology introduced without adequate security infrastructure does not simply fail to help. It creates new and serious vulnerabilities; and in healthcare, those vulnerabilities have consequences that go well beyond data.
What the Evidence Actually Shows
The Sophos “State of Ransomware in Healthcare 2023” report, based on a survey of 233 IT and cybersecurity professionals across 14 countries, found that cybercriminals successfully encrypted data in nearly 75% of ransomware attacks on healthcare organisations that year; the highest encryption rate recorded in the sector in three consecutive years. The mean cost of recovery stood at $2.2 million per incident. By 2024, that figure had risen to $2.57 million, and two-thirds of healthcare organisations surveyed reported being hit by ransomware in the previous twelve months; a four-year high.
(Source: Sophos)
African healthcare institutions are not immune. In June 2024, the BlackSuit ransomware group attacked South Africa’s National Health Laboratory Service (NHLS), a government-operated network of 265 laboratories providing diagnostic testing for public healthcare facilities across all nine provinces. The attack deleted sections of the NHLS’s systems; including its backup servers, and left physicians across the country unable to access more than 6.3 million blood test results through normal channels. Results had to be communicated by telephone. Major operations were postponed. The incident occurred during an active mpox outbreak, compounding the public health impact of the disruption.
(Source: The Record / Recorded Future News)
These are not distant threats. They are the current reality for digitizing healthcare systems on this continent.
Where the Gaps Actually Sit
From my experience supporting IT infrastructure in both Nigerian financial services and UK technology environments, I can point to several recurring failure patterns that are not unique to any single organisation.
Access control is applied inconsistently
In my previous role providing senior IT support across a multi-branch Nigerian banking environment, one of the most critical disciplines in maintaining security was ensuring that user access rights were properly managed and that departing staff did not retain active credentials, that permissions were granted based on role rather than convenience, and that privileged access was logged and audited. These are not sophisticated requirements. They are foundational. Yet multi-factor authentication, role-based access control, and structured off-boarding processes remain inconsistently deployed across many Nigerian healthcare institutions.
The Sophos 2023 report identified compromised credentials as the leading root cause of ransomware attacks in healthcare, responsible for 32% of the most significant incidents, ahead even of exploited vulnerabilities. This is a direct consequence of poor access management. When an attacker can obtain valid login credentials through phishing or credential theft and simply walk through an unlocked front door, the absence of MFA and least-privilege principles turns every user account into a potential breach point.
(Source: Techpoint)
Legacy systems remain in production
Working across multiple branches in a large banking environment, I regularly encountered the tension between keeping critical systems running and finding the time, budget, and expertise to upgrade them. Healthcare institutions face an even more acute version of that tension. Many public hospitals continue to operate systems that have not received security patches in years, not because their IT teams are negligent, but because procurement cycles are slow, vendor support has ended, and the internal expertise to manage a migration safely is scarce. End-of-life software cannot be patched. Running it alongside newer digital tools creates hybrid environments that are exceptionally difficult to defend.
Cybersecurity awareness is treated as optional
In my current role supporting a UK technology organisation, one of the most consistent sources of security incidents I encounter is human error; staff clicking on phishing links, misconfiguring access settings, or failing to recognise social engineering attempts. Healthcare workers in Nigeria are under far greater pressure than most IT users anywhere. Adding security awareness training to their workload feels like an imposition. But phishing and malicious emails were the starting point for more than a third of healthcare ransomware attacks in 2023, according to Sophos, above the cross-sector average. Without training, technical controls have a ceiling.
Data governance frameworks are underdeveloped
Nigeria’s Data Protection Act 2023 is a meaningful legislative step. It creates obligations around the processing of sensitive personal data, including health records. But legislation creates obligation; it does not automatically create capability. Many institutions do not yet have the internal expertise to understand what the Act requires, let alone implement it systematically. During my postgraduate studies in cybersecurity, one of the clearest lessons from examining ISO/IEC 27001 implementation across organisations was that the gap between policy on paper and practice in systems is rarely bridged without dedicated internal resource and external audit. That gap is significant in Nigerian healthcare right now.
AI Makes the Stakes Higher
The conversation around AI in African healthcare is moving quickly, and rightly so. Predictive tools for disease surveillance, algorithmic case prioritisation in social care, AI-assisted diagnostics. These are not distant prospects; some are already being piloted.
But AI systems in healthcare operate on data at a scale and depth that makes every security weakness more consequential. A triage algorithm is processing diagnostic histories, demographic information, and clinical observations. A predictive safeguarding tool is handling some of the most sensitive personal data that exists. If these systems are not built on a foundation of encrypted data pipelines, rigorous access controls, clear data retention policies, and independent security audits, then a breach does not just expose records, it exposes people.
There is also an algorithmic dimension that cybersecurity professionals are not always trained to think about, but cannot afford to ignore. Many AI systems used globally have been trained predominantly on data from Western healthcare populations. Deploying tools that have not been validated against local patient data in Nigerian or African contexts introduces a different kind of risk; not a cyberattack, but an inequity built into the system itself. An algorithm that performs well in a London teaching hospital may misclassify presentations that are routine in Lagos. That is not a theoretical concern. It is a design failure, and it needs to be part of the due diligence conversation when institutions consider AI adoption.
What Responsible Adoption Looks Like
I am not arguing against digitisation. I am arguing for a version of it that treats security as a design principle rather than an afterthought.
At the institutional level, that means embedding cybersecurity review into procurement decisions for any new digital health tool. It means conducting vulnerability assessments before going live with electronic record systems, not after an incident occurs. It means multi-factor authentication, role-based access control, endpoint security, and encryption as baseline requirements, and regular staff awareness training as a standard operating procedure rather than a one-off event.
At the policy level, deeper coordination is needed between the National Information Technology Development Agency, the Federal Ministry of Health, and the Nigeria Data Protection Commission, not just in enforcement after breaches, but in publishing practical, sector-specific guidance that institutions with limited internal expertise can actually implement.
At the professional level, those of us working across cybersecurity and IT in Nigeria and the diaspora have a responsibility to speak plainly about what is at stake. The skills I developed supporting regional IT across a large Nigerian banking network – incident response, root-cause analysis, access management, security-aware troubleshooting; are precisely the capabilities that digitising healthcare institutions need access to. That knowledge transfer is part of what advancing the sector means in practice.
A Window That Will Not Stay Open Forever
Nigeria has a genuine opportunity here. The digital health ecosystem is early stage enough that strong security architecture can still be designed in from the start, rather than retrofitted onto systems that were never built with it in mind. The countries that will benefit most from AI in healthcare will not necessarily be the ones that adopted it fastest. They will be the ones whose populations trust it, and that trust, once lost to a serious breach or a discriminatory algorithm, is extraordinarily difficult to rebuild.
The NHLS attack in South Africa was not a warning from a distant future. It was a demonstration of what happens when critical health infrastructure goes digital faster than its security posture can keep up. We have seen this play out. We do not need to repeat it.





