📖 ABSTRACT/OVERVIEW
E-commerce platforms in Nigeria are increasingly targeted by sophisticated cyberattacks including phishing, payment fraud, and data breaches, yet incident response capabilities among local operators remain underdeveloped. This study examines cybersecurity incident response management practices in Nigerian e-commerce companies, focusing on platforms operating in the South West and South South zones including Jumia Nigeria, Konga, and smaller regional retailers. Using a qualitative research design, data was collected through semi-structured interviews with 15 cybersecurity managers and IT directors. Analysis is guided by the NIST Cybersecurity Framework, mapping organisations' preparation, detection, containment, eradication, and recovery capabilities. Findings reveal that most companies lack formal incident response plans (IRPs), with only 33 percent having documented containment playbooks and even fewer conducting post-incident reviews. The study identifies inadequate cybersecurity budgets, talent shortages, and low executive awareness as the primary structural barriers to effective incident management. A severity-tiered incident classification model adapted to Nigerian e-commerce is proposed as a practical IRP foundation. Professional recommendations include mandatory cybersecurity incident drills, engagement with the Nigeria Computer Emergency Response Team (ngCERT), and adoption of Security Information and Event Management (SIEM) platforms. Keywords: cybersecurity, incident response, e-commerce, NIST framework, Nigeria
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬