📖 ABSTRACT/OVERVIEW
State security agencies in Nigeria are increasingly targeted by cyber operations that compromise sensitive intelligence, disrupt command and control systems, and expose citizen data. Despite this threat landscape, empirical assessment of cybersecurity incident response capabilities within these agencies remains largely absent from the published literature. This study conducts an empirical assessment of cybersecurity incident response capabilities in selected Nigerian state security agencies, focusing on agencies within the Office of the National Security Adviser's coordination remit. A structured assessment instrument adapted from the National Institute of Standards and Technology Cybersecurity Framework was administered to 55 IT security officers through a confidential questionnaire, complemented by three expert panel interviews. Capability dimensions assessed include incident identification, containment, eradication, recovery, and post-incident learning. Findings reveal that incident identification capabilities are comparatively strongest, while recovery and post-incident learning processes are weakest, with the latter constrained by absence of formal after-action review procedures. Cross-agency information sharing on cyber threats is minimal, limiting collective situational awareness. The study proposes a Nigerian Security Sector Cyber Incident Response Maturity Model and benchmarks participating agencies against it. Recommendations include establishment of a dedicated cyber incident response unit under the Office of the National Security Adviser and formal inter-agency threat intelligence sharing protocols. Keywords: cybersecurity incident response, national security, NIST framework, Nigeria, security agencies.
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬