Managing Cybersecurity Risks in Nigerian E-Commerce Platforms: A Case Study of Konga and Jumia Operations

📖 ABSTRACT/OVERVIEW

The rapid growth of e-commerce in Nigeria has been accompanied by escalating cybersecurity threats targeting transaction platforms, customer data repositories, and payment processing systems. This study examines cybersecurity risk management practices in two leading Nigerian e-commerce platforms, Konga and Jumia, focusing on their Nigerian operations. A qualitative research design employing semi-structured interviews with 12 senior IT security and operations managers across both organisations was employed. The study investigates risk identification processes, security architecture decisions, threat monitoring capabilities, incident response management, compliance with Payment Card Industry Data Security Standard requirements, and consumer data protection obligations under the Nigeria Data Protection Act 2023. Findings reveal that both organisations maintain dedicated cybersecurity teams and have implemented multi-factor authentication, encryption, and continuous threat monitoring. However, third-party vendor security management was identified as a significant gap, with neither organisation conducting comprehensive cybersecurity audits of logistics and payment processing partners. Social engineering attacks targeting customer service staff were identified as the most frequently successful intrusion vector. The study recommends formalisation of third-party cybersecurity assessment requirements in vendor contracts and development of Nigeria-specific e-commerce cybersecurity incident reporting standards. Keywords: cybersecurity risk, e-commerce, Konga, Jumia, Nigeria Data Protection Act.

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬