- What: Nigeria launches sovereign cloud initiative for national security
- Impact: Reflects growing emphasis on data sovereignty in Africa
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS CYBERATTACKS & DATA BREACHES ICS/OT SECURITY DATA PRIVACY NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America. Nigeria Looks to Sovereign Cloud for Cyber, National Security The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge. Robert Lemos,Contributing Writer August 26, 2026 5 Min Read SOURCE: QQMINH88 VIA SHUTTERSTOCK Nigeria took the initial concrete steps this month toward creating its own sovereign data centers and cloud services, as more African nations accelerate the digitalization of their economies with an eye toward cybersecurity. Last week, the western African nation established the Joint Technical Committee of the National Sovereign Cloud Initiative (JTC-NSCI), an effort to expatriate data back within its borders and to break its reliance on foreign data storage and cloud providers. The sovereign cloud initiative is also designed to boost national security and help Nigeria create a deep expertise, Kashifu Inuwa, director general of NITDA and co-chairman of the JTC-NSCI, said in an Aug. 20 statement. "As a nation, we should determine our digital future," he said. "We should have control over our data. We should have control over our algorithms, our AI, and all our transactions." Sovereignty of data, technology infrastructure, and technical capabilities have become increasingly sought after by nations — not just in Africa, but worldwide. In part, the initiatives are a reaction to US legislation that can give the government access to foreign data. The past year's restrictions on exporting the most powerful AI chips and AI models to other countries has likewise caused nations to look to strengthen domestic capabilities. Related:Europe's Multilingual Reality Exposes AI Security Gaps The United Arab Emirates, for example, has worked with Microsoft, OpenAI, Nvidia and other companies to start building a large 5 gigawatt AI capability, dubbed Stargate UAE, managed by the Middle Eastern nation's technology service provider, G42. The United Kingdom has pushed for sovereign AI services and an AI defense capability after the Trump administration placed short-lived export restrictions on Anthropic's most capable AI models. Japan has partnered with Microsoft to build AI compute and data centers, the latest nation in the Asia-Pacific to work with hyperscalers to expand domestic capacity. A "National Framework for Trusted Cloud Adoption" Nigeria's initiative aims to allow the country to create its own national cloud infrastructure that boosts the nation's digital-transformation efforts in the areas of government services, finances, AI, and the national economy, NITDA stated in its announcement. The JTC-NSCI will promote a cloud-first policy using the domestic capabilities as a way to cut costs, attract $750 million in investment over the next two years to build out the infrastructure, and establish compliance and certification requirements for data security, according to the Federal Ministry of Communications, Innovation & Digital Economy. Related:Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife Nigeria is the third largest economy in Africa with a gross domestic product estimated at $377 billion. Source: International Monetary Fund, April 2026 While data residency and sovereign cloud infrastructure addresses national economic and security concerns, the certification is the important step that needs to be taken, says Paul Barbosa, vice president of cloud security and SASE for Check Point, because what matters is whether the provider or their customer can prevent, detect, and respond to attacks in real time. "Where I get cautious is when residency becomes a proxy for security, and certification becomes a one-time audit rather than an ongoing discipline," he says. "We tell governments the same thing we tell enterprises: location plus a badge is not a security architecture." Nigeria's approach is promising because the government is not just requiring data residency or local cloud providers. Adding requirements and technical certification — especially if frequently checked and updated — promises to improve security, says Ian Van Rensburg, head of security engineering for Africa at Check Point Software. "Many countries already have extensive cyber security and data-protection policies — the challenge is translating those policies into consistent technical controls and measurable outcomes across government," he says. "Nigeria's approach has the potential to achieve this because the initiative brings together technology, procurement, budgeting, and government administration, rather than treating sovereign cloud purely as an IT project." Related:European Organizations Have a Collaboration Security Confidence Gap Sovereign Done Right Can Boost Security The country certainly is in the crosshair. Nigeria, the third largest economy in Africa estimated at $377 billion by the International Monetary Fund, has faced increasing cyberattacks, not only from cybercriminals but also from nation-states with interests in the region. While Africa currently ranks third in weekly attacks per organization in the region — behind Latin America and Asia — Nigeria has often been the most attacked country, although Angola surpassed it in both June and July 2026, according to Check Point Software Technologies' August threat landscape report. In addition, government agencies are the second-most targeted organizations, behind the education sector, according to the report. Nigeria's government has felt the growth in attacks firsthand, NITDA's Inuwa said in an August 4 statement promoting various cybersecurity measures. "We have watched websites of government organizations defaced, hijacked and quietly redirected to gambling sites," he said. "We have seen coordinated ransomware attacks force government web portals to shut down and witnessed repeated attacks on government databases leading to data exfiltration and abuse of personal data." Yet, localization of technical capabilities only work when resilience is a priority and security a requirement, says Lior Atar, chief information security officer at Dream, a sovereign AI provider. Creating sovereign capabilities can reduce fragmentation and make infrastructure operations more efficient, but also requires continuous monitoring, effective incident response, hardening, and local expertise, he says. "The key is verification," Atar says. "If certification requires providers to demonstrate the effectiveness of their controls continuously, through ongoing monitoring, testing, and real consequences for failure, citizen data will be measurably safer." With AI automation, attackers have become more agile, more pernicious, and more persistent, says Atar. Governments face a dual challenges: They must first close basic weaknesses that continue to provide attackers with easy points of entry, while also creating their own AI-resilient and powered defenses that can foil adversaries that operate at greater speed, scale, and autonomy. "Sovereign infrastructure gives a nation a defined perimeter it can actually see and defend as a whole, instead of a scattered surface nobody owns," he says. "But that same defined perimeter also tells the adversary exactly where to aim. Defending it becomes a national mission." Read more about: DR Global Middle East & Africa About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS Shutdown Sparks 85% Increase in US Government Cyberattacks by Nate Nelson OCT 24, 2025 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi