Africa is no longer sitting on the side-lines of an industrial revolution. The rapid advancement of ICT has demonstrated the Continent’s growing role in shaping the global digital landscape through increased innovation. However, cybersecurity remains a dominant threat that may affect how Africa benefits from the ICT. This piece will therefore examine Africa’s participation in multilateral process on ICT and cybersecurity and explore the extent to which this has been translated into meaningful change at the regional level by exploring ongoing cybersecurity initiatives.
The Fourth Industrial Revolution presents new opportunities to redefine work and education, boost research and transform traditional ways of providing services. The increasing reliance on information and communications technologies (ICTs) and global interconnectedness through computers and mobile phones has revolutionised the way we interact, conduct business and engage daily. Furthermore, artificial intelligence tools promise to lead us into a world of convenience which would greatly improve people’s quality of life. Beyond convenience, it is palpable that technology is also driving economic growth by opening new industries and expanding global income opportunities. As a Continent, Africa has the opportunity to utilise the Fourth Industrial Revolution as a conduit to boost socio-economic development. If regional efforts like the African Continental Free Trade Area (AfCFTA) are fully operationalised, more than 1.4 billion people across the Region would become beneficiaries of free-flowing goods, services and investment. Evidently, ICTs will become a major catalyst to most of these achievements. The question, however, remains whether the Continent will stand at the forefront of this revolution or lag behind by not putting in place the relevant measures needed to safeguard its gains.
Unfortunately, with this increased reliance on ICTs and new technology comes a consequent increase in cybercrimes and ICT-enabled crimes. According to a report by the United Nations, “there is growing concern over the misuse of [ICTs] by terrorists, in particular the Internet and new digital technologies, to commit, incite, recruit, fund or plan terrorist acts.” Scholars such as Pytlak and Lad note that “from cyber operations targeting critical infrastructure to the spread of cybercrime and the use of social media to incite violence, the growing use of [ICTs] in modern conflicts, military strategies, and as a component of foreign policies presents a spectrum of international security risks.” It is, without a doubt, that the proliferation of ICTs and the advent of new and emerging technologies have transformed threats to International Security over the years. In view of this, countries around the world are beginning to acknowledge how detrimental cyberattacks could be to the socio-economic development of a country. Additionally, once security is compromised, trust in digital systems is lost.
In view of this reality, Member States, over the last decade, have begun to prioritise multilateral cybersecurity and cybercrime forums, namely those provided by the UN, to discuss responsible state behaviour in the use of ICTs, as well as cyber-related benefits and risks. Since the Group of Governmental Experts (GGE) began its work in 2004, there have been other cyber-related processes such as the United Nations Open-Ended Working Group on the security of and in the use of ICTs (OEWG), the Global Digital Compact, the WSIS+20 process and the United Nations Ad Hoc Committee to Elaborate a Comprehensive International Convention on Countering the Use of ICTs for Criminal Purposes. The latter, especially, brought together UN Member States (between 2019 and 2024) to have extensive conversations aimed at drafting the first international convention on cybercrime to augment existing cybercrime conventions like the Budapest and Malabo Conventions. In spite of all these efforts, it is important to examine whether Africa’s presence in these processes has made a significant impact on national and regional cybersecurity efforts. Furthermore, one must consider whether Member States are equipped with the capacity and resources needed to engage meaningfully in all these cybersecurity processes. Almost a decade ago, it was evident that when some of these processes began, Africa’s participation was not the strongest.
Luckily, almost a decade after the first GGE, there have been significant milestones across the continent worth mentioning. The Ad Hoc Committee on Cybercrime, for example, was chaired by Algeria. An African country at the helm of a major cybersecurity process was a testament to Africa’s willingness to be part of the conversation. During the UN OEWG, Africa Member States also developed the Common African Position (CAP) on the Application of International Law to the Use of ICT in the Cyberspace, which was a milestone for the Continent. At the sub regional level, ECOWAS has also become the first Sub Regional group on the Continent to adopt a set of Confidence Building Measures (CBMs), another major milestone. CBMs were one of the key thematic areas during the UNOEWG on ICT, demonstrating that the continuous dialogue led to some tangible outcomes. This gives ECOWAS the opportunity to share best practices not only across the Region but across the globe, thus becoming a shining light. Additionally, according to an article by Connecting Africa, 22 African countries signed the United Nations Convention against Cybercrime, which is a testament to Africa’s preparedness to align with global best practices. Finally, The Africa Union has also begun working to implement guidelines on the implementation of norms at a regional level and efforts are being made to broaden ratification of the Malabo Convention.
Although Member States must be lauded for these milestones, we must acknowledge that there is still a long way to go. Ratification of the Malabo Convention remains low with only about 20 ratifications. If African countries have been meaningfully engaging in these processes and truly have understanding of the need for cybersecurity legislation, and international cooperation, then this should be evidenced in how Member States support regional efforts as significant as this. There is an urgent need for the continent to assess whether this can be attributed to a lack of political will or the lack of established technical agencies to spearhead these efforts in some countries. Africa needs to put in place the efforts needed to close some of the legislative and policy gaps by prioritizing the ratification of regional and international Conventions. This is where regional bodies like the African Union (AU) must also demonstrate their convening influence and put in place measures to increase awareness and strengthen cyber capacity. The AU can additionally provide some unique incentives for ratification. For example, countries that ratify the Budapest Convention are provided with additional training on its operationalization such as trainings for officials in the criminal justice sector and capacity building for the 24/7 Points of Contact among others. RECs in Africa also have the opportunity to be influential in these efforts and champion cybersecurity best practices in the Sub region, thus complementing the work of the African Union.
Looking at the impact of cybercrime on nations, merely participating in cybersecurity processes at the international level is simply not enough. It may lead to some capacity building and increased awareness; A strong example of such capacity building has been the emergence of experts and cyber diplomats across the region championing cybersecurity regionally and internationally. Most of these experts built their capacity by engaging in multilateral processes, a notable example being the Women in Cyberspace and International Security Fellowship. However, it is important to reiterate that true change goes beyond mere attendance. It will be significant to see peer-to-peer engagements on the Continent and increased south-south cooperation among Member States. There needs to be effort to ratify significant legislation, develop and update cybersecurity policies and strategies and strengthened political will and commitment, among others. African countries that have achieved TIER 1 status as determined by the ITU-GCI index, need to work more with other countries who are not at such an established stage in order to encourage progress. Countries that have progressed and made strides in cybersecurity development, and are further influencing cybersecurity frameworks internationally, must be burdened with the responsibility to pull others along.
Africa needs to develop a collective responsibility to cybersecurity development because cybercrime is borderless. Participating in international processes matter; especially noting they provide frameworks that countries can abide by. However, the true test of success is not what is collectively agreed and signed at these global forums. Rather, it is what is implemented, experienced and ultimately sustained at the national and regional level. Multilateralism succeeds when societies begin to feel the impact. This means strengthened institutions, empowered communities and improved lives.