Email Security Practices for Organizations in Nigeria
For many Nigerian organizations, email is the lifeblood of daily operations. It is how you communicate with clients, process orders, share sensitive documents, and coordinate with teams. But this essential tool has also become the primary battleground for cybercriminals.
The numbers are alarming. Nigerian organizations face an average of 4,388 cyberattacks per week—a 47% increase that marks the country as Africa’s most targeted nation. Business email compromise (BEC) and cloud exploitation account for most of these attacks, with Nigeria recording the highest weekly attack volume on the continent at 4,200 attempts per organization, compared to the continental average of 3,153 and the global average of just 1,963.
In 2025 alone, the Nigeria Police Force National Cybercrime Centre, in collaboration with the FBI and US Secret Service, arrested high-profile fraud suspects involved in targeted cyberattacks against corporate email systems. The attackers used a sophisticated phishing toolkit known as RaccoonO365 to create fraudulent Microsoft login portals, harvesting user credentials and gaining unauthorized access to corporate email accounts. Between January and September 2025, multiple organizations suffered unauthorized Microsoft 365 account access, leading to business email compromise, data breaches, and significant financial losses.
This guide explores the email security threats facing Nigerian organizations, the legal framework that governs data protection, and practical steps for building a resilient email security posture.

The Threat Landscape: What Nigerian Organizations Face
Business Email Compromise (BEC)
Business email compromise is the most significant email security threat facing Nigerian organizations. Interpol’s African Cyberthreat Assessment Report labels Nigeria a continental hub for BEC and ransomware. Attackers compromise legitimate business email accounts and use them to send fraudulent payment instructions, request sensitive information, or redirect funds.
The financial impact is staggering. Recent arrests by the Nigeria Police Force, FBI, and US Secret Service revealed that between January and September 2025, multiple organizations suffered unauthorized Microsoft 365 account access through phishing emails carefully crafted to mimic legitimate Microsoft authentication pages. These attacks led to business email compromise, data breaches, and financial losses across multiple jurisdictions.
Phishing and Spear Phishing
Phishing remains the most common entry point for cybercriminals. Modern phishing campaigns are not only targeted but also personalized and psychologically nuanced. Fraudsters now harness publicly available data from social media profiles and corporate websites to craft emails that feel familiar and legitimate.
Ruth Itua, a security operations analyst, explains: “Phishing remains the easiest and most reliable entry point for criminals”. The introduction of multi-factor authentication (MFA) offered some respite, but attackers have quickly adapted. “We’ve seen fake MFA prompts, social engineering calls, and even QR-based phishing pages emerge,” she warns.
AI-Powered Attacks
The threat landscape is evolving rapidly. Threat actors are increasingly using artificial intelligence to automate phishing, impersonation, and cloud exploitation. AI-generated phishing, credential theft, and misconfigured cloud environments are now the leading causes of compromise.
As Kingsley Oseghale, Country Manager for West Africa at Check Point Software, notes: “AI has become part of the attack surface. Attackers are using it to automate phishing and identity theft at scale”. Deepfake incidents have increased by 300%, with fraudsters impersonating executives to drain corporate funds.
Ransomware and Data Extortion
Traditional ransomware has evolved into data-leak extortion, where criminals threaten to expose sensitive data rather than simply encrypting it. Ransomware attacks encrypt business data and demand payment for the decryption key, with email often serving as the initial vector.
The Legal Framework: What the Law Demands
The Nigeria Data Protection Act (NDPA) 2023
The NDPA, which replaced the NDPR in September 2025, is Nigeria’s primary data protection legislation. It requires that every act of data processing—including sending an email—has a lawful basis. For email communication, the two most relevant bases are consent and legitimate interest.
Key Requirements for Email Communication:
Consent must be explicit and freely given. A pre-ticked checkbox is not valid consent under Nigerian data protection law. Every marketing email sent without proper consent was sent without a lawful basis.
Transactional emails (order confirmations, password resets, delivery updates) are typically covered by legitimate interest and do not require explicit consent.
Marketing and promotional emails require explicit, informed consent. The NDPA gives data subjects the right to object to processing for direct marketing.
Data subjects must be able to unsubscribe easily. The NDPA requires you to honor opt-out requests promptly.
The NDPA applies to any organization processing the personal data of Nigerian residents or citizens. An email address is personal data—it identifies an individual or makes them identifiable. There is no small business exemption.
The Cybercrimes (Prohibition, Prevention, etc.) Act 2015
The Cybercrimes Act provides the criminal framework for email-related offenses:
Section 9 addresses the interception of electronic messages, emails, and electronic money transfers.
Section 10 makes it unlawful for employees to commit unauthorized acts with respect to emails or critical infrastructure.
Section 11 addresses the willful misdirection of electronic messages.
Willful destruction or abortion of electronic mails through which money or valuable information is being conveyed carries imprisonment of 7 years on first conviction and 14 years on second conviction.
Phishing—attempting to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity—is explicitly prohibited.
The Nigeria Data Protection Commission (NDPC)
The NDPC, established under the NDPA, is the primary enforcement authority. Organizations processing data for more than 2,000 data subjects within a 12-month period have additional audit filing obligations with the NDPC. The NDPC has demonstrated a willingness to enforce compliance, with significant fines imposed on organizations for data protection breaches.
NITDA and the National Cybersecurity Framework
The National Information Technology Development Agency (NITDA) has confirmed plans to roll out a cybersecurity framework that will set minimum cybersecurity spending requirements and introduce mandatory breach-reporting timelines. NITDA has reiterated that all Ministries, Departments, and Agencies must comply with the National Cybersecurity Policy and Strategy (NCPS) 2021.
Lagos State Cybersecurity Guidelines
In April 2026, the Lagos State Government unveiled comprehensive cybersecurity guidelines designed to enhance digital safety for businesses. The guidelines offer practical, scalable measures including data minimization, encryption, incident response plans, and mandatory reporting of cyber incidents within 72 hours.
The Pain Points: Why Nigerian Organizations Struggle with Email Security
Let us be honest. Most organizations know they should secure their email systems, but they do not. Here is why:
The Human Factor. The most potent defence may not be the latest firewall or intrusion detection tool—it may be people. Yet many organizations treat cybersecurity as a technology problem rather than a human one. “The problem is no longer a lack of technology; it is the human factor,” Ruth Itua asserts.
The Training Deficit. Phishing emails are the most common initial vector for Nigerian business cyberattacks, yet basic staff awareness training remains inadequate. Many employees cannot recognize suspicious emails, do not know how to report them, and are unaware of the risks of clicking unsolicited links.
Weak Authentication. Despite the availability of multi-factor authentication, many Nigerian organizations still rely on passwords alone. Attackers have adapted, creating fake MFA prompts and QR-based phishing pages to bypass even this layer of protection.
The Regulatory Gap. While the NDPA provides a framework for personal data protection, many businesses remain unaware of their obligations. They collect email addresses without proper consent, send marketing emails without lawful basis, and fail to honor unsubscribe requests.
The False Sense of Security. Many organizations believe that because they have antivirus software or a firewall, they are protected. This is a dangerous misconception. As Check Point’s report notes, “AI has become part of the attack surface”. The threat landscape is evolving faster than many defenses.
Inadequate Incident Response. When a breach occurs, many organizations do not have a plan. They do not know who to contact, how to contain the breach, or how to report to regulators. The Lagos State guidelines require reporting cyber incidents within 72 hours—a deadline many organizations are unprepared to meet.
Essential Email Security Practices
1. Implement Email Authentication Protocols
Email authentication prevents attackers from spoofing your domain and impersonating your organization.
What to Do:
SPF (Sender Policy Framework). Specify which servers are authorized to send email from your domain.
DKIM (DomainKeys Identified Mail). Digitally sign outgoing emails to verify they were not tampered with.
DMARC (Domain-based Message Authentication, Reporting, and Conformance). Set policies for how receivers should handle emails that fail SPF or DKIM checks, moving DMARC toward quarantine or reject enforcement.
2. Require Multi-Factor Authentication (MFA)
Passwords alone are no longer sufficient. Require phishing-resistant MFA for all email accounts. Close legacy authentication paths that attackers probe after modern login flows are locked down.
Key Point: Attackers have adapted to MFA. They now use fake MFA prompts, social engineering calls, and QR-based phishing pages. Train employees to verify MFA prompts and report suspicious requests.
3. Deploy Layered Email Filtering
Keep native email filtering in place, then layer behavioral and language-aware detection for novel, well-written lures. Use solutions that can detect AI-generated phishing attempts and sophisticated impersonation attacks.
4. Train Employees to Recognize Phishing
Regular, realistic, and engaging training programmes are essential. The organizations that treat their staff as active defenders instead of weak links will stay ahead.
What to Do:
Conduct regular phishing simulations.
Provide bite-sized training for all employees.
Establish clear reporting processes for suspicious emails.
Include warnings for “urgent payment” or “account update” requests.
Provide training on recognizing suspicious email addresses, urgent language, and unexpected attachments or links.
5. Encrypt Sensitive Emails
Protect sensitive communications and data with encryption. Ensure that confidential information is not transmitted in plain text.
6. Implement Strong Password Policies
Ensure that users create and maintain strong passwords for their email accounts to prevent unauthorized access. Enforce password complexity requirements and regular password changes. Educate employees about the risks of clicking on links or downloading attachments from unknown sources.
7. Keep Software Updated
Ensure that anti-malware protection is installed on all IT systems to protect your organization’s network from potential attacks through virus-laden software and email attachments. Apply security patches promptly.
8. Document and Review Email Policies
Document your email security policies and ensure employees are aware of them. Review and update policies regularly.
What Policies to Include:
Acceptable use of email
Password and authentication requirements
Reporting procedures for suspicious emails
Data protection and confidentiality requirements
Consequences of policy violations
9. Conduct Regular Security Audits
Regular security audits help identify vulnerabilities before attackers exploit them. Penetration testing is essential to see how employees interact with scenario-based attacks. Consider regular vulnerability assessments and penetration testing of your email systems.
10. Develop an Incident Response Plan
When a breach happens, you need a plan.
What Your Plan Should Include:
Who is responsible for what
How to contain the breach
How to notify affected parties
How to report to regulators (within 72 hours under Lagos guidelines)
How to communicate with stakeholders
How to learn from the incident
11. Segment Email Systems
Separate work and personal email accounts. When possible, use separate devices to keep your work and personal email accounts separate. This limits the impact of a compromise.
12. Monitor for Compromised Accounts
Monitor for signs of unauthorized access: unusual login locations, unexpected email forwarding rules, or messages in sent folders that the user did not send. Implement real-time monitoring and alerting for suspicious activity.
How Qeeva Advisory Helps
At Qeeva Advisory, we understand that email security is essential for protecting your business information, maintaining customer trust, and ensuring regulatory compliance. We work with organizations of all sizes to build robust email security postures.
Our Risk Management Services encompass cybersecurity, fraud prevention and mitigation, regulatory compliance, third-party risk management, and internal audit support. We help you identify vulnerabilities and build systems that protect your business.
For businesses needing to understand the full scope of regulatory compliance, our Regulatory Compliance service provides comprehensive guidance on all your data protection and email compliance obligations under the NDPA 2023 and other regulations.
Our Advisory Services provide strategic guidance for developing and implementing email security strategies that align with your business goals.
We also offer Training and Capacity Building to equip your employees with the skills needed to recognize and respond to phishing attacks.
Our Business Strategy Consulting Services help you align your email security strategy with your overall business objectives.
Our Service Methodology
We do not offer generic solutions. Our methodology is designed to be thorough, transparent, and actionable, ensuring that your email security initiatives are grounded in your organisation’s unique realities and positioned for long-term success.
Step 1: Email Security Assessment
We begin by understanding your current email security posture. This includes reviewing your authentication protocols, filtering systems, employee training practices, and incident response capabilities. We identify gaps, risks, and opportunities for improvement.
This step is powered by our Risk Management Services .
Step 2: Email Security Framework Design
Based on the assessment, we help you design a comprehensive email security framework tailored to your business size, industry, and regulatory obligations. This includes authentication protocols, filtering systems, training programmes, and incident response plans.
This step is powered by our Advisory Services and Regulatory Compliance .
Step 3: Implementation Support and Training
We help you implement the framework—from deploying authentication protocols to training employees on phishing recognition. We provide ongoing support to ensure successful adoption and address challenges as they arise.
This step is powered by our Training and Capacity Building .
Step 4: Monitoring and Continuous Improvement
We provide ongoing support to ensure your email security practices remain effective as threats evolve and regulations change. This includes regular reviews, updates, and guidance on emerging best practices.
This step is powered by our Risk Management Services and Advisory Services .
Frequently Asked Questions
Q: What is the biggest email security threat facing Nigerian organizations?
A: Business email compromise (BEC) is the most significant threat, with Nigeria identified as a continental hub for BEC. Phishing attacks, increasingly powered by AI, are the most common entry point. Nigerian organizations face an average of 4,388 cyberattacks per week.
Q: What are the legal requirements for email communication under the NDPA?
A: Every act of data processing—including sending an email—must have a lawful basis. Marketing emails require explicit consent; transactional emails are typically covered by legitimate interest. Pre-ticked checkboxes are not valid consent. Data subjects have the right to object to direct marketing and must be able to unsubscribe easily.
Q: What are the penalties for email-related cybercrimes in Nigeria?
A: Under the Cybercrimes Act, willful destruction or abortion of electronic mails through which money or valuable information is being conveyed carries imprisonment of 7 years on first conviction and 14 years on second conviction. Phishing and unauthorized access to email systems can also result in significant fines and imprisonment.
Q: How can I protect my organization from phishing attacks?
A: Implement email authentication protocols (SPF, DKIM, DMARC), require multi-factor authentication, deploy layered email filtering, and conduct regular employee training with phishing simulations. The organizations that treat their staff as active defenders instead of weak links will stay ahead.
Q: What should I do if my organization experiences a data breach involving email?
A: Contain the breach, notify affected parties, report to the NDPC and other relevant authorities (within 72 hours under Lagos guidelines), communicate with stakeholders, and learn from the incident. Professional guidance is essential.
Q: How can Qeeva Advisory help my business with email security?
A: Qeeva Advisory provides comprehensive email security support including risk management, regulatory compliance, strategic advisory, training, and ongoing monitoring. Our Risk Management Services help you identify vulnerabilities and build systems that protect your business.
The Bottom Line
Email security is not optional—it is essential for survival in Nigeria’s digital economy. Nigerian organizations face an average of 4,388 cyberattacks per week, making the country Africa’s most targeted nation. Business email compromise and phishing attacks, increasingly powered by AI, are costing businesses billions.
The legal framework is clear and enforceable. The NDPA 2023 requires lawful processing of personal data, including email addresses. The Cybercrimes Act imposes severe penalties for email-related offenses. The NDPC is actively enforcing compliance. NITDA is rolling out a cybersecurity framework with mandatory spending and breach-reporting requirements.
Yet many organizations still treat email security as an afterthought. They rely on weak passwords, neglect employee training, and fail to implement basic authentication protocols. They hope they will not be targeted.
Hope is not a strategy.
The key is to be intentional, not reactive. Implement email authentication protocols. Require multi-factor authentication. Deploy layered email filtering. Train employees to recognize phishing. Encrypt sensitive emails. Develop an incident response plan. Document and review policies. Monitor for compromised accounts. Seek professional guidance.
With the right approach and the right support, any Nigerian organization can build an email security posture that protects business information, maintains customer trust, and ensures regulatory compliance.
The choice is yours.
Suggested Reading from Our Blog
Explore these related articles to deepen your understanding of information protection and business security:
Protecting Business Information in the Digital Age – Understand the broader information security landscape and how to protect your business assets.
Building PR Trust in an Age of Misinformation – Learn how to maintain authenticity, transparency, and trustworthiness in communication.
Related Services
We offer specialised services to help organizations build robust email security postures:
Risk Management Services – Cybersecurity, fraud prevention, regulatory compliance, and internal audit support.
Regulatory Compliance – Comprehensive guidance on all your data protection and compliance obligations under the NDPA 2023 and other regulations.
Advisory Services – Strategic guidance for developing and implementing email security strategies.
Training and Capacity Building – Equip your employees with the skills needed to recognize and respond to phishing attacks.
Business Strategy Consulting – Align your email security strategy with your overall business objectives.
Let’s Talk About Your Email Security Strategy
Email security is not just about technology—it is about protecting your business, your customers, and your reputation. At Qeeva Advisory, we take the time to understand your unique organisation and develop email security strategies that work for you.
Whether you need help with risk assessment, regulatory compliance, or employee training, our team is here to support you.
📞 Call us: (+234) 802 320 0801, (+234) 807 576 5799
📧 Email: info@qeeva.com
📍 Visit us: 5, Ishola Bello Close, Off Iyalla Street, Alausa, Ikeja, Lagos, Nigeria
Contact us today to schedule a complimentary consultation. We would love to hear about your organisation and explore how we can help you build an email security posture that protects your business.
Your journey to email security starts with a conversation. Let’s talk.
Reference Links / Sources
Police, US secret service, FBI arrest suspects in Nigeria over fraud – Daily Post NG
Police arrest suspects over Microsoft 365 phishing attacks – Tribune Online
Police Arrest Suspect over Microsoft 365 Cyber Attack – ThisDay Live
Nigeria faces rising tide of AI-powered cyberattacks – ITEdgeNews
Africa’s Digital Weak Link? Nigeria’s Alarming Position in Cybercrime Rankings – The Journal
Nigeria’s Data Protection Laws and Email Communication – SmartSMSSolutions
NITDA, CAC activate coordinated cybersecurity measures – ITEdgeNews
Nigeria mandates cybersecurity spending thresholds – The Paypers
Cyber security best practices for managing email – Canadian Centre for Cyber Security
12 Essential Email Security Best Practices for 2026 – Security Boulevard
Email security best practices – Canadian Centre for Cyber Security
Cybercrimes (Prohibition, Prevention, etc.) Act 2015 – NCC
NDPC Data Protection Compliance Guide – SmartSMSSolutions
Check Point African Perspectives on Cyber Security Report 2025 – Check Point Software










