- CybAfrique Newsletter
- Posts
- Should cybersecurity services be licensed?
Should cybersecurity services be licensed?
Inside: a refresher on Africa’s intra-continental fibres

CybAfriqué is a space for news and analysis on cyber, data, and information security on the African continent.
HIGHLIGHTS
Should cybersecurity services be licensed?
Cybersecurity is mostly an unregulated profession. In most parts of the world, if you want to setup shop as a security consultant, you wouldn't need to get any government certifications or qualifications first. Most parts of the world, not all.
Earlier this week, Ghana's Cyber Security Authority (CSA) fined a government agency and a private contractor a combined GH¢360,000 for breaking the country's cybersecurity licensing rules. The Office of the Registrar of Companies (ORC), a designated Critical Information Infrastructure institution, was ordered in June to hire a Tier 1 licensed provider to shore up its security, and it hired Purpleline Solutions Limited, a firm that had only applied for its license after regulators caught it working without one. ORC was fined GH¢240,000 across two separate penalties. Purpleline was fined a further GH¢120,000.
The fine is the latest bit of enforcement under a regime Ghana's CSA has been building since March 2023, when it began requiring Cybersecurity Service Providers, Cybersecurity Establishments, and Cybersecurity Professionals to be licensed or accredited under the Cybersecurity Act, 2020 (Act 1038). The move made Ghana the first country in Africa, and one of a handful worldwide, to license cybersecurity work the way many countries license doctors or lawyers.
And Ghana isn't the only one. Malaysia's Cyber Security Act 2024, which took effect that August, set up a similar Cyber Security Service Provider license covering services like penetration testing, managed security operations, digital forensics, incident response, and vulnerability assessment.
Singapore, which is among the earliest to go down this road, wrote a licensing framework into its Cybersecurity Act back in 2018, but began using it in 2022, using the years in between to consult industry. Today, anyone offering penetration testing or managed security operations centre monitoring in Singapore needs a license from the Cybersecurity Services Regulation Office. Operating without one can mean fines of up to S$50,000, prison time of up to two years, or both.
The thinking behind making cybersecurity a licensed occupation is that cybersecurity talent gets unsupervised access to a client's systems, networks, and data and can abuse said access. A client has almost no independent way to check whether the person probing their network actually knows what they're doing. Licensing, regulators argue, helps with standards and accountability.
It's the same logic that governs other sectors treated as vital to national order and security. Telecoms operators need spectrum licenses; private security firms need licenses too, in nearly every country on earth. Increasingly, governments are deciding that cybersecurity firms embedded within critical infrastructure deserve the same treatment.
This heavy regulatory environment makes it easier to enforce standards and policies, but it could also be abused. Governments can use these licenses to stifle open source culture, which much of the cybersecurity sector thrives on.
A refresher on Africa’s Intra-continental fibres
We have talked about this before. African countries have comparatively poorer and less efficient internet. One way they could solve that is by improving communication infrastructure, especially fiber and radio pathways between different countries. This would, in theory, improve efficiency, cost, and speed.
This week, Namibia and Botswana signed a Memorandum of Understanding on ICT cooperation in Kasane, covering broadband infrastructure, digital government, cybersecurity, and digital skills. The agreement lands alongside Namibia's Mobile Telecommunications Limited (MTC) just-completed fibre run from Gobabis to the Buitepos border, where it interconnects directly with Botswana Fibre Networks (BoFiNet) at Charles Hill. Namibia's ICT minister, Emma Theofelus, described it as the first direct cross-border fibre link between the two countries' operators.
It's not the only one on the continent. It joins a slew of similar announcements this year, including Zambia and Mozambique's new link between Chanida and Cassacatiza, the Djibouti-Ethiopia-Sudan Horizon Fibre Initiative, Paratus Group's 2,000km Goma-to-Mombasa route through Rwanda, Uganda, and Kenya, and the first phase of a new corridor linking Zimbabwe, Botswana, Zambia, and South Africa.
Last year had its own wave of these milestones spread across the continent's blocs. Kenya and Tanzania switched on a link at the Lunga Lunga-Horohoro border in the east, Algeria completed its segment of the Trans-Saharan fibre corridor reaching toward Niger, Chad, and Nigeria in the north, and Zimbabwe's Powertel signed the public-private partnership in the south that's only now bearing fruit.
Yet, the journey is still far. According to the Africa Broadband Outlook, published by the African Telecommunications Union and Africa Analysis, the continent still lacks the terrestrial density to move its abundant international bandwidth inland. Africa has 77 undersea cables landing on its coastlines, but its internet boom, as one analysis of the report put it, stops at the shoreline.
The continent has a landmass of 30 million square kilometres covered with 2,130,506 km of operational terrestrial fibre, with 1,337,158 km in maximum use, 112,373 km under construction, and 124,179 km planned. In comparison, India, a country roughly a tenth of Africa's landmass, had laid 4.24 million route kilometres of optical fibre cable by September 2025, according to its telecom ministry, nearly double Africa's continent-wide total.

FEATURES
HEADLINE
Nigerian banks respond decisively to worldwide cyber attacks
Papua New Guinea seeks feedback on digital ID, data protection laws
Morocco arrests suspects for inciting mass migration to Ceuta on August 15
NDPC hosts African peers to strengthen cross-border data security
Burundi extends biometric civil registration toward national digital ID
Angola’s new online content law raises compliance risks for digital platforms
Ethiopia INSA introduces critical infrastructure cybersecurity fund
Kenya orders cyber cafés to log customer identities from August 14
Somalia plans national data centre to strengthen digital infrastructure
Namibia and India explore cooperation on cybersecurity and digital transformation
South Africa’s largest private security company suffers data breach
Namibia, Botswana expand cross-border fibre and cybersecurity partnership
Reply