By Stéphane Mbiankeu Nguea
Executive Summary
Cameroon’s digital economy has advanced rapidly, but cybersecurity protections have not kept pace with this expansion. Between 2020 and 2023, cyberattacks in the country rose by 156%, while financial losses from digital fraud exceeded $45 million over that same period. In 2024 alone, attacks exploiting security vulnerabilities jumped 91% year-on-year, from 174,472 to 333,930 incidents. These figures do not represent isolated anomalies; they are symptomatic of a structural mismatch— the state is accelerating digital transformation while security remains treated as a subsequent consideration. This brief posits that cyber security in Cameroon requires repositioning, not merely, as a technical function managed by a single agency, but as a core component on industrial policy. Protecting the digital economy is inseparable from building it.
Key Messages
– Cyberattacks have become a significant economic and industrial risk with direct implications for SND30 objectives across manufacturing, fintech, and e-government.
– Cameroon’s legal framework, anchored in 2010 legislation and 2012 decrees — is structurally outdated relative to the current threat environment.
– Investment in cybersecurity capacity, skills, and institutions should be considered productive infrastructure spending – essential for securing the digital economy and sustaining long-term growth.
Introduction
The National Development Strategy 2020–2030 (SND30) places digital transformation at the centre of Cameroon’s route toward middle-income status. The stated ambitions include expanding e-government services, formalising the economy through digital ID and payment systems, and increasing manufacturing’s contribution to GDP up to 25% by 2030. These targets are interconnected and mutually reinforcing. Yet they depend on a digital infrastructure that is under significant strain. Cameroon now has more than 10 million internet users, with an internet penetration rate of approximately 45% in 2024. This represents a threshold at which digital exposure has become systemic rather than niche. Online commerce, mobile payments, cloud based administrative services, and connected industrial systems have become integral to everyday economic activity. However, each route also presents a potential entry point for actors with increasingly sophisticated capabilities. On the public response side, the National Agency for Information and Communication Technologies (ANTIC) processed 32,500 legal requests tied to cybercrime in 2025, representing an increase of approximately30% from the previous year. ANTIC also identified 8,502 security vulnerabilities through audits conducted since January 2024. Taken together, the evidence points not to policy inaction, but to a growing gap between threat evolution and institutional response capacity. That mismatch constitutes the central policy problem.
The Threat Landscape and Its Industrial Consequences
Discussions of cybersecurity in Africa often focus on high-profile cybersecurity incidents or abstract GDP loss estimates. The more instructive question for Cameroon is a sectoral one: which parts of the economy are most exposed, and what does that mean for industrialisation? The financial services sector is the most exposed. Mobile money platforms, microfinance institutions, and the banking system rely on digital transaction rails that, in Cameroon, often lack adequate layered protection. The most common attack vectors — phishing, ransomware, and Remote Desktop Protocol intrusions — are well-documented. Across Africa, the costs of these attacks are real and growing: the continent lost an estimated $3.5 billion to cybercrime between 2019 and 2025, with annual losses now conservatively placed between $4 billion and $10 billion. For an economy of Cameroon’s size, even a fraction of that exposure is material. Beyond finance, there are consequences for manufacturing and industrial investment. Businesses evaluating whether to establish or expand operations in Cameroon weigh the regulatory environment, infrastructure reliability, and — increasingly — digital security.
Industrial operations reliant on networked machinery or cloud-managed logistics face exposure that was not the case a decade ago. Weak cybersecurity does not just create direct losses; it raises the cost of doing business and suppresses the foreign and domestic investment that SND30 depends on. The informal sector adds another layer of complexity. Approximately 90% of Cameroon’s economy remains informal. As formalisation efforts push more small businesses online — through digital tax registration, mobile banking, and e-commerce platforms — they enter a threat environment they are unprepared for. Small enterprises are attractive target due to lower investment in security and slower recovery from breaches.
The Institutional and Regulatory Gap
Cameroon’s cybersecurity architecture has a recognisable structure. ANTIC is mandated to oversee digital security, conduct audits, and coordinate incident response through the Computer Incident Response Team (CIRT). The legal framework draws on the 2010 Law on Cybersecurity and Cyber-criminality, supplemented by a series of 2012 decrees governing network audits, infrastructure sharing, and electronic communications. The challenge lies not in the absence of a framework, but in its age. The 2010 legislation predates the era of cloud computing, mobile money at scale, ransomware-as-a-service, and state-sponsored Advanced Persistent Threat campaigns. Between 2021 and 2023, intelligence reports identified 45 APT campaigns targeting Cameroon’s critical infrastructure — telecoms, energy management systems, and public networks. These attacks differ in character from the phishing incidents the original legal architecture was designed to address.
A further institutional constraint is capacity. The Cybercrime Investigation Unit operates at approximately 23% of its required personnel level, and the majority of cyber incidents — around 67% — involve cross-border elements that current enforcement mechanisms struggle to handle. Equipment upgrades funded through the World Bank’s PATNUC project — five high-performance servers, digital investigation platforms, and penetration testing tools commissioned in January 2026 — represent a significant upgrade, but investment in equipment should be complemented by parallel investments in human capital and institutional capacity. The regulatory framework also lacks explicit control standards. Cameroon’s legal provisions allow for security audits but do not enumerate the specific controls organisations must implement, leaving compliance open to interpretation. Integrating NIST frameworks or ISO 27001 standards into audit requirements would provide both clarity and international alignment.
Policy Recommendations
Three interconnected reforms would move Cameroon meaningfully toward treating cybersecurity as industrial infrastructure.
- Modernise the legal and regulatory framework
The 2010 cybersecurity law requires a comprehensive revision that addresses cloud environments, data residency, breach notification obligations, and sector-specific requirements for critical infrastructure, including energy, telecoms, and financial services. This revision should explicitly incorporate international control standards — at minimum, alignment with NIST CSF or ISO 27001 — as mandatory baselines for organisations handling public data or operating in regulated sectors. Regional harmonisation with CEMAC’s electronic communications directives should be a parallel objective, given that the majority of attacks originate from or route through cross-border networks.
- Build cybersecurity human capital as a deliberate investment
Institutional reform depends on adequate staffing. Cameroon’s universities and technical institutions should introduce dedicated cybersecurity curricula at undergraduate and postgraduate level, with state scholarships attached to commitments in public sector roles. ANTIC’s Cybercrime Investigation Unit should be fully staffed as a priority. In the interim, the regional training initiative undertaken jointly by Kaspersky and INTERPOL’s AFRIPOL — which brought together investigators from 23 African countries between November 2025 and March 2026 — offers a model for accelerated capacity building while domestic pipelines mature.
- Embed cybersecurity standards in industrial and investment policy
Cameroon’s investment promotion frameworks — including those governing industrial zones and public-private partnerships — should include minimum cybersecurity requirements as conditions of approval or eligibility for fiscal incentives. This would strengthen investor confidence and improve the overall digital business environment. It would also create a compliance market that can stimulate the growth of local cybersecurity firms, contributing to the knowledge economy SND30 envisions. SME support programmes should include subsidised access to managed security services, recognising that the informal-to-formal transition exposes hundreds of thousands of small businesses to threats they cannot individually absorb.
Conclusion
Cameroon is at a moment where its digital ambitions and its digital vulnerabilities are growing in parallel. The investments being made in connectivity, e-government, and digital financial services are real and consequential. So are the risks. The policy gap has been the absence of a posture that treats those risks as an industrial concern rather than a technical one. Cybersecurity should be considered a strategic investment that supports sustainable digital and industrial development. In the context of SND30, it is a precondition for the returns that digital transformation is supposed to generate. A factory that is breached loses output. A fintech that is compromised loses customers and investor confidence. A government portal that is defaced loses legitimacy. These outcomes are incompatible with the development goals Cameroon has set for itself. The reforms needed are not exotic. A revised legal framework, a staffed and equipped enforcement unit, and security standards embedded in investment policy are all feasible within existing institutional structures. What they require is a deliberate decision to place cybersecurity on the industrial policy agenda.



Leave A Comment