By Felix Fomengia
Cameroon’s digital transformation is expanding the number of services that process personal data, financial transactions, identities and critical operational information. Mobile-money services, fintech platforms, government portals, health systems, education platforms and small-business applications increasingly depend on cloud infrastructure, application programming interfaces (APIs), mobile applications and third-party software.
This growth creates economic opportunity, but it also expands exposure to credential theft, account takeover, ransomware, insecure APIs, data leakage, payment fraud and AI-enabled social engineering. The appropriate response is not simply to purchase more cybersecurity tools or conduct occasional awareness campaigns. Cameroon needs a measurable security operating model that combines governance, asset visibility, access control, secure software engineering, fraud prevention, incident response and recovery.
Cameroon already has a statutory cybersecurity framework under Law No. 2010/012 of 21 December 2010 relating to cybersecurity and cybercriminality. This legal framework provides an important foundation for cybersecurity; its effectiveness at the service level depends on translating its principles and obligations into practical technical and operational controls. Organisations must know their systems and data, control access to them, build software securely, monitor misuse, respond to incidents and restore essential operations safely. The World Bank’s digital-transformation work in Cameroon has similarly identified the importance of secure and resilient digital services, stronger trust frameworks and critical-infrastructure risk management. Law No. 2010/012 | World Bank digital-transformation programme
Cybersecurity must be governed as operational risk
Cybersecurity should be treated as an organisational risk and resilience issue, not solely as a technical function. A serious cyber incident can disrupt payments and services, expose sensitive information, interrupt operations, damage trust and create regulatory or financial consequences. Responsibility for cyber risk therefore belongs at both executive and technical levels.
Organisations operating critical digital services should assign clear responsibility for cyber risk, designate security leadership, maintain a risk register and track key indicators such as MFA coverage, critical vulnerabilities, application security testing, incident-response times and backup recovery.
This is consistent with the NIST Cybersecurity Framework 2.0, which organises security outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. The framework is useful because it prevents cybersecurity from becoming only a technology-purchasing exercise. NIST Cybersecurity Framework 2.0
Organisations must know what they are protecting
An organisation cannot secure systems it does not know exist. Many incidents become severe because a company has lost track of an exposed test environment, cloud storage repository, old domain, administrator account, third-party integration or database containing sensitive data.
The first implementation priority should be a continuously maintained asset and data inventory. It should cover internet-facing websites and applications, APIs, domains, cloud accounts, servers, storage services, databases, employee devices, privileged accounts, application secrets, remote-access tools, backup systems and third-party suppliers. Every critical asset should have a business owner, a technical owner, an identified location, a security classification and a recovery priority.
Data must also be classified by sensitivity. Public information requires integrity controls; internal information requires authenticated access; confidential data requires restricted sharing, encryption and audit logs; and restricted information, such as payment records, identity documents, authentication secrets and health data, requires the strongest access controls, encryption, monitoring and retention rules. Production customer data should not be casually copied into personal devices, unsecured spreadsheets or development environments.
Make identity the primary security boundary
Many serious cyberattacks begin with compromised credentials rather than a failure of the organisation’s firewall. Attackers exploit reused passwords, phishing messages, social engineering, excessive privileges and poorly protected administrator accounts. For this reason, identity security should be treated as a primary control.
Multi-factor authentication should be mandatory for email, cloud-administration consoles, remote access, source-code repositories, payment and payroll systems, databases, backup platforms and other high-risk services. Privileged users, including system administrators, developers with production access and finance teams, should move progressively toward phishing-resistant methods such as FIDO2 security keys or passkeys based on FIDO/WebAuthn.
CISA identifies FIDO/WebAuthn as a widely available phishing-resistant authentication method, using cryptographic verification tied to the legitimate service to reduce the risk of credential theft through phishing. CISA guidance on phishing-resistant MFA
Strong authentication should be combined with least privilege: users and applications should receive only the access they need, privileged accounts should be separated and monitored, and access should be reviewed regularly, especially when roles change or staff leave.
Secure software and APIs before deployment
As Cameroon expands digital payments, online public services and consumer applications, software security must be embedded from design through operation. Security cannot be a final penetration test conducted shortly before launch.
A secure software-development process should begin with security requirements and threat modelling, particularly for platforms that process payments, personal data or identity information. It should continue through secure coding, peer review, automated source-code and dependency scanning, secret scanning, vulnerability remediation, independent testing and security logging. Development, test and production environments should be separated, and sensitive production data should not be used in testing without appropriate controls.
NIST’s Secure Software Development Framework provides a practical reference for these activities, including preparing the organisation, protecting software from tampering, producing secure software and responding to vulnerabilities after release. NIST Secure Software Development Framework
API security is critical because APIs connect applications, payment systems and third parties to core organisational data. Sensitive APIs should enforce server-side authorisation, least-privilege access, rate limiting, input validation, secure key management, encryption in transit, removal of unused endpoints and logging of high-risk activities.
The OWASP API Security Top 10 highlights risks including broken object-level authorisation, broken authentication, security misconfiguration and unsafe use of third-party APIs. These risks are directly relevant to any platform that handles customer data or financial transactions. OWASP API Security Top 10
Design processes to resist fraud
AI tools are making fraud more convincing and scalable. Criminals can create fluent English and French messages, imitate writing styles, produce fraudulent invoices, clone voices and target many people at once. The response cannot depend only on asking citizens or staff to “be careful.” High-risk processes must be designed to resist deception.
Organisations should protect their email domains with SPF, DKIM and DMARC; use email and endpoint security controls; monitor abnormal login, account-recovery and transaction behaviour; and apply additional verification to risky payments. Changes to supplier-bank details, payroll instructions or high-value transfers should never be approved solely through email, messaging applications or voice calls. They should be verified using a previously known contact method and independently approved.
Financial and digital-service providers should monitor signals such as new devices, unusual login locations, changed beneficiaries, rapid account changes, abnormal payment values and repeated failed authentication attempts. These indicators can trigger enhanced verification, temporary holds or investigation before funds are transferred.
Prepare to detect, respond and recover
Prevention will sometimes fail. The decisive question is whether an organisation, SME or startup can detect compromise early, limit the harm and restore services quickly.
Critical systems should send security-relevant logs to a central monitoring platform or managed security provider. Monitoring should identify repeated failed logins, suspicious privileged access, new administrator accounts, unusual downloads or deletion of customer data, changes to cloud permissions or payment rules, unusual use of service accounts and suspicious access to backup infrastructure.
Every organisation should maintain and test an incident-response plan. The plan must identify who has authority to make decisions, contain an attack, preserve evidence, notify customers or regulators when required, communicate externally and restore services. Tabletop exercises allow organisations to test these arrangements before a real incident. CISA provides practical exercise resources covering ransomware, phishing and other scenarios. CISA Tabletop Exercise Packages
Recovery must be engineered in advance. Backups should be encrypted, segregated from production systems, protected by separate credentials and tested through actual restoration exercises. At least one critical backup copy should be offline, immutable or logically isolated so that ransomware cannot easily encrypt or delete it. CISA’s ransomware guidance recommends maintaining offline, encrypted backups and regularly testing their availability and integrity. CISA #StopRansomware Guide
What policymakers should prioritise
Cameroon should build on ANTIC’s existing cybersecurity and CIRT capabilities by consistently enforcing proportionate baseline controls across critical digital services. These should include strong access controls, encryption, secure software development, vulnerability management, security logging, incident response, protected backups and third-party risk management.
Security requirements should also become standard in public procurement. Government technology contracts should require secure-development practices, independent security testing, audit logs, encryption, vulnerability-disclosure commitments, incident-notification obligations and tested business-continuity arrangements. A platform should be assessed not only by how quickly it can be launched, but also by how securely it can be operated, updated, audited and recovered.
Conclusion
Cameroon’s digital future will depend not only on expanding digital services, but on ensuring that the systems supporting citizens, businesses and public institutions are secure and resilient. Effective cybersecurity requires an integrated operational capability combining accountable leadership, asset visibility, strong identity controls, secure software delivery, fraud prevention, continuous monitoring, incident response and recoverable infrastructure. Digital growth and cybersecurity are complementary priorities. Secure and resilient digital services are essential to sustainable innovation, investment, public confidence and economic participation.
About Felix Fomengia
Felix Fomengia is an award-winning cybersecurity and digital technology professional with 8+ years of experience across security architecture, secure product development, digital transformation and technology entrepreneurship. He holds an MSc in Cybersecurity and Forensics from the University of Westminster, London, and has a proven track record of building and scaling digital products, strengthening production security and delivering technology-led transformation across private-sector, multilateral and international environments.
