African Nations Join UN Cyber Crime Initiative

African diplomats will meet their global counterparts in New York on January 17th to thrash out the details of a proposed new United Nations (UN) treaty to tackle cyber crime. It will be an opportunity for the African delegates to highlight growing digital threats and determine how to define, investigate and prosecute what is in effect a borderless crime.

Existing treaties such as the Budapest Convention or the African Union (AU) Convention on Cybercrime and Personal Data Protection (the Malabo Convention) are considered by some states to be useful if somewhat limited regional instruments. 

Russia has been among the countries arguing for a UN-wide convention, with cyberspace increasingly becoming a theatre of geopolitical competition.

The New York meeting is an example of the growing influence of cyber diplomacy. It is among a raft of multilateral forums, many of them led by the UN and driven by competing resolutions, where cyber governance, resilience, capacity and response are discussed. 

The core of such engagements is how states balance freedom of information, privacy and security in the rapidly evolving digital world.

An upcoming Institute for Security Studies (ISS) report explains why Africa cannot afford to take a back seat in such diplomatic discussions. The continent currently lags behind many other parts of the world when it comes to digital ‘capacity’, the people, processes and technology that define the digital age. Discussions on cybercrime, cyber security and how future digital technology is developed, diffused and deployed cannot be the sole preserve of richer nations with more advanced digital capabilities. 

Those same technologies are increasingly being used in Africa to shape the way business, government and security are conducted.

Africa’s more digitally advanced states, including Kenya, South Africa, Mauritius, Nigeria, Ghana, Morocco, Egypt and Rwanda, must articulate the continent’s digital priorities coherently and convert this into organisational strength. This would almost certainly bolster Africa’s influence in cyber diplomacy negotiations. One regional cyber security expert interviewed for the ISS report observed that in many multilateral forums, ‘cyber superpowers view Africans as junior partners needed to make up the numbers in possible coalitions.’ 

To counteract this, Africa needs continental champions who can negotiate common digital positions for presentation by continent-wide bodies such as the AU.

Examples of the most pressing issues include how African states can rapidly develop their digital capacity in line with the AU’s Digital Transformation Strategy. Beyond this are issues of cyber security. For instance, how should African states respond to attacks on critical infrastructure or the weaponisation of cyberspace to conduct disinformation campaigns and undermine democracy? 

It also includes the threat posed by cyber-enabled crimes. Their perpetrators use the internet to engage in traditional crimes like fraud and forgery, human trafficking or the illicit trade in drugs, wildlife products, weapons, precious stones etc.

The AU’s Digital Transformation Strategy emphasises the economic and developmental potential of rapid digital advances to the continent. A key part of this is ensuring equitable access to digital technologies and building the human capacity to benefit from them. However, discussions are needed on the unintended consequences of evolving technologies on human security. Without strategic thinking on shaping and taming the algorithms and deploying future digital technologies, African states risk being swept along by the more digitally mature superpowers and their agendas. 

The continent needs to upskill African cyber diplomats and embed digital knowledge across government. 
Competition over the ownership of emerging technologies and related power relationships are another reason Africa should engage more actively in cyber diplomacy.  African states need the infrastructure underpinning digital technologies such as the networks, hardware and other tools that define the cyber ecosystem. This makes them dependent on other state actors and their proxies but also leaves them vulnerable to influence and imported norms about privacy, mass surveillance and security.

The rapid rollout of CCTV camera systems along with facial recognition tools supplied by Chinese firms in countries including Ethiopia, South Africa, Kenya and Zimbabwe have ignited a debate about sovereignty, technological interdependence and digital feudalism.

Given the modest level of digital development among many of the AU’s 54 states, Africa seems particularly vulnerable to tech-infused geopolitics. The economic challenges facing many countries on the continent may incline them to opt for the cheapest tech rather than the most secure. The ISS report argues that the AU should encourage states to, where possible, delink trade from cyber diplomacy dialogue. Bilateral trading relationships with powerful state tech suppliers may cloud judgements over governance issues, for example. 

Delinking trade from tech may encourage continent-wide approaches to governance and cyber security rather than pursuing individual short-term economic gains. This would reduce the potential for global powers to adopt ‘divide and rule’ strategies on digital issues. With their relatively youthful populations, African states can also position themselves as a rapidly expanding future source and marketplace for new technology. The emergence of indigenous technologies such as M-Pesa in Kenya is an example of local innovation. 

According to World Bank figures, by 2050, one in four of the world’s people will come from sub-Saharan Africa. This, together with the continent’s large proportion of young people, provides leverage for African states to ensure their current digital needs and challenges are addressed as a global priority.

Article First published by ISS Today

Karen Allen is an  and former BBC Foreign Correspondent, an expert on international policy and founder of Karen Allen International

You Might Also Read: 

Internet Cable To Encircle Africa:

 

« The Cyber Skills Shortage & Training Gap - What Is The Solution?
Azure Active Directory Recycle Bin Won’t Save Your Critical Data »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

AlgoSec

AlgoSec

The AlgoSec platform enables the world’s most complex organizations to gain visibility, reduce risk and process changes at zero-touch across the hybrid network.

Technology Association of Georgia (TAG)

Technology Association of Georgia (TAG)

TAG's mission is to educate, promote, influence and unite Georgia's technology community to stimulate and enhance Georgia's tech-based economy.

Software Testing News

Software Testing News

Software Testing News provides the latest news in the industry; from the most up-to-date reports in web security to the latest testing tool that can help you perform better.

Gatewatcher

Gatewatcher

Gatewatcher is a digital breach detection platform targeting crafted attacks and protecting organizations against advanced cyber threats.

Assured Information Security (AIS)

Assured Information Security (AIS)

AIS is committed to providing our customers with critical information security products, services, and training. We support diverse needs throughout business and industry.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Totaljobs

Totaljobs

Totaljobs is the UK’s largest hiring platform. We have over 280,000 live jobs adverts on our site, helping you to find any type of job in any industry, including cybersecurity.

Symantec

Symantec

Symantec delivers data-centric hybrid security for the largest, most complex organizations in the world – on devices, in private data centers, and in the cloud.

Seavus Accelerator

Seavus Accelerator

Seavus Accelerator's goal is to create an enabling and stimulating environment for start-ups growth and provide continuous high quality acceleration and investment support.

CoursesOnline

CoursesOnline

CoursesOnline.co.uk is a database listing IT security courses from providers across the UK.

DeepFactor

DeepFactor

DeepFactor is the industry’s first Continuous Observability platform enabling Engineering and AppSec teams to find and triage RUNTIME security, privacy, and compliance risks in your applications.

evolutionQ

evolutionQ

evolutionQ delivers quantum-risk management strategies and robust cybersecurity tools designed to be safe in an era with quantum computing technologies.

Spinnaker Support

Spinnaker Support

Spinnaker Support is a premier global provider of on-premise and cloud-based enterprise software support services.

at-yet (@-yet)

at-yet (@-yet)

at-yet are an interdisciplinary team of experts. We are all about achieving results, whatever the situation – an acute incident, risk minimisation, safeguarding or data protection.

SFY Information Technology

SFY Information Technology

SFY helps companies with Cyber Security and Managed IT, allowing them to focus on what really matters to them.

Cyvore Security

Cyvore Security

Cyvore combines cutting-edge AI, machine learning, and behavioral analytics to detect, investigate, and neutralize threats before they compromise your organization.