scieee AI-readable full text Open interactive document viewer

Criminal Uses of Information and Communication Technologies (ICTs) in Sub-Saharan Africa: Emerging Trends, Security Concerns, and Policy Perspectives

Ehigiator, Egho-Promise; ASANTE, GEORGE; Udoh, Ekereuke

Abstract

This study explores the new trends, driving factors and governance challenges to cybercrime in Sub-Saharan Africa (SSA). This research employed a mixed-methods design, incorporating a survey, interviews, and a literature review. The results indicate that the cyber security situation is advanced and dynamic, with the extensive deployment of phishing, viruses, and personal imitation on social media, as well as practices targeting small firms, learning institutions, and the general population. Many of the survey participants attested that they had experience of ICT-related crimes, showing an increased exposure to cyber threats in industries. The research also points to the high relationship between unemployment among young people and their involvement in cybercrime. The regulatory issues are still a problem, as the majority of the participants view national systems against cybercrime as ineffective. These observations are supported by the interview information that highlights the following issues as common obstacles to cyber security: infrastructural gaps, inadequate regional co-operation, and insufficient institutional capability. Considering these results, the study recommends a multi-layered policy-technology framework that includes legal reform, technology innovation, collaboration between the government and the business, and residents’ awareness to build cyber resilience in the region. The study makes a strong case for a concerted legal framework, cross-border collaboration, and digitally inclusive policies that can help in alleviating cyber risks and bringing security to the digital destiny of SSA.

Full text

IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -260 Criminal Uses of Information and Communication Technologies (ICTs) in Sub-Saharan Africa: Emerging Trends, Security Concerns, and Policy Perspectives Ehigiator Egho-Promise Department of Computing and Digital Tech., University College Birmingham, United Kingdom [email protected] https://orcid.org/0000-0001-8948-1813 George Asante Department of Information Technology Education, Akenten Appiah-Menka University of Skills Training and Entrepreneurial Development, Kumasi, Ghana [email protected] https://orcid.org/0000-0001-8061-5387 Udoh Ekereuke Department of Computing, QA Higher Education, London, United Kingdom ekereuke.ud[email protected]om https://orcid.org/0000-0003-1655-8829 Publication History Manuscript Reference: IRJCS/RS/Vol.12/Issue07/SPCS10081|ResearchArticle | Open Access | Double-Blind Peer Reviewed Article ID: IRJCS/RS/Vol.12/Issue07/SPCS10081Received:24,August 2025,Revised:30,August 2025, Accepted: 10 September 2025 Published Online: 18 September 2025 http://www.irjcs.com/volumes/Vol12/iss-07/02.SPCS10081.pdf Article Citation: Ehigiator,George,Udoh(2025),Criminal Uses of Information and Communication Technologies (ICTs) in Sub-Saharan Africa: Emerging Trends, Security Concerns, and Policy Perspectives . IRJCS: International Research Journal of Computer Science, Volume 12, Issue 07 of 2025 pages 260-271 doi:> https://doi.org/10.26562/irjcs.2025.v1207.02 BibTeX Ehiigiator@2025ICT Copyright: ©2025 This is an open access article distributed under the terms of the Creative Commons Attribution License; Which Permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited. Abstract: This study explores the new trends, driving factors and governance challenges to cybercrime in Sub-Saharan Africa (SSA). This research employed a mixed-methods design, incorporating a survey, interviews, and a literature review. The results indicate that the cyber security situation is advanced and dynamic, with the extensive deployment of phishing, viruses, and personal imitation on social media, as well as practices targeting small firms, learning institutions, and the general population. Many of the survey participants attested that they had experience of ICT-related crimes, showing an increased exposure to cyber threats in industries. The research also points to the high relationship between unemployment among young people and their involvement in cybercrime. The regulatory issues are still a problem, as the majority of the participants view national systems against cybercrime as ineffective. These observations are supported by the interview information that highlights the following issues as common obstacles to cyber security: infrastructural gaps, inadequate regional co-operation, and insufficient institutional capability. Considering these results, the study recommends a multi-layered policy-technology framework that includes legal reform, technology innovation, collaboration between the government and the business, and residents’ awareness to build cyber resilience in the region. The study makes a strong case for a concerted legal framework, cross-border collaboration, and digitally inclusive policies that can help in alleviating cyber risks and bringing security to the digital destiny of SSA. Keywords: ICT, Cyber security, cybercrime, Sub-Saharan Africa, Criminal INTRODUCTION Rapid digitalization is underway across sub-Saharan Africa, transforming economies and daily life. Mobile phone ownership and internet connectivity have expanded significantly in the past decade. As of 2023, mobile penetration in sub-Saharan Africa had reached about 44% of the population, and roughly 27% of people were using mobile internet (GSMA Intelligence, 2025). A fintech revolution accompanies this mobile-driven connectivity boom; the region has seen an explosion in mobile money and digital payment services (Adewopo et al., 2025). By 2024, sub-Saharan Africa counted over one billion registered mobile money accounts (double the number in 2020), representing more than half of all mobile money wallets in the world (GSMA Intelligence, 2025; South African Times, 2025). Such growth in connectivity and financial technology has brought many benefits, improving access to services and economic inclusion for millions (Pantserev 2022). IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -261 However, the digital boom has also given rise to new forms of criminal activity leveraging information and communication technologies (ICTs). Both cyber-enabled crimes (traditional offences, such as fraud, theft, or extortion, conducted via digital tools) and cyber-dependent crimes (offences that exist only because of ICT, such as hacking or malware attacks) are on the rise. Criminals have been quick to exploit the expanding digital ecosystem, often outpacing users’ awareness and defensive measures. Africa was the region with the highest number of weekly cyberattacks per organization in the world (Bhebe, 2022). Threat actors ranging from lone hackers to syndicates have targeted the proliferation of mobile devices and online services. Their attacks include phishing scams, fraudulent mobile money transactions, ransomware attacks, and data breaches. Thus, alongside the opportunities from ICT growth, sub-Saharan African countries are confronting a new wave of security concerns in the digital realm (Mapiye et al. 2023). Even though ICT has spurred socio-economic development in sub-Saharan Africa, it has also introduced new vulnerabilities. A growing reliance on digital platforms means that banking, communications, and other services are exposed to cyber risks. Criminal actors are adept at exploiting these vulnerabilities, often outpacing the ability of legal frameworks or security measures to adapt. Cybercrime is advancing faster than the capacity of many states to respond, with one report finding that 75% of surveyed African countries acknowledge their cybercrime laws and investigative resources need significant improvement (Atalayar, 2025). Consequently, African economies collectively lose an estimated $4 billion each year to cybercriminal activities (Kshetri 2019). One illustration of the lag in response is the African Union’s Malabo Convention on Cyber Security (adopted in 2014), which took nearly a decade to come into force and still lacks widespread ratification. These gaps underscore the need for a region-specific analysis of ICT-facilitated crimes in sub-Saharan Africa to understand emerging trends and to inform more effective, proactive responses. The main purpose of this study is to explore the criminal exploitation of ICTs in sub-Saharan Africa, assess emerging trends and security concerns, and propose strategic perspectives for mitigation. Specifically, the study seeks to:  Identify and classify the major ICT-related crimes in sub-Saharan Africa.  Analyse the socio-economic, legal, and technical factors contributing to the rise of digital crime in the region.  Evaluate the effectiveness of existing policy, legal, and institutional responses to cybercrime in sub-Saharan Africa.  Recommend multi-facet strategies for combating these ICT-facilitated criminal activities. In this study, a case study is conducted on the nations chosen from sub-Saharan Africa, specifically Nigeria, Kenya, Ghana, and South Africa, to review the regional trend. It includes crimes that merely utilize the internet (cyber-enabled, e.g., online fraud, extortion, impersonation through digital platforms), as well as those that could not occur without the internet (cyber-dependent, e.g., hacking, malware attacks that rely on the existence of networked systems). Still, in either case, it is civilian (as opposed to state-sponsored) and financial (as opposed to online warfare) (Ganda 2024). It is worth noting a couple of limitations. Data on cybercrimes remains limited in most countries in Africa, which makes analysis difficult. The fact that the four countries were identified can be seen as a limitation to the generalisation of the study’s results. Lastly, the rapidly developing aspect of technology implies that new threats may emerge within a short period. Thus, any recommendations may need to be reconsidered in light of the evolving digital landscape. II. REVIEW OF RELATED STUDIES 2.1 ICT Development and Digital Transformation in Sub-Saharan Africa In Sub-Saharan Africa, there have been significant developments in the area of ICTs, especially the high-speed growth in mobile broadband, digital identity, and online financial services, including mobile money platforms. These inventions have played a significant role in enhancing connectivity, financial access and accessibility to public amenities in towns and rural setups. Nevertheless, the area still has significant problems associated with infrastructure shortages and inadequate digital skills required to perform well in the new digital world. Consequently, despite an increase in the velocity of digital transformation, its unequal distribution is also a risk of further social and economic stratification. 2.2 Conceptualizing cybercrime Cybercrime is a crime conducted through the application of digital technology to target individuals, organizations, or governments. The term covers a broad scope of offences that include cyber-dependent crimes (ones which could not have been committed without digital technology, like hacking and malware distribution), and cyber-enabled crimes (traditional types of crime, facilitated by technology, including fraud and identity theft) (Wall, 2024). Digital fraud is a branch of cybercrime characterized by deceptive actions aimed at gaining profits, including phishing, business email compromise (BEC), and mobile money fraud.Transnational cyber threats span national boundaries and complicate policing as they tend to span multiple countries with jurisdictional difficulties (UNODC, 2013). Diverse authorities have various classifications of cybercrime. The UNODC classifies cybercrimes as falling under the offences against the confidentiality, integrity and availability of data, computer-related fraud and content-related crimes (UNODC, 2013). Interpol, in turn, pays more attention to monetary online crimes, including cyber banking crimes and ransom ware. In contrast, the African Union (AU) emphasizes those issues that are peculiar to this region, i.e., mobile money fraud and SIM swap fraud (African Union, 2014). These typologies emphasize the dynamic character of cyber threats that requires flexible legal and policy solutions. The absence of a harmonized legal framework is regarded as the crucial difficulty in defining Cybercrime in Africa. Whereas specific laws have been introduced in countries, including Nigeria (Cybercrimes Act, 2015), Ghana (Cyber Security Act, 2020 (Act 1038)) and South Africa (Cybercrimes Act, 2020), some countries still have old penal codes that are not sufficient to compact new forms of cyber threat (Chawki et al., 2015). This discrepancy makes crossborder co-operation during investigation of cybercrimes difficult. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -262 2.3 Trends in ICT-Related Crime in Africa Along with the skyrocketing digital revolution in Africa, Cybercrime has skyrocketed. Unfortunately, email fraud, notably Business Email Compromise (BEC), is getting out of control as criminals pretend to be executives and authorize payroll redirection scams (Bisson, 2020). It is reported that African companies lose millions of dollars every year due to such scamming with the key areas being Nigeria, Ghana, and South Africa (Kaspersky, 2024). Other rising issues are mobile money fraud due to the inequalities in the authentication of systems such as M-Pesa and MTN Mobile Money (Kshetri, 2019). Social engineering frauds are employed by criminals to extract PINs or exploit the agent networks to divert money. In the same way, SIM swap scams, in which attackers steal the mobile phones of a given victim to circumvent twofactor authentication, have also risen in jurisdictions such as South Africa and Kenya (ITU, 2021). Romance scams and phishing are still among the most popular frauds because criminal attackers rely on playing with human emotions to cheat a victim. Also, there have been ransom ware-related takeovers of such critical services as healthcare and government systems, which were the case during the 2021 attack of the Kenya eCitizen portal (Interpol, 2021). There has also been the rise of a serious danger of social media manipulation, especially through the political arena. In elections in Nigeria and Kenya, there have been cases when disinformation campaigns affected the mass audience, which was organized both by internal and external forces. Those trends demonstrate the overlapping of technological weaknesses and socio-economic urges fuelling Cybercrime in Africa. 2.4 Theoretical Frameworks for Understanding Cybercrime Various criminological theories aid in explaining the dynamics of Cybercrime in Africa. One of such theories is that of Routine Activity Theory: A motivated offender, a target, and the lack of a capable guardian come together, according to Cohen and Felson (1979). Applying to cybercrime, poor Cyber Security and low digital literacy will pose a risk to being victimized (Wang et al., 2021). As an example, the increase of phishing in Africa can also be explained by poor users’ awareness and institutional protection. According to the General Strain Theory (Agnew, 1992), persons might resort to committing a crime when they see economic deprivation and fewer opportunities for achieving legitimate goals. The youth unemployment has been considered to have a relation with Cybercrime in Africa, specifically in Nigeria, in what has become known as the Yahoo Boys and involves under-employed youths committing cybercrimes as a means of survival (Chawki et al., 2015). Cybercrime may also be applied to the Technology Acceptance Model (TAM) (Davis, 1989), initially formulated to describe the adoption of new technologies by its users. Hackers use vulnerabilities in the usability of the systems, such as weak policies on password strength, to execute attacks. Nevertheless, Africa’s research in cybercrime has been mainly based on the Western theoretical frameworks with limited local modification (Bada and Von Solms, 2019). In future studies, researchers ought to generate specific frameworks taking into consideration the reality of Africa as a special socio technical environment. 2.5 Legal and Policy Landscape on Cybercrime in Africa Concerted challenges, such as poor cross-border co-operation and legally ineffective frameworks, are hampering efforts to curb cybercrimes in African countries. Although there have been enactments of some laws on cybercrimes in some countries, including the Cybercrimes Act (2015) in Nigeria and the Cybercrimes Act (2020) in South Africa, it is unevenly applied. The laws remain archaic in many countries without sufficient provisions to deal with the prevailing cyber threats. This is because, even though the African Union Malabo Convention (2014) aimed to standardise Cyber Security legislation on the continent, it has not come into effect yet in many countries, though it is effective in 15 of them as of 2023 (African Union, 2023). The inability to ascertain the technical and financial capacity to undertake measures towards Cyber Security is a major setback, especially in small economies. Internationally, the Budapest Convention (2001) provides international standards regarding the laws on cybercrimes, yet most countries in Africa do not comply with this convention due to issues with sovereignty (Radebe et al., 2024). Comparative evaluation shows that the legal systems of Africa are outdated in comparison with the rest of the world, especially in investigating the case of digital evidence and cooperation with other countries. To enhance the regional policies, it is essential to match the international best practices with realities in a particular region. 2.6 Research Gap in African Cybercrime Studies Even though cybercrime has become an increasingly imminent risk, Africa has been faced with a deficiency of empirical studies as well as theoretical contextualization. The current body of research draws mostly on anecdotal rather than on systematic data collection. Also, there is a failure on the part of African leaders to have evidence-based policy on cyber security, as this tends to be reactive and thus ineffective. Even policymakers have to adopt foreign studies without the localized studies, resulting in models that may not suit the socio technical circumstances in the region (Kshetri, 2019). It is suggested that further studies should focus on local empirical studies and context-based theoretical formulations to come up with contextualized solutions to cyber security. III. RESEARCH METHODOLOGY The study employs a mixed methods design to assess the legislation and enforcement of cybercrime in the sub-Saharan region, utilising both qualitative and quantitative procedures to gain a comprehensive understanding of the problem (Creswell and Creswell, 2018). 3.1 Philosophy of the study and approach This study is based on an interpretive paradigm that recognises the subjective character of the social phenomena and the critical role of context in human experiences (Saunders et al., 2019). The paradigm can be effectively applied when analysing cybercrime law, as it provides a detailed account of stakeholders’ viewpoints, legal interpretations, and enforcement issues (Bryman, 2016). IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -263 A pragmatic approach is also included, which makes the research problem-focused and solution-oriented, situated between theoretical knowledge and practical policy execution (Morgan, 2014). The adopted mixed-methods approach leverages the advantages of both qualitative and quantitative studies (Creswell, 2014). The qualitative tools, namely interviews and policy analysis, provide informative and situational data on the legal and operational issues of cybercrime enforcement (Yin, 2018).Quantitative approaches and tools, such as surveys and statistical analysis, contributed to the identification of general trends and patterns of cybercrime victimization and general awareness (Field, 2018). The twofold strategy enhances the validity and reliability of the research results through methodological triangulation (Denzin, 2017). 3.2 Research Design This study employs a multi-case research design, in which specific countries in sub-Saharan Africa are selected for a comparative analysis (Yin, 2018). The research combines three major methodological elements: research and analysis of laws and regulatory frameworks on cybercrime (Bowen, 2009); ethnography of digital methods, including observation of trends in cybercrime (Pink et al., 2016); and a survey approach using structured online questionnaires concerning ICT users (Fowler, 2013). The multi-faceted design of the study considered the case of cybercrime holistically, through the evaluation of macro-level policy and the assessment of micro-level user experiences (Patton, 2015). 3.3 Collection of Data The primary data collection involves two approaches, namely semi-structured interviews of Cyber Security experts, law enforcers in charge of cybercrime, legal professionals, and victims of cybercrime, and online surveys of ICT and financial service consumers placed in a set of countries. The surveys employ the stratified sampling method, which aims to capture individuals with diverse demographic characteristics. In addition, various sources were utilized to gather secondary data, including Cybercrime Reports published by Interpol, ECOWAS, and national Computer Emergency Response Teams (CERTs). These reports provide statistical data on trends in cybercrime (Interpol, 2021). Legal Documents - Court decisions, laws, and policy statements were used to determine the legality of the process used in cybercrime. Archives and scholarly articles provide historical context and comparative applications to complement primary data. 3.4 Data Analysis The data gathered is assessed using a combination of qualitative and quantitative methods. To recognise similarities between the interview transcripts and policy documents and extract themes, they were coded using NVivo software, and inductive coding was employed, allowing themes to emerge naturally rather than being imposed. Tools of statistics measure the responses of surveys to interpret the frequency, correlation, and other patterns involved in cybercrime victimisation (Field, 2018). Regression analysis was used to evaluate the interrelationship between variables (Tabachnick and Fidell, 2019). The methods of cross-case comparison distinguish common problems and regional variations in the matters of cybercrime law (Miles et al., 2014). 3.5 Ethics The importance of ethical compliance in the research process was advocated. Informed consent was obtained from all participants after they had been provided with clear information about the study’s purpose and their rights (Wiles et al., 2012). All data was scrubbed of personal identifiers to safeguard personal confidentiality, and magnetic data was stored securely following the GDPR specifications (GDPR, 2018). Institutional boards ethically evaluated the appropriateness of the study protocol in terms of research integrity. 3.6 Conclusion The chapter has elaborated on the methodological perspective of the study, which is based on mixed methods with a greater focus on qualitative aspects to present depth and a quantitative scale to show breadth (Creswell and Creswell, 2018). The incorporation of policy analysis, digital ethnography, surveys, and cross-case a comparison ensures that the research on cybercrime legislation in sub-Saharan Africa is conducted robustly (Yin, 2018). Meanwhile, ethical concerns ensure that the safety and rights of participants are safeguarded during the research. The following sections present the resultant findings of this methodological process. IV. ANALYSIS OF ICT-ENABLED CRIMES IN SUB-SAHARAN AFRICA This section gives a multifaceted synthesis of essential findings of the study. It also discusses the efficacy of the regulatory framework, infrastructural shortages, and the magnitude of horizontality or verticality when it comes to addressing cyber threats. These insights form the basis of having governance priorities and developing a region-specific cyber security framework that is sensitive to the issues of the region. 4.1 Patterns and Trends of Criminal Use of ICT The survey results indicate that 108 respondents expressed that ICT crimes happened frequently, 96 occasionally, and 82 very frequently, meaning cyber threats are a very present problem in the area. When it comes to tools employed by criminals, the most frequently mentioned ones were phishing emails (87 responses) and hacking tools (86), fake websites (78), and social media impersonation (71), which implies a combination of more technical and deception-related approaches. Regarding the primary targets, small businesses (84) and educational institutions (84) were the most common ones, and the general public (73), government institutions (72), and financial institutions (72) were also amongst the most targeted ones. These trends indicate the necessity to introduce multi-sector cyber security policies and nationwide digital literacy campaigns to reduce increased threats. Results from interview data demonstrate that financially motivated cyber crimes were reported most as ICT-enabled crimes without exception in Sub-Saharan Africa. The representatives of the companies repeatedly specified mobile money fraud, phishing attacks, SIM swap fraud, and business email compromise (BEC) to prevail, since the region is gradually transitioning towards the use of digital banking and financial services. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -264 Such crimes are usually enabled by malware, fraudulent investment sites, and crypto fraud to attack an individual user as well as institutional systems. Coupled with monetary exploitation, there is anxiousness towards socially and politically manipulative cyber attacks, including social media impersonation, relationship fraud, online blackmail, and misinformation. Table 1: Patterns and Trends of Criminal Use of ICT Theme Key Insights Across Participants (P001 – P010) 1. Financially Motivated Cybercrimes  Mobile money fraud , phishing , business email compromise (BEC) , and SIM swap fraud were reported in nearly every country (P001, P002, P003, P004, P005, P006, P007, P010).  Use of fake e-commerce websites, card-not-present fraud, and fake investment/crypto platforms also emerged as key trends.  Rise in ransom ware attacks targeting both private companies and critical infrastructure (P001, P002, P005, and P010). 2. Social and Politically Manipulative ICT Crimes  Common reports of online impersonation, social media scams, and romance scams (P002, P003, P004, P006, P010).  Increasing cases of cyber defamation, blackmail, and social media blackmail (P004, P007, P008).  Political disinformation and deep fake content used for destabilization or influence during elections (P003, P009).  Website defacement and cyber stalking also noted (P007, P009). Specifically, another risk factor is the increasing use of ICTs with deep faking, cyber defamation, and politically fraught messages during campaigns, which is an aspect of exploiting the power of ICTs to bias the views and reputation or social damage of other persons. 4.2 Socio-Economic and Infrastructural Factors The statistics point to robust socio-economic and infrastructural issues associated with ICT crime in Sub-Saharan Africa. For instance, 247 people (127 Agree, 120 strongly Agree) agree that youth unemployment is a factor that leads to cybercrime, which testifies to long-term social insecurities. On the same note, 272 respondents agreed that the risk of cybercrime would be enhanced by the absence of digital literacy, which was an indicator that educational programs are urgently required. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -265 Upon enquiry about the worst underdeveloped areas, at the lead were cyber security awareness (81) and regulatory capacity (80), indicating gross inadequacy, followed by ICT infrastructure (75) and fintech regulation (75).With regard to regulatory environment, 170 of the respondents rated the existing structures ineffective or very ineffective, whereas only 135 believed them effectual or very effectual. Hence, there is a common ground to be upset with a current state and an urgent need to change a structure. Table 2: Socio-Economic and Infrastructural Factors Theme Key Insights Across Participants (P001 – P010) 1. Youth Unemployment and Economic Marginalization  All participants (P001 – P010) identified youth unemployment as a core driver. Digitally skilled but economically marginalized youth turn to cybercrime as a survival or enrichment strategy.  Economic frustration, poverty, and lack of alternative income sources are linked to criminal online activity (P002, P005, P006, P009). 2. Digital Illiteracy and Weak Cyber Security Ecosystems  A lack of digital awareness among general users primarily rural populations and older citizens was highlighted by most participants (P001, P003, P004, P006, P007, P008).  Weak regulatory frameworks, outdated laws, and limited institutional capacity hinder cybercrime prevention (P001, P005, and P009).  Rapid digitalization without proportionate cyber security investment was frequently cited (P003, P004, P006). Interview data highlights that there were two main drivers, youth unemployment and poor digital governance. Most respondents inferred massive unemployment among the youth as the primary trigger of the increasing cases of digital crime, where most technologically savvy yet jobless youths turned out to consider digital crime as an avenue to earn a living. Meanwhile, the already quick digitalization process in the region has outstripped both users and their state of being prepared and cyber security. Gap in digital literacy, especially among rural and aging groups, coupled with the low level of enforcement mechanisms, the outdated laws of cyberspace, and the lack of inter-agency coordination, has exposed both a person and an institution to attack. This socio-economic pressure, in combination with the infrastructural lapse, has brought up a climate where ICT-enabled crime can revive with little to no deterrence. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -266 4.3 Case Study Insights Figure 8reports the finding that 137 respondents said they were not sure about unique cybercrime patterns in their countries and this indicates the possibility of little local mappings of data or understanding. There is a relatively equal proportion of those who said Yes (125) and No (123), indicating uncertainty or non-clarity of whether there is a significant difference in national patterns. Figure 9 (overall 167 respondents: 85 Agree and 82 Strongly Agree) confirmed that all countries in Sub-Saharan Africa encounter similar challenges of cybercrime, and this area presents the possibility to develop regional co-operation among countries. However, there is a significant opposition of 79 respondents, who strongly disagree. This is an indication of the different experiences or perceptions of the respondents, something that may not go well with collaborative attempts in policies. As a final point, the results affirm the necessity and difficulty of unified cyber security operations in Sub-Saharan Africa. Although a considerable number of respondents also recognize generic challenges in the region, the high levels of uncertainty and inconsistency regarding local trends indicate a lack of situational sensibility and evidence-based analysis. This shows that before regional co-operation can be effective, there is a need to first invest in regional race to gain maturity in local cyber security intelligence, capacity build-up in cyber security, and local awareness to facilitate perception bridging and forge a united and informed front on the policy. V. LEGAL AND POLICY ANALYSIS 5.1 Evaluation of National Cybercrime Laws The threat of cybercrime has been recognized by the governments of Sub-Saharan African (SSA) countries in recent years, and they have already responded to this threat by taking measures to establish legal grounds to fight it. Even though there is legislation in most countries dealing with numerous cybercrimes, the quality, uniformity, and enforceability of such laws differ significantly. This produces a stitching together of legal tools that usually lack the sophistication required under the contemporary cyber threat environment. Certain nations have also done a good job in the legislation of crimes involving electronic crimes, identity theft, unauthorized access and data breach. Nevertheless, such laws are often too old and do not cover emerging forms of technology like malicious use of artificial intelligence (AI). Through the interview with experts, it has been identified that in all the countries, the presence of cybercrime laws is established (e.g. in Nigeria in 2015 , in Kenya in 2018, in Ghana in 2020), but due to the absence of the training of judges, inefficiencies of the procedure, and poor technical knowledge, implementation and enforcement are severely limited. Laws that have been rendered outdated or uncouth also paralyze prosecutorial effectiveness in certain states. There is an immense disjunction between law and working capability. Table 3: Legal Framework Country Legal Framework Key Weaknesses Noted Kenya Computer Misuse and Cybercrimes Act (2018) Poor enforcement; weak digital evidence handling Nigeria Cybercrime Act (2015) Silos among agencies; weak judicial capacity Ghana Cyber Security Act (2020) Poor public awareness; lack of tech skills in judiciary Ethiopia Computer Crime Proclamation . No. 958/2016 Vague definitions; slow enforcement Senegal Cybercrime Law and Data Protection , 2008 - 11 . No coverage for new threats like crypto fraud South Africa Cybercrimes Act (2021) Jurisdictional overlaps; interpretation inconsistencies Rwanda Cyber Security Law . No. 60/2018 Low rural enforcement; coordination challenges Pantserev (2022) explains that although AI systems are being built to support development in the region, they are also used to conduct disinformation campaigns, automated fraud, and psychological manipulation, which national legislations pay little attention to. In addition, in a case where sufficient laws are enacted, implementation is still a problematic issue. The understanding of cybercrime laws and ability of the judges to interpret and enforce the laws is usually impoverished. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -267 According to Abubakari (2021) and Malawi, Kumwenda et al. (2024), the widespread issues that have affected Anglophone West Africa are corruption, political manipulation, and poor execution of policies. The lack of ICT equipment distributed by the government (and thus available to the officers) often makes them uses personal handheld devices. This is not only a functional constraint of investigative abilities, but it is equally a thing that interferes with the professionalism and confidentiality of investigating sensitive cases involving crimes conducted via a computer. Nationalistic legislations against cybercrime are set to remain largely cosmetic, without regular training programmes and investment in digital infrastructure. 5.2 International and Regional Co-operation Regional and international collaborations and measures in regard to Cyber Security have been established, but with patchy and, in most cases, symbolic growth. The African Union (AU) Malabo Convention, which was enacted in 2014, offers a detailed guideline in the field of Cyber Security, cybercrime law, and data protection. The strategies of most countries, as the Malabo Convention, ECOWAS, Interpol, and the African Union Cyber Security strategies, are beneficial. As revealed in the interview findings, there is a system in co-operation, little to no sharing of intelligence, slow exchanges of data and poor harmonization of national and regional legislations. Countries are still relatively minimal in terms of real-time cooperation, even when they have been involved in the forums. Table 4: Common Challenges Regional Body Level of Support Observed Common Challenges Identified African Union Provided frameworks like the Malabo Convention Weak national alignment; non - ratification (e.g., Nigeria) Interpol Cross - border case support, training Limited real - time coordination, slow data exchange ECOWAS/EACO Promoting legal harmonization and forums No operational joint task forces or alert systems Country Engagement All countries participate at some level Imple mentation and institutionalization remain weak Nevertheless, as demonstrated by Pantserev (2022), the convention has not been ratified in many AU member states, and thus it is underutilized and without much influence. On the same note, regional economic blocs such as ECOWAS, Southern African Development Community (SADC) and East African Community (EAC) have come up with model laws and strategies to harmonize Cyber Security practices. These are the ECOWAS Directive on Combating Cybercrime and the SADC Model Law on Computer Crime and Cybercrime. Although these efforts are reasonable, inequality in the national priorities and resources is a barrier to their practical implications. According to Abubakari (2021), the existence of incoherence between national and regional regulations forms gaps that cybercriminals can use. Also, law enforcement interagency co-operation is often undone by the absence of trust, technological know-how, and the ability to talk to each other at the digital level. The co-operation with global organizations such as Interpol has not been very successful. Interpol has enabled combined efforts, capacity-building efforts, and development of tools to report cases of cybercrime. 5.3 Institutional Capacity and Challenges Proper execution and using cybercrime policies and laws rely strongly on the institutional capability of the involved authorities. The sad thing is that most of the countries of SSA are really struggling in this aspect. Where they exist, National Computer Emergency Response Teams (CERTs) are frequently underfunded, understaffed, and ill-equipped with the infrastructure to react in real time to cyber incidents. The participants reported significant gaps in the national CERTs and law enforcement agencies. Cybercrime prevention and prosecution are hindered by lack of trained staff, inadequate funding, antiquated or non-existent digital forensics labs and low awareness in rural areas. It is not harmonized among the agencies that work inefficiently, and mistrust and confidentiality make the involvement of the private sector weak. Table 5: Common Issues Raised Challenge Area Common Issues Raised Countries Affected Staffing and Training CERTs and police are under - trained and overworked All 10 participants (esp. Nigeria, Kenya) Forensics and Tools Lack of modern labs/tools; poor chain of custody Ghana, Ethiopia, Senegal, Nigeria Inter - agency Silos Overlaps, rivalry, poor communication South Africa, Nigeria, Rwanda Reporting and Awareness Victims do not trust the system or lack awareness Senegal, Kenya, Ethiopia, Rwanda The same case applies to law enforcement agencies. In 2024, it was discovered that police departments in Malawi, especially those in rural locations, such as Muloza, function without the basic resources in ICT (Kumwenda et al., 2024). Police officers have to utilize their cellphones to collect information and pursue cyber crimes. Not only does this undermine the integrity of investigations, but it shows that there is an impending need to invest systematically in cyber security resources and training. Another important problem is the absence of specialised training. According to Pantserev (2022), the ever-accelerating rate of threats in the sphere of cyber security demands continuous learning and upskilling, and this rarely appears in the priorities of the national budget. Lack of coordination of various national agencies is also compromised by budgetary limitations and loose governance systems. Absence of inter-agency co-operation and division of tasks leads to ineffective efforts aimed at addressing the issue of cybercrime; they will be scattered and chaotic. IRJCS: International Research Journal of Computer Science ISSN: 2393-9842 Volume 12, Issue 07, September 2025 https://www.irjcs.com/archives _________________________________________________________________________________________ IRJCS: ©2014-25, AM Publications, India - All Rights Reserved https://doi.org/10.26562/irjcs Page -268 VI. TOWARDS A FRAMEWORK FOR CYBER SECURITY AND PRIVACY GOVERNANCE 6.1 Proposed Model: Multi-Layered Policy-Technology Framework To address the pressing cyber security challenges in SSA, a multi-layered framework combining legal, technological, and social interventions is essential (Egho-Promise et al, 2024). This approach must be grounded in local realities while being responsive to global cyber trends. Community Awareness: Raising awareness among citizens is crucial in reducing the human vulnerabilities exploited by cybercriminals. Kumwenda et al. (2024) found that many people are already using mobile phones for crime reporting and community safety, but lack guidance on how to identify and report digital threats. Public education campaigns can empower individuals to use technology safely and report suspicious activity. Legal Reform: Outdated and inconsistent legal frameworks must be revised and harmonised. As Abubakari (2021) argues, effective cybercrime legislation requires not only technical accuracy but also political independence. Legal reform should be guided by regional frameworks like the Malabo Convention and supported by international best practices. Tech Innovation: SSA countries must also invest in local technological innovation. Roger et al. (2022) and Wang et al. (2023) both highlight the role of ICT in improving agricultural productivity, governance, and economic resilience. Home-grown technologies can be tailored to local needs and offer scalable solutions for both development and security. International Partnerships: Collaboration with global institutions such as the World Bank and Interpol can provide much-needed technical expertise, funding, and policy guidance. Salimi (2025) notes that during the COVID-19 pandemic, the World Bank shifted its education strategy in SSA to include multimodal ICT solutions, a model that could be replicated in the cyber security sector. 6.2 Stakeholder Engagement Appropriate governance of Cyber Security includes the assistance of various stakeholders. Digital threats are complex and dynamic, and require more than governments to solve them. Public-Private Co-operation Companies in the telecom sector, banks and information technology companies can work closely with the government, and this will result in more secure systems in place. Kumwenda et al. (2024) reveal that in Malawi, citizens frequently use telecoms to report their crimes. Rationalising these types of other-than-formalised co-operation is possible to improve responsiveness and efficiency. Universities, Telecoms, and NGOs also have a role to play. Universities can play a key role in training digital skills and in policy research, as well as through partnerships with NGOs. NGOs may also contribute as a useful community outreach and digital literacy campaign agent. As stated by Mapiye et al. (2023) and Cordes and Marinova (2023), the culture of inclusive ICT access, especially in agriculture and e-commerce, would call in a web of informed and motivated players that operate across fields. 6.3 Technology as Enabler and Protector Technology should not only be considered an essential developmental tool but also as a way of protecting against cyber threats. New technologies have a great promise of enhancing security, transparency, and privacy. Such technologies include Artificial Intelligence, Blockchain, and Digital Forensics. Artificial intelligence tools are already implemented in the sphere of education and crime investigation. Salimi (2025) describes the possibility of AI and blockchain to guarantee equal access to digital education, whereas Kumwenda et al. (2024) talk about the opportunity of digital forensics to improve investigations of police work. Privacy-Preserving Tool and Mobile Security Apps also play a role. In SSA, mobile phones are the leading way of getting online, and, therefore, it is important to provide their security. Mobile applications that are secure can guard personal information, promote safe financial operations, and lead to service availability. Wang et al. (2023) and Botchie et al. (2022) stated that mobile technologies have already altered such sectors as agriculture and mobile finance, and now they have to defend them, too. Due to the digital journey of Sub-Saharan Africa, tremendous possibilities await the region, but it also puts it in grave Cyber Security danger. Existing law and the abilities in institutions are not entirely prepared to deal with the increasingly complex environment of threats. However, a multi-layered approach based on such aspects as legal reform, education of the population, innovative technology, and international cooperation has an opportunity to start the formation of a sustainable, inclusive, and secure digital landscape in SSA. Cyber Security cannot be considered a specialized problem anymore; it is a fundamental element of national progress, human security and integration of the continent. In the absence of it, the prospect of digital inclusion might not be achieved. VII. DISCUSSION 7.1 Interpreting Key Findings 7.1.1 Alignment with or Divergence from Global Cybercrime Patterns The findings of this study reveal that despite a series of similarities between Sub-Saharan Africa (SSA) and the rest of the world regarding cybercrime patterns, which include financial crime motives, phishing attacks, and ransom ware, there are significant discrepancies that relate to the context of the region. And that is, Its socio-economics, and infrastructure (Talesh, 2025). Similarly to international trends, the digital financial channels like mobile money are usually misused; however, only their introduction rate is by far higher in SSA because most of the population is under banked (Kitimbo, 2021). In this regard, the social engineering concept, such as romance fraud and social networking fraud, also matches trends spotted worldwide (Chaganti et al., 2021), but is more socially widespread because of the lack of control and digital visibility recognition. Moreover, as opposed to other more advanced areas, where cybercrime is, in the majority, transnational and highly organized, in SSA, they are much more often committed by persons lacking economic and political power or by loosely structured groups. This is based on the very correlation between the high youth unemployment rates and the issue of increasing cases of digital criminality, which was revealed in interviews and survey findings (Idris, and Maikomo, 2024). Ineffective enforcement, stale laws, and underfunded institutions are a strong indicator of a marked contrast between the regions that have more established Cyber Security landscapes (Testart Pacheco, 2016; Ali, 2024).