Back to all projects
POLITICAL SCIENCE

Cybercrime and National Security Challenges in Nigeria

Admin 0 views 0 downloadsBSc/BA

Notice: This is a sample project for study and reference. Submitting it as your own work violates most universities' academic integrity policies.

Abstract

About This Research Topic

For a long time, Nigeria's cybercrime story began and ended with 419 — the advance-fee email scams that gave the country an unwanted global reputation in the 1990s and 2000s. That story is badly out of date. Today's cybercrime landscape in Nigeria runs through ransomware attacks on government systems, business email compromise schemes that drain corporate accounts, phishing campaigns aimed at banks, cyber espionage, and even the digital financing of terrorism — and the Nigerian Communications Commission puts the annual cost to the economy at roughly ₦500 billion. A recent study went beyond the headline numbers to ask a harder question: is Nigeria's legal and institutional response actually built to handle any of this, a full decade after its founding cybercrime law was enacted? If you're working on a similar security studies or governance dissertation, it helps to first look through comparable social science research to see how a qualitative, document-based methodology like this one is typically structured. Here's what the analysis found.

Main Abstract

Cybercrime has become one of the more destabilising forces in modern national security thinking, cutting across borders and straining governance frameworks built for a different era of threats. This study examined the nature, scale, and national security implications of cybercrime in Nigeria, situating the analysis against broader African and global trends. Using a qualitative design built entirely on secondary sources — government policy documents, reports from the Nigerian Communications Commission and the Economic and Financial Crimes Commission, Interpol and UNODC publications, peer-reviewed literature, and institutional records — the study applied content, historical, and comparative analysis to its material. It found that Nigerian cybercrime today spans advance-fee fraud, identity theft, ransomware, cyber espionage, and social engineering aimed at both individuals and critical national infrastructure. Legislative frameworks have improved since the Cybercrimes (Prohibition, Prevention, etc.) Act came into force in 2015, but implementation remains weak — understaffed agencies, thin budgets, and a shortage of technically trained security personnel all show up clearly in the data. Reported cases rose from 1,016 in 2018 to 2,894 in 2023, with convictions growing more slowly and financial losses climbing from ₦210 billion to over ₦512 billion over the same period. Beyond the direct economic damage, the study found that cybercrime erodes public trust in digital systems, helps finance terrorism, and exposes sensitive government databases to compromise. It concludes that a genuinely effective national cybersecurity strategy needs legislative reform, stronger institutional capacity, better inter-agency coordination, deeper international cooperation, and sustained public awareness efforts — recommending an urgent review of the 2015 Act, increased funding for NITDA and related bodies, and the integration of cybersecurity education into university curricula.

Chapter One Preview

Background to the Study

The internet reshaped how people communicate, trade, govern, and even fight — mostly for the better, but it also opened an entirely new arena for crime and state-level conflict. Cybercrime, once a marginal technical nuisance in the 1990s, has grown into a central national security concern. National security itself has been redefined over the same period: where security studies once meant almost exclusively military threats and territorial integrity, scholars following Barry Buzan and the Copenhagen School's broader framework have long since folded in economic stability, public health, and information security as equally central concerns. Cybercrime fits squarely into that broader frame — not simply because it's illegal, but because it can destabilise financial systems, compromise critical infrastructure, undermine democratic processes, and hand real capability to both criminal networks and hostile states.

Nigeria's own cybercrime story has evolved dramatically since the 419 era, now encompassing ransomware, identity theft, business email compromise, phishing, cyber espionage, and terrorism financing — a shift that mirrors what INTERPOL's Africa Cyberthreat Assessment has documented across the wider continent, where two-thirds of surveyed member countries now report cyber-related crime as a medium-to-high share of all reported offences. Nigeria's own legislative response, the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, was a genuine milestone when enacted, criminalising a wide range of cyber offences and establishing institutional responsibility for prosecution. A decade on, this study set out to test how well that legislative and institutional framework has actually held up against a threat landscape that has kept moving.

Statement of the Problem

Nigeria still struggles to build and implement a coherent cybersecurity strategy, despite wide recognition of cybercrime as a genuine national security threat. The problem shows up at several levels at once. Legislatively, the 2015 Cybercrimes Act has been criticised for not covering newer threats like deepfake fraud, cryptocurrency scams, and state-sponsored cyber espionage — and its cyberstalking provision, Section 24, has drawn criticism from human rights organisations for being used to suppress online dissent rather than protect genuine victims of harassment. Institutionally, the agencies tasked with investigating and prosecuting cybercrime — the EFCC, the police cybercrime unit, and NITDA — operate on thin budgets, limited technical expertise, and weak coordination between one another, producing low conviction rates relative to the volume of reported cases. Structurally, the underlying drivers of cybercrime — youth unemployment, inequality, weak economic governance — get treated as background noise rather than as part of the security problem itself. And internationally, Nigeria has yet to ratify the African Union Convention on Cyber Security, limiting its ability to cooperate on the transnational cases that make up much of modern cybercrime. This study set out to analyse these interlocking gaps with the rigour the problem demands.

Objectives of the Study

The broad objective of this study is to examine cybercrime as a national security challenge in Nigeria. The specific objectives are to:

●      identify the major forms of cybercrime threatening national security in Nigeria

●      assess the institutional and policy responses of the Nigerian government to cybercrime

●      evaluate the effectiveness of the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 as amended

●      analyse the structural and governance conditions that sustain cybercriminal activity in Nigeria

●      examine Nigeria's engagement with regional and international cybersecurity frameworks

Research Questions

●      What are the dominant forms of cybercrime constituting national security threats in Nigeria?

●      How adequate are Nigeria's institutional and policy responses to the cybercrime challenge?

●      To what extent has the Cybercrimes Act 2015 effectively addressed cybercriminal activity in Nigeria?

●      What structural and governance factors sustain cybercrime as a persistent security challenge in Nigeria?

●      How does Nigeria's engagement with international cybersecurity frameworks compare with global best practices?

Significance of the Study

This study operates at three levels at once. At the policy level, it offers an evidence-based assessment of Nigeria's cybercrime legislative and institutional framework, generating concrete input for law reform, agency restructuring, and budget decisions — a useful corrective in a policy area too often driven by political considerations rather than evidence. At the academic level, it adds to a still-thin body of Nigerian and African scholarship on cybercrime and security governance, most of which currently borrows theoretical frameworks from the Global North that don't fully account for postcolonial African governance conditions; this study grounds the analysis specifically in Nigeria's political economy instead. At the societal level, it works to correct the tendency to trivialise cybercrime as individual greed or a minor nuisance, making the systemic and structural stakes clear to citizens, students, and civil society organisations. For students building a comparable qualitative security-studies dissertation, one-on-one research coaching can help sharpen the content-analysis methodology and secondary-source framework without doing the analytical work for you.

Scope of the Study

This study focuses primarily on cybercrime in Nigeria between 2015 and 2023 — a window bounded by the enactment of the Cybercrimes Act and the most recent available data — with historical references reaching further back where useful for context. It draws comparative insight from other African countries and selected global cases where the comparison sharpens understanding of the Nigerian situation, covering cybercrime in its various forms: financial fraud, cyber espionage, infrastructure attacks, and digital terrorism facilitation. It does not extend to personal data protection or digital rights issues beyond their direct bearing on national security.

Operational Definition of Terms

Cybercrime: any criminal activity in which a computer, network, or digital device is either the instrument, target, or venue of illegal conduct, including fraud, identity theft, hacking, ransomware, phishing, cyber espionage, and the digital facilitation of terrorism or organised crime.

National Security: a state's capacity to protect its sovereignty, territorial integrity, institutions, citizens, critical infrastructure, and economic wellbeing from threats — conventional or unconventional, internal or external, military or non-military — encompassing cyber dimensions of state vulnerability.

Cybersecurity: the practices, technologies, policies, and institutional frameworks designed to protect digital systems, networks, and data from unauthorised access, damage, or attack.

Critical Infrastructure: systems and assets, physical or virtual, so vital to a nation that their incapacitation would have a debilitating effect on security, economic stability, public health, or safety — in Nigeria, this includes the power grid, financial system, telecommunications infrastructure, and government data systems.

Governance: the processes, institutions, norms, and relationships through which public authority is exercised and public decisions are made — here specifically, the capacity, accountability, and legitimacy of Nigerian state institutions in addressing the cybercrime challenge.

Cyber Espionage: the use of digital means to obtain classified, sensitive, or proprietary information from governments, corporations, or individuals without authorisation, typically for political, military, or economic advantage.

Conclusion

The pattern this study surfaces is one of a legal and institutional response perpetually a step behind the threat it's meant to manage. Reported cases and financial losses have climbed steadily since 2015, convictions have grown more slowly, and the 2015 Act itself, whatever its founding value, was never built to cover deepfake fraud or cryptocurrency scams that barely existed at the time it was drafted. None of the fixes this study points to are exotic: a genuine legislative update, properly funded and staffed agencies, real coordination between them, deeper international cooperation, and cybersecurity education that reaches beyond IT departments into the wider public. What makes the problem hard isn't a lack of known solutions — it's the same governance constraints, funding gaps, and institutional fragmentation that show up across most of Nigeria's public-sector challenges, just with a cyber label attached. Anyone building a similar qualitative, document-based security studies dissertation will find it useful to look at a few worked content-analysis frameworks before structuring their own.

Frequently Asked Questions

1. How much does cybercrime actually cost Nigeria?

The Nigerian Communications Commission estimates the annual cost at roughly ₦500 billion, with this study's own data showing reported financial losses climbing from ₦210 billion in 2018 to over ₦512 billion in 2023.

2. What are the main types of cybercrime affecting Nigeria's national security?

The study identifies advance-fee fraud, identity theft, ransomware, cyber espionage, and social engineering as the dominant forms, targeting both individuals and critical national infrastructure.

3. Has Nigeria's 2015 Cybercrimes Act actually worked?

Partially — the Act was a genuine legislative milestone, but this study found implementation remains weak due to understaffed agencies, inadequate budgets, and a shortage of technically trained personnel, and the Act itself doesn't adequately cover newer threats like deepfake fraud and cryptocurrency scams.

4. Why are cybercrime conviction rates so low in Nigeria relative to reported cases?

The study points to understaffed and underfunded agencies — the EFCC, the police cybercrime unit, and NITDA — along with limited technical expertise and poor inter-agency coordination, which together produce a large and growing gap between cases reported and convictions secured.

5. Has Nigeria ratified the African Union's cybersecurity convention?

No — the study notes Nigeria has not ratified the African Union Convention on Cyber Security (the Malabo Convention), which limits its capacity to cooperate internationally on cybercrime that routinely crosses borders.

6. What structural factors make cybercrime persist in Nigeria?

The study points to youth unemployment, inequality, weak economic governance, and endemic corruption as key enabling conditions, combined with a youthful, digitally literate population facing limited economic opportunity.

7. Does cybercrime in Nigeria connect to terrorism financing?

Yes — the study found that cybercrime undermines national security not only through direct economic losses but also by enabling terrorism financing and exposing sensitive government databases to compromise.

8. Is Section 24 of the Cybercrimes Act controversial?

Yes — the study notes that Section 24, which addresses cyberstalking, has been criticised by human rights organisations for being used to suppress online dissent rather than to protect genuine victims of harassment.

9. How big is the cybercrime problem globally, compared to Nigeria's numbers?

Globally, Cybersecurity Ventures projected cybercrime costs would exceed USD 8 trillion in 2023, rising toward USD 10.5 trillion by 2025 — a scale that dwarfs Nigeria's roughly ₦500 billion annual estimate but underscores that Nigeria's challenge is part of a much larger global pattern.

10. Where can I see how a qualitative security-studies dissertation like this is structured?

You can review comparable qualitative, document-based governance and security studies in the sample research library for reference on structuring objectives, secondary-source methodology, and content analysis.

Purchase to unlock the full material.