Through the looking glass with Bright Emmanuel Segbefia: Cybersecurity disclosure and corporate accountability in this digital era
Through the looking glass with Bright Emmanuel Segbefia: Cybersecurity disclosure and corporate accountability in this digital era
Imagine a vast, fertile ecosystem-rich with food, water and opportunity, in this environment, corporations are like grazing herds thriving in abundance. Growth is rapid and the landscape appears secure. But beneath this prosperity lies a persistent threat, lurking at the edges and sometimes already within, akin to wolves, lions and hyenas. These predators represent digital threats: malware, ransomware attacks, phishing schemes, data breaches and increasingly sophisticated artificial intelligence-driven intrusions. In the digital economy, growth and vulnerability now move together.
Long before this digital ecosystem took shape, the idea of such threats existed only as theory. In the 1940s, mathematician John Von Neumann conceived the possibility of self-replicating programs. Programs that can spread, adapt and embed. At the time computers were remote and the risk remained conceptual.
By the 1970s, early network experiments showed that code could travel from one machine to another. At this time, users of computers were increasingly unbothered. Over the past two decades, businesses have shifted key operations onto digital platforms. It is like moving from narrow village paths to a high-speed highway system. In this space, progress and risk travel side by side, much like parallel lines moving in the same direction.
Let’s examine how organizations must navigate the growing complexity of cyber risk by strengthening cybersecurity disclosure, governance, and risk management practices in an increasingly digital and AI-driven economy.
1. Nature of attacks
Cyberattacks may appear unpredictable, but in reality they often follow a structured, multi-stage process. It may be noted that this writer refers to this sequence as the S.E.A model- Surveillance, Exploitation and Access.
Typically, attackers begin with surveillance, gathering information about their target systems and identifying potential weaknesses.
This is followed by exploitation, often described as the “testing the locks’’ stage where attackers repeatedly test vulnerabilities until they find a point of entry. This may involve phishing attempts, malware deployment, exploiting outdated company software, password attacks and use of stolen credentials.
Finally, attackers move to access and persistence, gaining control over the system and maintaining their presence for continued use or further attacks. They may install backdoors, steal sensitive information, encrypt files for ransom and monitor activity.
Digital attacks come in different forms, such as Denial of Service (DoS) Attack where a system or network is subjected to an abnormal volume of traffic, impairing the ability to respond to legitimate users. DoS attacks have emerged as prominent threats across African economies, particularly targeting financial institutions, telecom providers and technological firms. Recent data indicates that countries such as South Africa, Kenya and Morocco have experienced significant volumes of DDoS attacks, disrupting critical services and exposing weaknesses in infrastructure resilience.
In 2025, NETSCOUT’s Global Threat Intelligence Report identified South Africa as the most targeted country in Africa for DDoS attacks recording over 200,000 incidents within six months, largely concentrated in the commercial banking and telecommunications sectors. These incidents underscore that cyber risk is not confined to data breaches alone but extends to operational disruption, with profound implications for corporate governance and disclosure obligations.
In Ghana, the stakes of such operational disruptions are legally amplified for 13 industries designated Critical Information Infrastructure (CII) sectors in the Cybersecurity Act 2020, Act 1038. For these industries ranging from Energy to Banking- a digital attack is deemed as a threat to national security. The law recognizes these systems as ‘too vital to fail’.
2. Corporate governance and duty to shareholders
When a cyber breach occurs, accountability does not end at the IT department-it lands squarely in the boardroom. Companies owe fiduciary duties to shareholders to maintain transparency regarding cybersecurity challenges and incidents. This transparency enables investors to make informed decisions and aligns with broader principles of corporate social responsibility (CSR), especially when foreign investments or partnerships raise concerns about data security.
Ghanaian listed companies must disclose material risks under existing public company guidelines. Under Ghanaian law—particularly the Data Protection Act, 2012 (Act 843) and the Cybersecurity Act, 2020 (Act 1038)—companies remain subject to obligations. These laws require organisations to implement adequate safeguards, report data breaches (often within 72 hours to the Cyber Security Authority or Data Protection Commission), and protect customer data.
SEC Ghana emphasizes transparency to support informed investor decisions, while sector-specific regulations—such as Bank of Ghana directives for financial institutions—require risk assessments, incident reporting, and board-level oversight of cyber risks. This is important because the CISD elevates cybersecurity from an internal IT matter to a core governance and fiduciary responsibility particularly for RFIs.
3. Risk disclosure – What companies must address
Publicly listed companies are expected to provide investors with a clear and comprehensive picture of their cybersecurity exposure. Effective disclosure of digital risk centers on a few key considerations. These include the occurrence, probability, and frequency of incidents, which together indicate a company’s level of exposure and vulnerability. Equally important is whether the corporation has adequate preventive measures in place to address these risks, taking into account both their effectiveness and limitations.
The nature of the business itself also plays a critical role, as certain operations and dependencies may heighten risk exposure. Alongside this are the costs of maintaining protections, including insurance coverage, which must be balanced against the potential harm of a breach—such as operational disruption and reputational damage.
Finally, companies must consider the legal and regulatory consequences of incidents, including litigation, compensation claims, regulatory investigations, and possible sanctions. Together, these elements provide a concise yet comprehensive view of corporate risk and responsibility. For CII sectors under Act 1038, they require Rapid Incident Reporting within 24 hours once a breach occurs. For example, RFIs under the BoG are required to report significant cyber incidents within 24 hours of discovery. The directive of the BoG also requires comprehensive post incident reporting.
Disclosure serves as both a regulatory safety rule and a business necessity. For enterprises that are yet to commence operations, this accountability begins with robust Know Your Customer and Due diligence procedures. These processes often require companies to describe unusual or infrequent events, significant economic changes, or material cybersecurity matters and the effectiveness of their planned controls and risk management frameworks.
4. Deepfakes/Synthetic media
So imagine this scenario. A finance employee receives a routine video call from a senior executive to approve an important transaction. Nothing unusual. Just another day of urgent business. The faces on screen are familiar. The voices match. The authority in the room feels real. Everything aligns the way it always has—the urgency, the tone, the confidence in instruction. So the approval follows. As it always does when trust meets routine. Only moments later, reality fractures.
None of those executives were ever on that call. Not one. Every expression, every gesture, every carefully timed word had been synthetically generated—engineered to sit perfectly inside the employee’s sense of normality. The system didn’t break in. It didn’t force its way through firewalls or bypass encryption. It walked straight through the front door wearing a face everyone recognised.
By the time the illusion collapses, millions have already been moved. And then comes the uncomfortable truth: this was not theft in the traditional sense. It was permission—given under false reality. This time, the “devil” did not need to force his way in. He was invited. This is not fiction. It happened to a UK engineering firm, Arup, last year—where deepfake identities were used to manipulate an employee into authorising a multimillion-dollar transfer. And the most unsettling part is this: nothing about the system failed. Everything worked exactly as designed.
By now, most people have come across fabricated videos so strikingly realistic that they appear almost incontrovertible. These fabrications are typically powered by advances in machine learning techniques such as generative adversarial networks (GANs). Deepfakes achieve remarkable accuracy, convincingly depicting individuals doing or saying things that never actually occurred. Increasingly, there is even market value attached to such falsified content on social media platforms. This development introduces an entirely new and immeasurable category of risk, extending into the realm of reputational manipulation.
According to Smile Identity, a Lagos-based identity verification company, there has been a record of over 160,000 verification attacks across Africa’s Fintech ecosystem. These attacks are now largely concentrated on login processes, account recovery mechanisms, and other verification flows. There is little doubt that generative AI has significantly reduced the cost and increased the scale of identity fraud across the continent. In 2025 alone, reports indicate that a staggering 69percent of biometric fraud cases were linked to AI-enabled manipulation.
A security report by Microsoft further highlights that Africa is increasingly becoming a proving ground for AI-driven cyberattack techniques, particularly those involving voice cloning and video impersonation. This trend is especially concerning for corporations, as such breaches can be exploited to facilitate unauthorised transactions and compromise internal controls.
This type of digital vulnerability could happen to CII sectors like Energy, Water or Telecoms. A deepfake call to a plant manager could authorise a ‘routine’ system override that results in city-wide blackout or contaminated supply. In these sectors, the transition to proactive cyber security models- is not just a recommendation it is a regulatory imperative to prevent ‘permission-given’ national catastrophes.
Addressing this evolving threat requires deliberate countermeasures. First, organisations must implement lifecycle intelligence systems capable of detecting identity reuse across sessions and platforms. In practical terms this means identifying situations where the same face, device fingerprint, IP address or behavioural pattern is repeatedly used across multiple platforms or transactions in ways that suggest fraud.
Second, authentication processes should be strengthened at high-risk points, including login, deposit, and withdrawal stages. This may include multi-factor authentication, biometric verification, one-time passcodes, device recognition tools, transaction limits and mandatory second-level approvals. Third, Trusted Capture Systems (TCS) are essential to validate how identity evidence is created and submitted. TCS are basically systems that ensure that the identity data a user may submit is created by them in real time using verified devices and not copied, edited or artificially generated.
Ultimately, organisations must transition toward proactive cybersecurity models. These frameworks go beyond mere disclosure and risk management. They should incorporate AI-driven threat detection and continuous employee awareness. Organisations now employ systems like Darktrace, which uses “Digital Immune System” to learn the unique “pattern of life” for every executive and device. When a deepfake login occurs, the AI identifies it not by a broken password, but by subtle, “unnatural” anomalies in the connection behaviour.
Similarly, a company like CrowdStrike’s Charlotte AI now allows security teams to hunt threats in real time, instantly identifying which departments are vulnerable to voice cloning exploits before the “devil” knocks. For businesses that cannot build full cybersecurity in-house teams, partnership with Managed Security Service Providers are increasingly essential. For fintechs and companies who particularly deal with payment systems, strategic partnerships with reputable Managed Security Service Providers (MSSPs) have become a necessary pathway to digital resilience.
5. Risks and accountability
A strategic approach to combating cybercrime should feature targeted interventions that address specific needs and priorities, such as protecting critical information infrastructure (CII), enhancing incident reporting, and deterring threats through enforcement. Policymakers and organizations must identify gaps in current plans—such as skills shortages, limited forensic capabilities, or weak coordination—and adopt established good practices. hese may include implementing multi-factor authentication, establishing incident response teams and investing in employee phishing awareness training.
Good practices as provided by the BoG’s directive also include User Access Reviews at least twice a year for critical systems. Banks and Fintechs according to the CISD require post-incident reporting like root cause analysis and impact analysis (including financial, operational and reputational). Ghana’s National Cybersecurity Policy and Strategy (NCPS), launched in 2024, provides a roadmap structured around five pillars: Legal Measures, Technical Measures, Organisational Measures, Capacity Building, and Cooperation.
Cybercrime prevention and response should be integrated into corporate social responsibility (CSR) as a practical checklist. Treating cybersecurity as a Corporate Responsibility encourages corporations to adopt practical safeguards such as employee awareness training, consumer protection, breach notification protocols and accessible reporting mechanisms. Because cybercrime is transnational, policies must address cross-border threats, data flows, and international cooperation. Technical maturity, law enforcement resources, and specialist support in the digital economy all shape effectiveness.
6. Recommendations
Public awareness efforts, led by the CSA, include campaigns, school programs, media partnerships, workshops, and online resources on cyber hygiene and safe internet use. Initiatives target children, businesses, and the general public, supplemented by youth digital skills projects and programs on AI ethics. Victim protection measures encompass accessible reporting hotlines, breach notifications, and policies prioritising vulnerable groups under an EDI approach.
A practical framework to help practitioners, compliance officers, board members, and policymakers includes these guiding questions:
- What are our material cybersecurity risks, including past incidents and third-party exposures?
- Do we have adequate expertise and resources, and how are we closing skills gaps?
- How do our disclosures balance transparency with operational security?
- Are EDI principles embedded to protect diverse and vulnerable groups?
- Who is accountable, is the action plan funded and monitored, and how is progress communicated?
- Which national and international laws apply, and are we meeting due diligence and safeguarding standards?
- What gaps exist in our plans, and how can we adopt proven good practices from the NCPS or global benchmarks?
- For CII operators: Does our system fall within a designated critical sector, and have we fulfilled all registration, audit, and reporting obligations?
- Is our verification “deepfake-Proof”? Beyond standard passwords, have we implemented lifecycle intelligence systems and trusted capture technologies to verify identities during high-stakes transactions?
By systematically addressing these elements, companies and the nation can build a more resilient, inclusive, and accountable cybersecurity ecosystem. Robust disclosure and risk management are not merely regulatory burdens—they represent sound business strategy in a digital world where a single incident can carry far-reaching financial, reputational, and legal consequences.
Many organisations now engage with cybersecurity firms with ISO 27001 and CSA accreditation. Firms that provide risk assessments, penetration testing, incident response, training, and regulatory compliance support. Strategic partnership with such firms should be treated as a priority rather than an optional measure.
Conclusion
In an age of advanced connectivity and innovation, the question is no longer whether a cyber incident will occur, but when—and more importantly, how prepared an organisation is when it does. As John Chambers aptly observed, “there are only two types of companies: those that have been hacked, and those that don’t yet know they have been hacked”.
Picture this: a breach unfolds quietly. Not with alarms, but with subtle anomalies—an unusual login, a delayed response, a system behaving just slightly out of place. Would your organisation recognise it in time? Would your board be ready to act? And when the moment comes, would your disclosures reflect clarity and control—or confusion and reaction?
The reality is stark. Cyber risk is no longer confined to IT departments; it sits at the centre of corporate governance, regulatory compliance, and strategic decision-making. For Ghanaian companies, particularly regulated financial institutions and operators of critical sectors, legal obligations under the Cybersecurity Act, Data Protection Act, SEC disclosure obligations and sector-specific directives demand greater vigilance.
The real question remains: the digital climate is evolving– are we prepared for the storm we helped create?
Ultimately, the companies that will remain resilient in this digital era are not those that merely react after a breach occurs, but those that embed cybersecurity into governance structures, disclosure frameworks and long-term corporate strategy.