
#BoomingAfrica: frugal innovation and digital sovereignty
Between myths, models and realities, can frugal innovation serve genuine African digital sovereignty?
Identifying, prioritizing and treating cyber-risks: an accessible method adapted to African contexts.

In cyber as in other fields, in order to map threats and determine the effective security measures to implement, it is necessary first to conduct a rigorous risk assessment. Faced with cyber-threats that are both increasingly present and increasingly sophisticated, faced with a multitude of increasingly capable actors who wish to acquire or retain interests on the African continent by every means—including cyber means—risk analysis is a crucial step for African states in protecting their cyberspace. All the major powers have understood this and practise it rigorously. These extracts from the prologue of the United States' national strategy for cyberspace operations, made public by the Department of Defense, illustrate this very aptly:
"… Through the process of risk management, leaders must consider risk to U.S. interests from adversaries using cyberspace to their advantage and from our own efforts to employ the global nature of cyberspace to achieve objectives in military, intelligence, and business operations…"
"… For operational plans development, the combination of threats, vulnerabilities, and impacts must be evaluated in order to identify important trends and decide where effort should be applied to eliminate or reduce threat capabilities; eliminate or reduce vulnerabilities; and assess, coordinate, and deconflict all cyberspace operations…"
"… Leaders at all levels are accountable for ensuring readiness and security to the same degree as in any other domain…"
These short extracts reveal that, in their national security strategy, the United States considers cyber-risk management to be the process by which leaders identify hostile actors and assess the threats these pose to their interests in cyberspace, but also a means of assessing their own ability to exploit the very nature of cyberspace to achieve strategic objectives.
Thus, as recommended by the practical guide to cybersecurity and cyberdefence published by the OIF in 2016 (International Organisation of La Francophonie), all African leaders should (at least for these same reasons) have a good command of their digital ecosystem, of its planned evolution, and therefore of the related risks.
A digital risk is the possibility that a given threat exploits the vulnerabilities of an asset or group of assets and thus harms an organisation or a country. Risk is measured in terms of the combination of the likelihood of an event (the probability of it occurring) and its consequences (its concrete impact were it to occur).
The threat is the source of risk associated with its method of attack, while the vulnerability represents the flaw existing in the system and identifiable by the source of risk. Exploiting this flaw therefore amounts to compromising the system.
Below are some formulas that simplify understanding of the link between these different concepts, which are decisive for properly grasping the notion of cyber-risk:
R = T x V (Risk = Threat x Vulnerability)
T = S x A (Threat = Source/Origin x Attack method)
rL = R x P x I (Risk level = Risk x Probability x Impact)
Now that we have laid out these fundamentals, I invite you to begin the analysis proper. To do so, there are several standards that detail why a risk analysis is important and the key elements to take into account. The best known, widely used by specialists worldwide, is the ISO 27005 standard. However, while this standard tells you "why" you need to conduct a risk analysis, it does not tell you "how" to do it. A method is therefore necessary to implement the standard. Here again there are several, the most used being OCTAVE in the United States, then MEHARI and EBIOS in Europe.
In this article, we will use the EBIOS method to propose a risk-analysis scheme at the scale of an African country (or an organisation of vital importance in these countries), so that those who wish can draw inspiration from it to effectively develop their own cyberdefence strategy.
Developed by ANSSI (the National Information Systems Security Agency in France), the EBIOS method we use here relies on an approach comprising the following five steps:
– The study of the context and existing baseline
– The identification of feared events and targeted objectives
– The study of threat scenarios (strategic and operational)
– The treatment of risks (reduce, accept, avoid, etc.).
As a first step, let us begin by defining the scope of the analysis.

Between myths, models and realities, can frugal innovation serve genuine African digital sovereignty?

African cyber governance plays out at the crossroads of political decision, sovereignty and regional cooperation.

Can the proven principles of military strategy inform the conduct of operations in cyberspace?