By Jabulani Simplisio Chibaya
HARARE – ON 1 September 2026 — the very day this article is being written — Zimbabwe’s Postal and Telecommunications Regulatory Authority (POTRAZ) begins mandatory, on-site inspections of every organisation that collects or processes personal data under the Cyber and Data Protection Act. It is not a coincidence worth ignoring. Two months later, from 4–7 November 2026, the Internal Control Institute of Zimbabwe (ICIZ) will host the 12th Internal Control Congress for Africa at A’Zambezi River Lodge in Victoria Falls, under the theme “Building Resilient IT Control Environments for Effective Risk Governance, Cybersecurity, Data Protection and Digital Transformation.” Few conference themes have landed at a more consequential moment for African boards, auditors, CISOs and regulators.
The Congress brings together COOs, CFOs, CROs, CIOs, CISOs, chief audit executives, internal and external auditors, compliance officers, data protection officers and regulators from across the continent to work through a curriculum that spans IT governance, COBIT 2019, ISO/IEC 27001, identity and access management, change management, disaster recovery, cybersecurity governance, AI governance, third-party risk and IT audit. It is a deliberately practical agenda, and the events of the past year explain why.
The 200-day blind spot
IBM’s 2026 Cost of a Data Breach Report, produced with the Ponemon Institute from 602 breached organisations worldwide, found that it now takes an average of 247 days to identify and contain a breach — 183 days to spot it, 64 more to shut it down. That figure had been falling for five straight years; 2026 is the first year it reversed. The cost difference is not trivial: breaches contained within 200 days averaged $4.32 million, while those that dragged on longer averaged $5.65 million. The global average cost of a breach hit a record $4.99 million, up 12% year on year, and a quarter of malicious breaches now involve attacker-side AI, pushing their average cost closer to $6 million. For an African CISO, the message is blunt: the danger is rarely the initial intrusion. It is the six-plus months an organisation spends unaware that it has already been compromised.
When trust becomes the attack surface
Nowhere is that dwell-time problem more visible than in mobile money. In June 2026, Zimbabwean prosecutors detailed how a married couple and their accomplices used a fraudulently obtained SIM-card replacement to hijack an EcoCash line belonging to an unwitting victim, then used the hijacked number to defraud three separate people of a combined ZiG223,000 by posing as a legitimate currency trader. It followed an earlier, narrowly foiled attempt in which hackers tried to SIM-swap their way into a Zimbabwean security company’s EcoCash account to steal US$190,000, caught only because an alert agent grew suspicious during the SIM-replacement process. These are not isolated incidents. Regionally, Kenya recorded roughly 123,000 fraudulent SIM registrations and a 327% surge in SIM-swap fraud in a single year, draining an estimated $3.8 million from mobile wallets — a scale of loss that forced regulatory reform. The common thread across all these cases is a weak link in identity verification at the telecom-agent level, exploited to defeat SMS-based two-factor authentication that millions of African mobile-money users still rely on.

Malware doesn’t discriminate by market size
Banks and development finance institutions across the region have had a rough eighteen months. ZB Financial Holdings in Zimbabwe suffered a ransomware attack in mid-2024 that leaked customer and operational data. The Development Bank of Southern Africa confirmed in 2026 that the Akira ransomware gang had encrypted servers, logs and documents, exposing business names, director details, identification documents and contact information. South Africa’s Land and Agricultural Development Bank was hit by ransomware in January 2026, with attackers demanding roughly R5.7 million in Bitcoin after exfiltrating and encrypting files. None of these were exotic, novel attacks — they followed the well-worn ransomware playbook of initial access, lateral movement, exfiltration and encryption, the same playbook ITGC frameworks like COBIT and the CIS Controls are explicitly designed to interrupt at multiple points.
The root cause is rarely exotic
It is tempting to treat every breach as a story about sophisticated adversaries. The data says otherwise. The Association of Certified Fraud Examiners’ 2024 Report to the Nations, drawn from nearly 1,921 real cases across 138 countries, found that a lack of internal controls (32% of cases) and the override of existing controls by management (19%) together explained more than half of all occupational fraud — costing victim organisations over $3.1 billion and, on average, roughly 5% of annual revenue. Segregation of duties, password management, user provisioning and de-provisioning, and privileged access monitoring are not bureaucratic checkboxes; they are the specific controls that, when absent or overridden, show up again and again as the opening chapter in fraud and breach investigations.
From manual reviews to real-time streams
One of the more encouraging shifts in control design is the move from periodic, manual sampling toward continuous, automated monitoring using event-streaming architectures. Apache Kafka and Apache Flink have become a de facto standard for this: transactions are published as events to Kafka in real time, and Flink applies stateful rules and pattern-matching logic against them within milliseconds, rather than hours. PayPal and Capital One process billions of these events to catch fraud and PII exposure in-flight; ING Bank was an early adopter of Kafka-and-Flink-based fraud detection with embedded analytic models; Turkey’s Garanti BBVA uses Flink to monitor transactions and update detection rules without taking systems offline. For internal control functions, the practical implication is that velocity checks, threshold breaches, unusual access patterns and segregation-of-duties violations can be flagged and escalated continuously, rather than discovered in next quarter’s audit sample — directly attacking that 247-day dwell-time problem.
An open, auditable governance model worth studying
A genuinely notable case study for African institutions building their own AI and IT governance is Banco Santander’s decision, in June 2026, to open-source more than a dozen of its internal AI and governance tools on GitHub under an Apache 2.0 licence — becoming, by most accounts, the first major global bank to publish its AI governance stack for anyone to inspect, fork or challenge. Among the released tools is a “mechanical governance framework” for large language models, which defines configurable rules, thresholds, verification gates and audit metrics for high-stakes automated decisions, alongside a synthetic fraud-graph generator that lets institutions test detection models without exposing real customer data. Whatever one’s institution decides about publishing its own code, Santander’s framework is a useful reference point for what auditable, rule-based AI governance can look like in practice.
The compliance clock has started
For Zimbabwean organisations, the regulatory backdrop is no longer theoretical. The Cyber and Data Protection Act’s licensing regime — requiring data controllers to register, appoint a certified Data Protection Officer, and report breaches to POTRAZ within 24 hours — has been building since 2024, and as of today, POTRAZ inspectors are authorised to walk in and check compliance. Non-compliance carries fines and, in some cases, imprisonment.
What Interpol’s June report says about Africa — and Zimbabwe
Interpol’s African Cyberthreat Assessment Report 2026, released in June and drawing on data from 36 member countries, found that AI now plays a role in 55% of reported African cybercrime, and that continental losses more than doubled from $192 million in 2024 to $484 million in 2025 — against a combined continental cybersecurity spend of only $15.3 billion. Zimbabwe does not appear as a standalone line in the country-level statistics, which analysts read as a reporting gap rather than genuine immunity; the one direct reference is that Harare hosted the region’s first AFJOC Mobile Forensic Workshop in December 2025, a sign both of Zimbabwe’s emerging role as a training hub and of how thin forensic capacity was to start with. Zimbabwe sits inside the Southern African cluster the report describes as the continent’s most heavily targeted, sharing its defining exposure: high mobile-money dependence, growing connectivity and immature real-time biometric verification relative to markets like Kenya.
Board imperatives and a call to action
The recommendations that fall out of this landscape are consistent across every source: boards should treat cyber resilience as enterprise risk with quarterly reporting, not an annual IT briefing; CISOs should prioritise identity-layer defences — SIM-swap monitoring, MFA hardened against social engineering, deepfake-aware verification for high-value payment approvals; regulators should legislate mandatory, time-bound breach disclosure; and every AI capability rollout should be paired with an equivalent AI-threat-literacy programme for staff.
The ICIZ Congress in Victoria Falls is where these imperatives get translated into practice — through frameworks, peer case studies and direct access to regulators and practitioners shaping Zimbabwe’s and Africa’s IT control agenda. Registration is open now, with a “with accommodation” package (USD $2,150 members / $2,250 non-members, plus $500 airfare allowance) and a conferencing-only option (USD $1,250 members / $1,350 non-members, plus $500 airfare allowance). Full payment is due within seven working days of registration, and CPD points are available. Organisations serious about closing the gap between today’s 247-day breach lifecycle and tomorrow’s regulatory reality should reserve a seat — and a seat at the board table for this conversation — now.
Jabulani Simplisio Chibaya is a Data and AI Consultant specializing in data science, artificial intelligence, blockchain, and cryptocurrency innovation. A seasoned conference speaker, he also writes on the intersection of technology, regulation, and economic development. Contact: Cell: +263 778 921 881 | Email: simplisiochibaya22@gmail.com | LinkedIn: https://www.linkedin.com/in/jabulani-simplisio-chibaya
Discover more from Etimes
Subscribe to get the latest posts sent to your email.

