SunuBarometer: Africa Cybersecurity

This barometer relies solely on our real operational data, aggregated at continental scale — no modeling, no extrapolation.

Methodology

Between June and August 2026, we analyzed 130 distinct African targets through our platform, across all sectors — banking, telecom, government, fintech, Mobile Money. The data is aggregated and anonymized; no organization is individually identifiable.

Missing or misconfigured HSTS
63%

Without this header, visitors remain exposed to HTTPS downgrade attacks on their first connection.

DMARC absent
58%

Without DMARC, nothing prevents an attacker from spoofing the domain for phishing campaigns targeting customers or partners.

SPF absent
57%

Missing SPF makes it easier to send fraudulent emails impersonating the analyzed domain.

No CDN/WAF in front of the infrastructure
45%

The server's real IP address is exposed directly on the internet, allowing any application-layer filtering to be bypassed.

Publicly exposed SSH port
25%

An admin access point reachable from the internet is a prime target for brute-force attempts.

Database exposed on the Internet
13%

MySQL, MongoDB, or Elasticsearch reachable with no authentication from the outside — the equivalent of leaving the door wide open on customer, financial, or operational data.

Measured on 91 targets that underwent an in-depth network audit.

Invalid or expired SSL/TLS certificate
12%

An invalid certificate exposes users to man-in-the-middle attacks and undermines trust.

Where does your organization stand?

A free scan is all it takes to compare your exposure to these numbers, in minutes.

Free scan

Next edition: Q4 2026. These numbers reflect the sample we actually analyzed over the stated period — not a statistically representative study of the entire continent, just what we observe on the ground.