Articles & insights
Cybersecurity in Senegal in 2026: Priorities, Institutions and Emerging Challenges
Senegal cybersecurity in 2026: New Deal Technologique, cyber resilience, AI, critical infrastructure, skills and executive committee priorities.
Explore the full story
Senegal is accelerating its digital transformation. But as government, public services, payments, identity, cloud and businesses become more digital, cybersecurity becomes a matter of continuity, sovereignty and trust — not just technical tools.
In 2026, the signal is clear: cybersecurity is now tied to the country's economic and institutional agenda. The New Deal Technologique, launched in February 2025 as part of Senegal 2050, explicitly places digital sovereignty, infrastructure security, protection of critical data and development of local solutions at the heart of the national ambition.
Key takeaway
The issue is no longer simply “how do we block an attack?” The real question becomes: how do we continue to operate, decide and serve when the digital environment becomes more exposed, more automated and more dependent on third parties?
The 5 figures and signals to remember
| Signal | What it means for an executive |
|---|---|
| 55% of cybercrimes reported in INTERPOL's 2026 assessment in Africa are linked to AI use | AI also accelerates fraud, phishing and industrial-scale attacks. |
| Senegal ranks Tier 3 — Establishing in the ITU Global Cybersecurity Index 2024 | Foundations exist, but organisational and human capabilities remain areas for improvement. |
| The New Deal Technologique includes 12 priority programmes and 50 flagship projects | Digital transformation will create new assets, flows and dependencies to protect. |
| Senegal has had a national AI strategy since 2023 | Cybersecurity and AI governance must be considered together. |
| In June 2026, the Presidency again emphasised sovereign security for critical data and infrastructure | Cyber resilience is now an explicit public policy concern. |
1. The New Deal Technologique changes the scale of risk
The New Deal Technologique, officially launched on 24 February 2025, aims, among other things, to digitalise government, provide universal internet access, establish digital identity, develop local champions and modernise public infrastructure.
For cybersecurity, this creates three immediate effects.
More essential services become digital
Civil registration, healthcare, payments, land registries, citizen services, taxation and other digital procedures expand the exposure surface. An incident no longer affects “IT” alone: it can interrupt a service, undermine trust or block an operational chain.
Identity becomes critical infrastructure
The unique digital identity project announced in the New Deal Technologique raises a central question: how do we prove that a person, machine or agent is actually acting with the authority it claims?
The more identity is used as a gateway to sensitive services, the more critical authentication, privilege management, evidence and traceability become.
Sovereignty requires scrutiny of technology dependencies
Cloud, SaaS, operators, integrators, APIs, cybersecurity suppliers, AI and subcontractors create dependency chains. An organisation can be well secured internally while remaining vulnerable through a critical supplier.
Cyber risk in 2026 is therefore also a concentration and supply-chain risk.
2. Senegal has solid foundations — but organisational maturity must improve
The ITU Global Cybersecurity Index 2024 gives Senegal relatively strong scores for legal, technical and cooperation measures. Organisational measures and capacity development, however, remain areas for improvement.
An executive reading of the GCI
| ITU pillar | Senegal score / 20 | Interpretation |
|---|---|---|
| Legal measures | 15.56 | Relatively structured legal foundation |
| Technical measures | 14.41 | Technical capabilities in place |
| Organisational measures | 9.06 | Governance and coordination need strengthening |
| Capacity development | 9.31 | Skills and maturity are priorities |
| Cooperation | 18.83 | A relative strength |
These results come from the 2024 GCI edition: they are not a real-time measurement for 2026. But they offer a useful indication: the next step is not simply to buy more technology. It is to improve governance, coordination, measurement and skills development.
3. AI is shifting the cybersecurity frontier
According to INTERPOL, AI is now linked to more than half of the cybercrimes reported in its 2026 assessment in Africa. The report describes cybercrime that is more industrialised, more scalable and harder to detect.
This changes how we think about defence.
Previously, the question was:
“Who has access to the system?”
Now we must also ask:
“Which AI agent can act? With which identity? On which data? On whose behalf? Within which limits? And how can we prove what it actually did?”
This is why AI governance and cybersecurity can no longer be handled by two teams that do not talk to each other.
For more detail: Responsible AI Governance in Francophone Africa.
4. Critical infrastructure becomes the real test of maturity
In June 2026, Senegal's Presidency explicitly called for stronger comprehensive, sovereign security of critical data, systems and information infrastructure.
This priority is consistent with evolving risk: when digital technology becomes economic infrastructure, availability becomes as important as confidentiality.
Questions senior management should ask
- Which critical service cannot stop for more than two hours?
- Which single supplier could cause a major shutdown?
- Which compromised identity could open up the broadest access?
- Which backups have actually been tested?
- What plans exist if cloud, ERP, email or the IdP become unavailable?
- Who makes the decision when a service must be shut down to protect the rest?
These are governance questions, not just SOC questions.
5. ISO/IEC 27001: useful because it requires organisations to structure risk
ISO/IEC 27001:2022 defines the requirements for an information security management system (ISMS). The standard's value is not limited to certification: it requires an organisation to define its scope, responsibilities, risks, controls, monitoring and continual improvement.
In a Senegalese context where organisational and human capabilities are specifically identified as areas for improvement, this discipline is particularly relevant.
A well-built ISMS helps answer simple but often poorly documented questions:
- which assets are genuinely critical;
- which risks are accepted;
- which measures are justified;
- who is responsible for them;
- how management knows whether the level of risk is actually improving.
See also: ISO/IEC 27001 in Senegal: A Practical Guide for Businesses and Executives.
6. The six cyber priorities we would put on a 2026–2027 roadmap
1 — Governance and accountability
Clearly define who decides, who accepts risk and who reports to the executive committee.
2 — Identity and privileges
Reduce standing privileges, strengthen identity assurance and monitor sensitive access.
3 — Critical service resilience
Test continuity, backups, dependencies and unavailability scenarios.
4 — Third parties and supply chain
Map suppliers capable of creating systemic impact.
5 — Governance of AI uses
Inventory uses, data, models, agents and their permissions.
6 — Skills
Build sustainable internal capabilities: governance, risk management, incident response, architecture, audit, AI and cloud.
7. An opportunity: turn cybersecurity into a trust advantage
Senegal seeks to strengthen its digital position in Africa. To achieve this, cybersecurity must not be treated solely as a necessary cost.
An organisation capable of demonstrating:
- control over its risks;
- continuity of its services;
- protection of its data;
- governance of its AI uses;
- management of its suppliers;
- and the competence of its teams
can turn cybersecurity into a trust advantage with customers, investors, partners and institutions.
ECW Insight
The real question in 2027 will probably no longer be “do you have a cybersecurity policy?” It will be: can you prove that your controls work when the context changes?
Executive committee takeaways
- Digitalisation increases dependence on systems and third parties.
- Digital sovereignty creates a need to manage critical dependencies.
- AI accelerates both legitimate uses and attacks.
- Senegal already has legal, technical and cooperation foundations; governance and skills remain decisive.
- Cyber resilience becomes an executive issue because continuity and trust depend on it.
For more: CISOs and Executive Committees: 10 Cyber Questions Boards Should Ask in 2027.
ECW Dakar 2026
The ECW Executive Forum on 19 December 2026 brings together executives, CISOs, CIOs, CTOs, institutions, investors and technology companies around the cybersecurity, AI and digital trust decisions shaping Africa.
The Forum is free. In-person access is curated.
Explore the Executive Forum · Join ECW Live
Sources
- Presidency of Senegal — New Deal Technologique, 24 February 2025: https://www.presidence.sn/fr/actualites/new-deal-technologique-une-ambition-nationale-pour-faire-du-senegal-un-leader-de-leconomie-numerique-en-afrique/
- Presidency of Senegal — Council of Ministers, 17 June 2026: https://www.presidence.sn/fr/actualites/communique-du-conseil-des-ministres-du-mercredi-17-juin-2026/
- ITU — Global Cybersecurity Index 2024: https://www.itu.int/pub/D-HDB-GCI.01-2024
- INTERPOL — African Cyberthreat Assessment 2026: https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa
- UNESCO — AI Readiness / Senegal Country Profile 2026: https://www.unesco.org/ethics-ai/en/global-hub/senegal
- ISO — ISO/IEC 27001:2022: https://www.iso.org/standard/27001
