AFRICA DATA TALK

AFRICA DATA TALK

Governance • Risk • Compliance • AI

🚨 Regulatory Alert
🇸🇳 SENEGAL EXPLAINED

PROTECTING CRITICAL INFRASTRUCTURE

Senegal's draft law: securing vital networks and mandating cyber-resilience

Cybersecurity Essential / Vital Operators GRC Compliance

AFRICA DATA TALK

Context & Urgency

1. The Context: Why Cyber-Resilience Is Urgent

Multiplying threats: Senegal's energy, telecoms and banking infrastructure is being targeted directly.
A move to hard law: awareness raising is no longer enough; the state is shifting to a binding legal framework.

Continuity of Essential Services

An IT outage in the banking or energy sector can paralyse the national economy. The law is designed to guarantee operational continuity.

Protecting Sovereignty

Shielding critical data belonging to the state and to Senegalese citizens from espionage, ransomware and external tampering.

AFRICA DATA TALK

Legal Framework

2. Pillars of the Law: Operators' Obligations

1. Designating Essential Operators

Formal identification of operators of vital importance (banking, energy, telecoms, health, transport) that fall under regulation.

2. Strict Standards

A duty to apply rigorous security standards: periodic information security audits, zero-trust architectures and identity management.

3. CSIRT Reporting

Mandatory notification of any security incident or data breach to the national authorities (ANC / Senegal CSIRT).

Certification of Critical Systems

Operators must obtain prior security certification for any new information system of vital importance.

AFRICA DATA TALK

C-Level Accountability

3. C-Level Governance & Financial Penalties

Financial & Administrative Penalties

Heavy fines and suspension of operations where the mandated security rules are plainly breached.

Executive Accountability

Executive committees, CISOs and DPOs are directly involved in approving security policies and ensuring compliance.

Mandatory BCP / DRP Testing

A legal duty to test business continuity and disaster recovery plans at least once a year.

Third-Party Audit

Regular audits by state-accredited firms to verify the real cyber maturity of vital operators.

AFRICA DATA TALK

ECOWAS Standards

4. Regional Alignment & ECOWAS Standards

ECOWAS Act

Direct alignment with the revised ECOWAS Supplementary Act on cybersecurity and critical infrastructure.

Malabo Convention

Implementing the principles of the African Union Convention on cybersecurity and data protection.

AfCFTA Trust

Protecting cross-border data flows to offer international investors a trusted environment.

Regional Alert-Sharing Network (IoCs)

Linking national CSIRTs so indicators of compromise are shared in real time and attacks stop spreading.

AFRICA DATA TALK

Action Plan

5. Action Plan: A Checklist for Businesses

1️⃣ Map Critical Information Systems

Identify vital assets and sensitive databases, and audit every dependency on IT subcontractors.

2️⃣ Run Regular Audits & Penetration Tests

Launch external and internal penetration tests, tighten privileged access management (PAM) and formalise security policies.

3️⃣ Build the Crisis & Notification Protocol

Define a clear emergency escalation procedure so the national CSIRT can be alerted within 72 hours of an incident.

AFRICA DATA TALK

ADT Takeaway

"Cybersecurity for critical infrastructure is no longer a technical recommendation: it is a sovereignty imperative and a legal duty for Senegal's resilience."

🌍 Explore all 45 African laws, decoded, on our platform:

www.africadatatalk.com