60
CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
Crime, which reports directly to the Ministry of Territorial Administration and Internal Security (MATSI).
The country has established numerous informal mechanisms for responding to cyber incidents but has
not yet established into law formal procedures and policies to do so.
The Government of Burkina Faso has established and operated a national-level CIRT (BF-CIRT) for
several years. The primary role of Burkina Faso’s CIRT is to coordinate and assist government agencies
in implementing services and technical guidance to lower the risk of computer security incidents as
well as respond to mitigate such incidents when they occur. Another primary role for CIRT-BF is to
develop and conduct awareness campaigns to help educate the local population about the dangers
of cyber threats and cyber crime. Lastly, CIRT-BF disseminates timely cyber threat advisories to all
national constituents. In addition, BF-CIRT is planning to evolve into an Agency level organization named
the Security Agency of Information. Once established, this Agency will have additional tasks assigned
to them including to ensure the effective implementation of national policy and to establish specific
national standards for information security.
Burkina Faso developed their national cyber security strategy called the National Plan for Cyber
Security in 2010 at the request of the Electric Communications Regulatory Authority with the support
of the International Telecommunications Union (ITU). The primary objective of the national strategy is
to “engage and authorize each Burkinabe government agency to secure the portion of cyberspace
that controls and manages or with which it interacts.” In addition, the national plan seeks to provide
a strategy to reduce vulnerabilities in cyberspace, conduct effective incident management, and to
strengthen the overall culture of cyber security through awareness initiatives.
Two notable actions stemming from the Cyber Security National Plan was the creation of a National
Security Agency Information Systems (ANSSI) in 2013, and the National Incident Response Centre
(BF-CIRT). Government agencies have not been actively promoting cyber resilience or cyber security
awareness or carried out activities involved in cyber resilience.
Several challenges have been identified by the government in effectively implementing the National
Cyber Security Policy. The primary challenges faced by the government in implementing a national
cyber security policy are the establishment of standards for action, budgetary constraints, and lack
of local cyber expertise. The government of Burkina Faso has not yet begun to work with NGOs to
educate and raise awareness of cyber risks. Nor has the government established cyber security
education and training centers due to a number of obstacles including budgetary constraints and lack
of local expertise.
Over the last few years, Burkina Faso has experienced an increase in the number and severity of cyber
incidents. In particular, there has been a dramatic increase in the number of attacks against websites.
Unfortunately, there is a lack of reporting of incidents by victims and therefore estimates remain artificially low. But already in the first half of the year, the number of recorded attacks exceeded the total
number of attacks in the previous year. Some public sources exist that provide limited data on attacks
against websites in Burkina Faso, such as www.zone-h.org. The most serious cyber security incident
occurred in April of 2015 when 56 government websites were defaced. While the perpetrators have not
been identified, most indicators, such as indicators of compromise and IP addresses, suggest that the
criminals came from outside of Burkina.
While no formal working framework has been established to partner with the private sector, a number
of private entities have been identified as primary stakeholders in Burkina Faso’s national CIRT, BF-CIRT.
The actions that can be taken in order to effectively partner with the private sector should be clearly
established in the national strategy and policy documents and agreements that are non-existent at
the moment. At this time, Burkina Faso has no formal partnership arrangements signed with other
countries. However, they do have several technical information exchanges established with organizations including the US-CERT, France’s ANSSI, Tunisia’s ANSI, and the Ivory Coast CERT
In principle, based on the public channels established by the various national agencies responsible for
the management of cyber security incidents, Burkina Faso is able to exchange cyber threat information.
They have taken a number of steps to establish structures that have enabled them to process tasks
and share cyber threat information. These entities include the National Security Agency Information