Marrakech, Morocco — Africa’s most prominent cybersecurity diagnosis arrived on Day 2 from the operator, not the regulator. Justin Williams, Group Chief Information Security Officer at MTN Group, took the main stage of GITEX Africa’s inaugural STAR Summit to make the case that the continent’s digital infrastructure buildout — faster and broader than any comparable emerging market — has outrun the governance architecture meant to secure it. The session, the first dedicated cybersecurity main-stage event in GITEX Africa’s four-year history, framed a challenge that Africa’s telcos and fintechs navigate daily but rarely articulate in public. Africa is building the digital infrastructure of a middle-income continent. It is doing so with the cybersecurity architecture of a country that has not yet decided who is responsible for protecting it. That gap — between the pace of deployment and the maturity of governance — was the subject that finally made it onto the main stage at GITEX Africa 2026.
The Strategic Digital Defence AI Readiness Summit, known as the STAR Summit, took over the GITEX Africa main stage on Day 2 for a session that framed Africa’s cybersecurity challenge not as a technical deficit but as a governance failure. The session, organised in partnership with Morocco’s DGSSI (the national cybersecurity agency), brought together the most senior gathering of African cyber officials ever assembled at a regional technology event.
Justin Williams, MTN Group: Named Source on the Risk
Justin Williams, Group CISO at MTN Group, is the most prominent voice on African enterprise cybersecurity to take a main-stage slot at GITEX Africa 2026. MTN operates in 19 African markets, serves 280 million subscribers, and runs MoMo, the continent’s largest mobile money platform. On April 6 — the day before GITEX Africa opened — MTN completed the carving out of its Ghanaian mobile money operations into a standalone fintech entity, the latest step in a continental restructuring intended to allow MoMo to raise capital independently and be valued separately from traditional telecom. That is the operational context for Williams’ STAR Summit appearance: MTN is simultaneously disaggregating its financial services infrastructure and putting its security chief on stage to explain why that infrastructure needs better protection than the frameworks currently governing it. When MTN’s CISO says Africa’s digital infrastructure is outpacing its defences, he is speaking from a vantage point that no national cyber director can match — a system that has to secure transactions, identity data, and mobile money flows across nearly every regulatory regime on the continent simultaneously.
Williams’ STAR Summit appearance centred on the specific threat profile that AI introduces for African financial infrastructure: AI-assisted fraud, deepfake-enabled identity attacks, and the acceleration of phishing and social engineering at scale across mobile money platforms. BETAR.africa reported that 82% of regulators across African markets have cited cybersecurity as a primary concern for their digital economy frameworks — a statistic that GITEX Africa’s STAR Summit brought into executive relief with its most senior-ever panel of African cyber officials. For MTN, the operational stakes are not abstract. MoMo processes transactions across nearly every regulatory regime on the continent simultaneously; a security failure in one market propagates liability across the rest.
Williams’ appearance at STAR Summit follows a documented escalation in AI-assisted cyberattacks targeting African financial infrastructure. BETAR.africa’s analysis of Africa’s AI surveillance and fraud economy — documented in BETA-946 — found that approximately $2 billion is being spent annually on AI-enabled surveillance and cyber tools across the continent, operating in a regulatory environment where zero African countries have enacted comprehensive AI cybersecurity governance frameworks. That is the structural context Williams is operating inside.
Four National Cyber Directors: Different Problems, Same Gap
The STAR Summit panel assembled the most senior gathering of African cyber officials ever convened at a regional technology event. Confirmed participants alongside Justin Williams include Dr. Mohamed Al Kuwaiti (Head of Cybersecurity for the UAE Government, reflecting GITEX’s Gulf-Africa connectivity track), Divine Selase Agbeti (Director-General, Ghana Cyber Security Authority), David Kanamugire (CEO, Rwanda National Cyber Security Authority), Tigist Hamid Mohammed (Director-General, Ethiopia’s Information Network Security Administration — INSA), and Amit Ghodekar (Global CISO at Aramex) representing the private logistics sector — a reminder that cybersecurity risk in Africa is not confined to financial services.
Ghana’s Cyber Security Authority has established a national CERT and begun licensing cybersecurity service providers under the Cybersecurity Act 2020 — the most comprehensive cyber legislation in West Africa. Rwanda’s National Cyber Security Authority operates within Kigali’s broader ambition to position Rwanda as Africa’s most governance-ready digital economy. The UAE’s representation through Al Kuwaiti reflects the Gulf-Africa digital corridor that GITEX — originally a Dubai event — has formalised over four editions. The UAE’s national cybersecurity architecture, built over the past decade into one of the most mature frameworks in the Global South, has become an active reference model for African cyber agencies benchmarking their own governance development.
The STAR Summit closed without a binding multilateral framework — but that was never the stated objective. Its function was to put Africa’s cybersecurity governance gap on record, in public, with named senior officials from five countries and the continent’s largest mobile network operator acknowledging the same structural problem. The sharpest tension in the room was between the pace of AI deployment in financial services — where the continent’s fintechs and telcos are among the most aggressive adopters — and the absence of harmonised incident-response protocols, shared threat intelligence frameworks, or cross-border licensing requirements for cybersecurity service providers operating across multiple African markets simultaneously. That gap remains open.
The Fintech Track: Who Governs Digital Money
While the STAR Summit dominated Day 2’s morning programme, GITEX Africa’s fintech and payments track ran simultaneously across the afternoon — and its central question was simpler and more commercially urgent: in a continent with 54 countries, 42 currencies, and no unified payment infrastructure, who decides the rules for digital money?
The featured panel — “The Digitalisation of Money: Who Governs the Future of Payments?” — framed Africa’s fintech moment as a regulatory arbitrage problem as much as a technology one. Pre-announced speakers include Germain Bahri, Arnoud d’Yve de Bavay, and Aaron Markowitz-Shulman, with Olugbenga Agboola, co-founder and CEO of Flutterwave — Nigeria’s most prominent cross-border payments infrastructure company — among the confirmed fintech track names. Sadeque Ahmed, Executive Director for Digital Onboarding and KYC at JP Morgan Chase, brings the institutional banking perspective. Agboola, whose company secured a Nigerian microfinance banking licence on April 2, framed the regulatory posture that defines Africa’s fintech moment: working with African regulators requires a collaborative approach, he argued, because regulators across the continent are open to innovation but remain focused on protecting users — a constraint that has shaped Flutterwave’s decade-long compliance journey across 34 markets.
Bank Al-Maghrib’s digital dirham project was positioned at the session as a test case for CBDC design in a middle-income African economy: how to build monetary sovereignty into a digital currency without sacrificing interoperability with the regional payment systems that Moroccan firms depend on for cross-border trade. The central bank’s CBDC development — launched under its “Stay Cashless” initiative in February 2026 and targeting faster, more transparent transactions and expanded access in rural Morocco — anchors the country’s argument that monetary digitisation and financial inclusion are the same project, not competing priorities.
The Pan-African Payment and Settlement System (PAPSS) — which launched commercial operations in 2022 and now processes intra-African trade payments in local currencies across a growing number of markets — was anchored to a concrete milestone at GITEX Africa’s fintech track: Bank Al-Maghrib has formally signed the PAPSS membership agreement, making Morocco the 17th country in the network. The addition is strategically significant. Morocco’s PAPSS membership extends the cross-border settlement system’s reach into North Africa’s largest economy and its most active trade corridor with Europe and the Gulf. PAPSS is the most concrete existing infrastructure for the payments layer the continent needs; Morocco’s membership signals that it intends to use GITEX Africa’s fintech credibility to advance its position in that infrastructure, not merely observe it.
Stablecoins and tokenisation received session time that would have been unusual at GITEX Africa two years ago. No single company announcement defined the discussion; instead, the session mapped the regulatory patchwork that stablecoin operators currently face — a patchwork that the continent’s most advanced frameworks are only beginning to address. Kenya’s VASP stablecoin capital framework — which BETAR.africa covered in BETA-1121 — and Nigeria’s VARA regulatory licensing regime are among the most advanced regulatory positions on the continent. Neither is yet comprehensive enough to provide the cross-border legal certainty that fintech operators need to build on.
Deal Flow: Day 2 Is When Term Sheets Move
Day 2 deal flow at GITEX Africa has historically been lighter on formal announcements than Day 1 — the opening day carries the press-release cycle — and heavier on the private meetings that convert into term sheets after the event. The investor presence in Marrakech — 400-plus funds representing $350 billion in assets under management — had 24 hours of Supernova semi-final results and Day 1 showcases to filter toward its highest-conviction follow-ups. No major public investment close or partnership announcement had been confirmed by end of Day 2; the Supernova Challenge final and its $100,000 award are scheduled for Day 3, where investor interest is expected to crystallise around the Fintech and Blockchain, Cybersecurity, and Artificial Intelligence category winners.
BETAR Analysis: Governance Before the Crisis
The STAR Summit’s significance is not that it produced solutions. It is that Africa’s cybersecurity challenge — the gap between digital infrastructure deployment and the security and governance architecture meant to protect it — made it onto the main stage of the continent’s largest technology event, with named senior officials from four countries and the CISO of Africa’s largest mobile network operator committing publicly to the framing.
That is the first step. The second is whether the communiqué or framework commitment that comes out of the STAR Summit produces any binding coordination — cross-border incident response protocols, shared threat intelligence, harmonised licensing requirements for cybersecurity service providers — or whether it joins the long list of African tech governance documents that identify the problem accurately and solve it on no fixed timeline.
Africa’s $2 billion AI surveillance and cyber economy is growing faster than the frameworks meant to govern it. GITEX Africa Day 2 put the right people in the room. Whether anything durable comes out of that room is a different question — one BETAR.africa will track through 2026.
Day 3 of GITEX Africa 2026 focuses on GreenTech and climate-aligned digital infrastructure. BETAR.africa’s post-event analysis publishes later this week.