Ivory Coast

Your cybersecurity company in Ivory Coast.

We test your systems, watch them around the clock, and help you meet Law 2013-450 and what the ARTCI expects. We work with banks, telecom operators, industry and SMEs in Côte d'Ivoire, in French or English, in your time zone.

01 · Why nexaya in Ivory Coast

The digital economy is moving fast. So are the rules.

Mobile money, online banking and e-government are growing quickly in Ivory Coast, and attackers have noticed. The law is catching up too: data protection overseen by the ARTCI, a cybercrime law, and BCEAO requirements for the financial sector. We help you handle all of it in one programme.

nexaya's managing director in conversation at a client briefing
01

We know the Ivorian framework

Law 2013-450, Law 2013-451, Law 2013-546, the ARTCI, CI-CERT, the BCEAO. We prepare the files and evidence your regulators expect.

02

In French, in your time zone

Reports, policies and read-outs in French. During an incident, you reach someone who's working the same hours you are.

03

One base for the whole region

If you also operate in Senegal, Burkina Faso or Mali, we line up each country's requirements on a single ISO 27001 base.

04

Named, certified engineers

CISSP, CEH, OSCP, ISO 27001 Lead Auditor. The engineers you meet before you sign are the ones who hold them.

02 · The rules

Which Ivorian rules apply to you.

Most of our clients answer to at least two of these. We treat them as one programme so you only collect the evidence once.

nexaya consultants at our stand at a technology trade show
Law 2013-450 & ARTCI Personal data protection. Declarations and prior authorisations with the ARTCI, people's rights over their data, and rules on sending data outside Ivory Coast.
Law 2013-451 The cybercrime law. Obligations to keep data, cooperate with the authorities and report incidents, working with CI-CERT.
Law 2013-546 Electronic transactions. Security requirements for online commerce, electronic signatures and trust services.
BCEAO & Banking Commission Risk management, information security and business continuity requirements for banks, microfinance institutions and e-money issuers across the West African Monetary Union.

How we handle compliance across our markets →

04 · Sectors

We spend most of our time where the exposure is highest.

Banking, microfinance & mobile money Insurance Energy Public sector Ports, transport & logistics SMEs

Mobile payment fraud, targeted phishing against financial services, and ransomware aimed at businesses are among the threats we see most often. Our tests, monitoring and training are built around those scenarios.

05 · Questions

What Ivorian companies usually ask us.

Do we have to declare our personal data processing to the ARTCI?

Generally, yes. Law 2013-450 requires you to complete formalities with the ARTCI before processing personal data, either a declaration or an authorisation depending on the data and what you do with it. It also controls transfers of data outside Ivory Coast. We map your processing and prepare the files.

Do you run penetration tests in Ivory Coast?

Yes. External, web, API and cloud tests are done remotely. Internal tests and infrastructure reviews happen on site when the scope needs it. Reports are written in French, with a summary for management and findings tied to ISO 27001 and your regulator's requirements.

Can our BCEAO requirements be handled alongside ISO 27001?

Yes, that's how we work. Each BCEAO and Banking Commission requirement is mapped to an ISO 27001 Annex A control, so you build the evidence once and use it for both.

What should we do if we're under attack?

Don't switch off the affected machines. Disconnect them from the network, don't delete anything, and contact us straight away, whether you're a client or not. We'll help you contain it, keep the evidence and report it to the right authorities. Our emergency page walks through the steps.

Do you work with smaller Ivorian companies?

Yes. Our Core package is built for organisations taking security seriously for the first time: endpoint protection, patch management, a monthly vulnerability scan and a quarterly review, at a predictable monthly cost. Our SME page has the details.

Free assessment · Ivory Coast

See what an attacker can see.

It takes five days and costs nothing. We map what you have exposed on the internet, check your controls against Law 2013-450 and ISO 27001, and give you a prioritised list of what to fix. You keep the report.

Under attack right now? Here's what to do →

Free security assessment, Ivory Coast.

Mutual NDA signed first. Findings stay yours.

You'll hear back within one business day, from an engineer.

Request received.

An engineer will get back to you within one business day to sort out the NDA and a start date.