Cyber, AI, and the African Frontier
Issue 02 · ASMM #1: Foundations · Name Your Operating Assumptions Before You Name Your Controls
Every control you run is a bet on a condition you have not written down. Write it down first.
A bank in Lagos buys a second internet line. Two carriers, two contracts, two invoices, redundancy on paper. Eighteen months later both lines go dark for nine hours on the same afternoon, because both carriers route through the same submarine cable, and that cable was cut by an anchor off the coast of the Ivory Coast. The bank did not buy redundancy. It bought the appearance of redundancy, twice. The control was real. The assumption underneath it was wrong, and nobody had written the assumption down where it could be checked.
This is the failure that the second issue of this publication is about. Not a missing control. A missing assumption. The security programme that fails on contact with operators almost never fails because someone forgot to deploy a tool. It fails because the tool was deployed against a condition that does not hold, and the gap between the assumed condition and the real one was never made visible enough to argue about.
The refusal
Here is the piece of received framework wisdom this issue refuses: that you start with controls. Almost every imported maturity model opens with a control catalogue or a function list. Identify, Protect, Detect, Respond, Recover. Pick your tier, map your controls, close your gaps. The assumptions that make those controls coherent are left implicit, which is precisely how organisations adopt models that do not match their reality. The catalogue looks complete, so the question of whether it fits never gets asked out loud.
The African Security Maturity Model inverts this. Edition 1 buried its operating assumptions at the back, where they could not shape the reading. Edition 2 pulled them to the front, ahead of the Postures, ahead of the ten Domains, ahead of every control. The reordering was not cosmetic. It was the single most important structural change between the two editions, because it changes what the reader does first. You do not begin by asking which controls to run. You begin by asking which conditions you are betting on.
Six bets you are already making
The ASMM names its assumptions across five groups: infrastructure, regulatory, organisational capability, threat environment, and economic and social conditions. You do not need the full instrument to feel the force of the idea. Six bets carry most of the weight, and each one, stated plainly, is the kind of sentence a board has never seen in a security paper.
Power and connectivity are unreliable but not absent. Your continuity controls assume intermittent grid power and multiple sources to fall back on. In a sustained conflict zone where every source is gone for weeks, that bet is off, and your Power and Pipe Resilience controls need a different design than the model prescribes.
Your two carriers may be one carrier. Redundancy is a bet on divergent upstream paths, not on two logos on two invoices. The Lagos bank lost that bet. Validate the cable, not the contract.
A meaningful share of your customers cannot read. Every SMS warning, every text-driven authentication challenge, every phishing-recognition assumption is a bet that the user can read it. For a non-trivial fraction of the continent that bet fails silently, and the customer who cannot read your warning is the customer the fraud economy reaches first.
The state has legal demand authority over your security function. Imported frameworks treat lawful demand as a privacy footnote. On most of the continent it is a working condition: call detail records, customer data, intercept assistance, server-room access. Compliance with the law is not the failure. Operating without a documented practice for handling the demand is.
Your people are physically exposed. A response runbook that requires a senior engineer to drive to the data centre at three in the morning has quietly assumed they will arrive. In parts of the operating geography that assumption is a real bet with a real failure rate, and it belongs in the runbook, not in the silence around it.
Fraud is the first threat, not the second. If your threat model is inherited from a stable jurisdiction, it ranks the nation-state intrusion first and the fraud economy somewhere below. Across most African regulated organisations that ranking is inverted, and the adversary frequently has community ties to the people inside your own building.
The Monday-morning exercise
Here is the decision you can act on at the start of the week. Before your next control review, before the next tooling renewal, before the next board paper, take one page and write down the six conditions your current programme assumes. Then mark each one against your environment: true, partial, or false. True means the assumption holds and your controls are coherent. Partial means it holds in part and the control needs local adaptation. False means the condition does not exist and the control is running against air.
This is the ASMM Field Test, compressed to a single sitting. The model’s own threshold is blunt: if three or more of your core assumptions come back false, you do not adopt the framework as written. You adapt it first, or you find a better reference. The same threshold applies to your existing programme. Three false assumptions is not a tuning problem. It is a programme built for a place you do not operate in.
The exercise costs an hour. It will not produce a new control. It will produce something more useful: a written record of where your defensible-looking programme is betting on conditions that are not true, which is the one document an external assessor, a regulator, or a sceptical board chair can actually argue with. An assumption you have written down is a gap you can work. An assumption you have left implicit is a gap that works you.
Next issue moves from the assumptions to the Postures themselves: why they are operating states rather than capability tiers, why an organisation can lose one as well as earn one, and why the weakest critical Domain, not the average, sets the headline. For now, the work is the page.
List the controls and you describe what you have bought. List the assumptions and you find out what you have actually been defending.
— Baliyat Johnson
CISM, PMP
Written from Denver, Colorado · June 03, 2026

