by Shehzadi NAJAF
In 2025 the world’s online population reached six billion people for the first time, while 2.2 billion remained offline, according to the International Telecommunication Union, most of them in low and middle income countries. That is, on its own, a connectivity success story. The trouble is that the newly connected are being plugged into a digital world most of their governments are not yet prepared to defend.
The gap is not only about who gets online, but about the quality and security of that access. The same ITU data show that 5G coverage reaches 84 percent of people in high income countries but only 4 percent in low income ones, and that users in wealthier countries consume nearly eight times more mobile data than users in poorer ones. Newer, faster connectivity is arriving overwhelmingly in places that can already afford to secure it, while slower, older, and more exposed networks are left to carry the world’s fastest growing user base.
Security readiness tells much the same story. The ITU Global Cybersecurity Index 2024 found that 105 countries sit in its middle tiers, described as establishing or evolving. These are states that have expanded digital services and connectivity rapidly but have not integrated cybersecurity into that growth, leaving what the index calls a cyber capacity gap in skills, staffing, equipment, and funding. The World Economic Forum’s Global Cybersecurity Outlook 2026 warns that this tech divide is widening rather than closing, as better resourced economies pull further ahead in cyber resilience even as connectivity itself becomes more equal.
The consequences are visible in Africa’s healthcare sector, one of the fastest digitizing on the continent. Ransomware attacks on African organizations surged 48 percent by mid 2026, with government services and critical infrastructure in Nigeria, Angola, Ethiopia, and Zimbabwe facing especially concentrated targeting. In June 2026, South Africa’s National Health Laboratory Service was hit by a ransomware attack that deleted backups and cut physicians off from test results nationwide, arriving in the middle of an mpox outbreak that had already strained the country’s public hospitals. A separate ransomware breach at a private hospital in Durban followed just months later. Neither attack required a sophisticated state actor. Both exploited the same ordinary weaknesses, underfunded security teams and thin institutional defenses, that the ITU index flags across the region.
Pakistan illustrates the same pattern, along with an early attempt at a response. The country’s Computer Emergency Response Team recorded 253 cyberattacks in the first half of 2026 alone, after 927 attacks combined in 2024 and 2025, most aimed at public and private critical infrastructure. That count included a ransomware attack on a government entity in June 2026 that forced officials to rebuild encrypted systems from backup. In response, Pakistan has ordered every public and private organization to stand up a functioning cybersecurity operations center within six months and is finalizing its first national compliance framework, a sign that governments in the Global South are beginning to treat cyber capacity as seriously as connectivity itself, even if the response usually arrives after the damage is done rather than before it.
This matters for global connectivity in a way that goes beyond any single breach. Much of the digital growth in the Global South is now built on mobile banking, digital identity systems, and e governance platforms that citizens are told to trust with their money, their health records, and their legal identity. Every ransomware attack on a hospital network or a government server erodes that trust, and with it the case for further digitization. A region that connects quickly but defends poorly risks becoming dependent on digital infrastructure it cannot fully control or secure, trading one form of vulnerability for another.
International responses exist, but they remain thin relative to the scale of the problem. The Partner2Connect Digital Coalition has mobilized pledges toward closing the access gap in the least developed countries, and the new United Nations Convention against Cybercrime includes provisions meant to help developing states build cyber capacity alongside connectivity. Yet as one representative for the Group of 77 and China put it during recent United Nations digital policy talks, the divide that matters most going forward may increasingly be about who has the capacity to shape and secure technology, not simply who has access to it. Most existing capacity building instruments remain underfunded and thinly staffed compared with the pace at which new users, and new attackers, are arriving online.
Closing this gap requires treating cybersecurity as part of the connectivity project itself, not as an upgrade to be purchased later. Every internet access initiative, digital identity rollout, or e governance platform funded in the Global South should carry a security and workforce training component from its first day of design, not its first day of breach. Universal connectivity was always meant to mean everyone online. It should also mean everyone defended.












