Abridged Version for Stakeholder Validation | January 2026
KNS KNOWLEDGE NETWORK SOLUTIONS
NATIONAL CYBERSECURITY COORDINATION CENTRE (NC3)
SIERRA LEONE DIGITAL TRANSFORMATION PROJECT
In response to Sierra Leone's rapid digital transformation and the corresponding escalation in sophisticated cyber threats, this National Cybersecurity Skills Strategy and Action Plan has been meticulously formulated. Its central purpose is to cultivate a robust, highly skilled, and resilient national cybersecurity workforce. Commissioned by the National Cybersecurity Coordination Centre (NC3) with vital support from the World Bank, this strategy is the culmination of a comprehensive national workforce assessment and an extensive stakeholder consultation process. It identifies critical skills gaps, defines clear strategic objectives, and presents an actionable roadmap to position Sierra Leone as a competitive leader in the global cybersecurity market.
This strategy provides a comprehensive, forward-looking roadmap designed to fortify Sierra Leone's cybersecurity workforce and ecosystem. It is built upon a rigorous, evidence-based assessment of the existing skills landscape, including a detailed analysis of workforce supply and demand, competency gaps, and the distribution of talent across various sectors and demographics. The development process was deeply collaborative, engaging a wide array of stakeholders from government, the private sector, academia, civil society, and international partners to ensure a holistic, inclusive, and nationally-owned strategy. The document prioritizes the creation of a future-ready talent pipeline, the strengthening of educational pathways from primary to tertiary levels, the promotion of a vibrant and innovative domestic industry, and the fostering of a security-conscious culture across the nation.
Sierra Leone is navigating a significant phase of digital transformation, propelled by increasing internet connectivity and the expansion of digital services. The Government has demonstrated a clear commitment to digital resilience through the enactment of the Cyber Crime Act (2021) and the formation of the NC3. Despite these progressive steps, the country faces notable exposure to a wide spectrum of cyber threats, including data breaches, financial fraud, and potential attacks against critical infrastructure. These vulnerabilities, if inadequately addressed, pose substantial risks to public confidence, national security, and the sustainable advancement of Sierra Leone's digital economy.
The recent national assessment underscores a critical shortfall in cybersecurity professionals. The current workforce is primarily concentrated in select government agencies and large private sector organizations, with a significant void in small and medium-sized enterprises (SMEs) and rural communities. While most practitioners demonstrate foundational IT competencies, there is a substantial deficit in advanced expertise in areas like digital forensics, incident response, and secure software development.
The national workforce assessment and subsequent stakeholder consultations revealed several critical challenges that this strategy aims to address:
A severe shortage of qualified cybersecurity professionals exists across all sectors. Key specialized roles, such as Incident Responder and Threat Analyst, are largely absent, with most cybersecurity duties informally delegated to general IT staff who lack specialized training.
Existing training programs and certifications are not aligned with globally recognized frameworks like the National Initiative for Cybersecurity Education (NICE) or the European Cybersecurity Skills Framework (ECSF), hindering career progression and international competitiveness.
Cybersecurity concepts are not systematically integrated into formal education curricula at primary, secondary, or tertiary levels, resulting in low foundational awareness and a severely limited talent pipeline.
Women, youth, and individuals from rural communities are significantly underrepresented in the cybersecurity workforce, reflecting broader inequities in access to STEM education and professional opportunities.
The domestic cybersecurity industry remains in its early stages, characterized by constrained opportunities for research, innovation, local solution development, and entrepreneurship.
Despite legislative progress, efforts to build cyber resilience remain fragmented. Public and private sector entities exhibit low levels of specialized cyber hygiene knowledge, creating systemic vulnerabilities.
To position Sierra Leone as a leader in the global cybersecurity market, fostering a secure digital society, a thriving and innovative cybersecurity industry, and a resilient, inclusive workforce that supports national development and global competitiveness.
To build an inclusive, resilient, and future-ready cybersecurity ecosystem by integrating cybersecurity education at all levels, enhancing workforce capacity, promoting innovation, and ensuring broad-based participation across all demographic groups and geographic regions of Sierra Leone.
Systematically integrate comprehensive cybersecurity education across all levels of the national curriculum to build foundational awareness, digital citizenship, and technical competency from an early age.
Advance workforce capacity and professionalism through continuous development, upskilling, and accessible pathways to internationally benchmarked certification programs for both specialist and non-specialist personnel.
Foster the growth of a vibrant and self-sustaining local cybersecurity industry by actively promoting research, innovation, entrepreneurship, and the development of homegrown solutions.
Enhance public awareness and promote cybersecurity as a viable, attractive, and inclusive career path, with a dedicated focus on engaging and empowering women, youth, and other underrepresented groups.
Strengthen and expand multi-stakeholder partnerships and international collaborations to leverage global expertise, share best practices, mobilize resources, and ensure the long-term sustainability of the strategy.
A cornerstone of this strategy's development was the National Cybersecurity Skills Strategy and Action Plan Consultative Meeting, held on July 29, 2025, in Freetown. Organized by the NC3, this pivotal event brought together a diverse assembly of over 100 professionals from financial institutions, telecommunications companies, national security agencies, civil society organizations, academic institutions, and the media. The primary objective was to validate the findings of the national skills assessment, gather expert feedback, and build a collective consensus on the strategic path forward.
Figure 1: View of the National Cybersecurity Skills Strategy Consultative Meeting held in July 2025.
The dialogue and breakout sessions during the consultation provided invaluable insights, confirming the assessment's findings and adding crucial context. Key feedback themes included:
Stakeholders from all sectors strongly advocated for the adoption of international frameworks like NICE and ECSF to create national job standards. This was seen as essential for defining clear career pathways and aligning Sierra Leone with the global market.
Participants stressed the need for practical training through cybersecurity clubs, national hackathons, and robust internship programs to bridge the gap between theory and practice.
There was a strong consensus on the need to mandate key cybersecurity roles, particularly the Chief Information Security Officer (CISO), within all critical national infrastructure sectors to ensure accountability.
The private sector, particularly financial and telecommunications companies, expressed a strong willingness to collaborate on curriculum development, training initiatives, and resource sharing.
Civil society and media representatives emphasized the need for sustained, nationwide awareness campaigns that are culturally relevant and accessible in local languages to foster a society-wide culture of security.
The feedback from the consultative meeting has been systematically integrated into every pillar of this strategy, transforming it into a truly nationally-owned document. This direct stakeholder input ensures the strategy is relevant, practical, and addresses the most pressing needs of the nation.
This collaborative approach ensures that the strategy is not merely a top-down directive but a shared roadmap, built on the collective expertise and commitment of Sierra Leone's key stakeholders.
The strategy is built upon five interdependent pillars, complemented by cross-cutting themes, as identified in the national skills assessment and validated by stakeholders. This structure ensures a comprehensive, integrated, and holistic approach to building national cybersecurity capacity.
Guaranteeing equitable access to cybersecurity education and careers for all, irrespective of gender, age, location, or disability.
Promoting long-term development of national capacity through continuous learning and local ownership.
Fostering robust multi-stakeholder partnerships across government, academia, industry, and civil society.
Cultivating a dynamic culture of research, development, and entrepreneurship.
Upholding the highest international standards in education, training, and practice.
Ensuring the strategy remains flexible and responsive to the rapidly changing digital environment.
The strategy is structured around five key pillars and a set of integral cross-cutting themes:
Integrating cybersecurity into formal education, from primary to tertiary levels.
Reskilling and upskilling the current workforce and standardizing job roles.
Supporting entrepreneurship and the development of homegrown solutions.
Establishing robust policies, national standards, and governance structures.
Ensuring evidence-based tracking of progress, impact, and accountability.
Objective: To systematically integrate cybersecurity awareness and foundational competencies across all stages of the national education framework, from primary to tertiary levels, thereby cultivating a sustainable and diverse talent pipeline.
Objective: To strengthen the capabilities and competencies of both current and future professionals by implementing robust frameworks for continuous professional development, upskilling, and access to internationally benchmarked certification programs.
Objective: To cultivate a vibrant, innovative, and self-sustaining local cybersecurity industry, support entrepreneurship, and promote the development of homegrown solutions.
Objective: To establish and enforce a robust, agile, and comprehensive governance, policy, and regulatory framework that safeguards national critical infrastructure and promotes best practices.
Objective: To ensure the effective implementation, accountability, and continuous improvement of the National Cybersecurity Skills Strategy through a rigorous, transparent, and evidence-based M&E system.
To ensure the strategy is equitable and sustainable, a series of cross-cutting issues are integrated across all five pillars. These address systemic challenges fundamental to building an inclusive cybersecurity ecosystem.
Challenge: The national assessment revealed a stark gender disparity, with women constituting less than 20% of the cybersecurity workforce. This gap represents a significant loss of potential talent and perpetuates inequality.
Strategic Approach: A deliberate, multi-faceted strategy is required to dismantle barriers and actively promote women's participation. This includes:
Enacting policies that promote gender equality in STEM/ICT education and employment, in partnership with organizations like the 50/50 Group.
Developing scholarship programs specifically for women and girls pursuing cybersecurity degrees and certifications.
Establishing a national mentorship network connecting aspiring female professionals with established women leaders and launching a "Women in Cyber" campaign to showcase success stories.
Working with employers to adopt inclusive hiring practices, flexible work arrangements, and zero-tolerance policies for harassment.
Challenge: While Sierra Leone has a large, digitally-savvy youth population, there are limited structured pathways for them to transition from interest in technology to a professional career in cybersecurity.
Strategic Approach: Foster a vibrant ecosystem that captures the interest of young people from an early age and provides them with skills and opportunities. This includes:
Establishing and funding cybersecurity clubs in every secondary school and tertiary institution as hubs for practical learning and peer mentorship.
Organizing annual national events such as hackathons and "capture-the-flag" competitions to make learning engaging and identify top talent.
Developing a national, government-endorsed internship program that provides paid, hands-on work experience.
Supporting and funding youth-led organizations focused on digital literacy and cybersecurity awareness.
The Action Plan operationalizes the strategy through specific, time-bound, and measurable activities. It delineates clear responsibilities, timelines, and performance indicators, creating a pragmatic framework for implementation.
Successful implementation requires robust governance, clear accountability, and a phased approach to ensure momentum and long-term sustainability.
Clear governance structures will be established to ensure all stakeholders are aligned and responsible for delivering on their commitments:
The National Cybersecurity Coordination Centre (NC3) is designated as the lead agency, responsible for the overall coordination, day-to-day management, monitoring, and reporting of the strategy's implementation.
A multi-stakeholder Steering Committee, co-chaired by a high-level government official and a private sector representative, will be established. It will comprise representatives from key ministries, academia, the private sector, and civil society to provide high-level oversight, strategic direction, and ensure political and financial commitment.
Dedicated implementation teams, or Thematic Working Groups, will be formed for each strategic pillar. These teams will be responsible for the day-to-day execution of the action plan, data collection, and reporting to the NC3.
To operationalize the strategy effectively, the following phased roadmap with clear next steps is proposed:
The success of this strategy hinges on a collaborative, multi-stakeholder approach where each partner understands and fulfills their unique role. This ecosystem of shared responsibility is critical for building a sustainable national cybersecurity capacity.
Government ministries are the primary drivers of policy and regulation. Their role is to mainstream cybersecurity into national planning, allocate necessary budget, and create the enabling legal environment. The education ministries (MBSSE, MTHE) are directly responsible for curriculum reform and teacher training, while MoCTI provides the overarching technology policy direction.
As the lead coordinating body, the NC3 is the central hub for implementation. Its responsibilities include managing day-to-day activities, monitoring progress against KPIs, reporting to the Steering Committee, facilitating partnerships, and serving as the primary point of contact for all strategy-related matters.
Academic institutions are the engine of talent creation. Their role is to develop and deliver high-quality degree and certificate programs, conduct cutting-edge research, host innovation hubs, and collaborate with industry to ensure curricula remain relevant to market demands. They are also key partners in the "Train-the-Trainer" initiatives.
The private sector is both a key beneficiary and a critical partner. Its roles include providing industry expertise for curriculum development, offering internships and apprenticeships, co-funding training programs, sponsoring innovation challenges, and adopting best practices to secure their own operations. Industry leaders are expected to champion the strategy and serve on the National Cybersecurity Skills Council.
Civil society organizations and the media are essential for grassroots awareness and accountability. They will help disseminate information in local languages, advocate for inclusive policies (especially for gender, youth, and disability), and provide independent monitoring. International development partners like the World Bank provide crucial financial resources, technical expertise, and access to global best practices.
National Cybersecurity Skills Strategy and Action Plan