
Sierra Leone is going digital and fast. Power grids, hospital records, school examination systems, and national security communications increasingly run on interconnected digital infrastructure. This has made public services faster and more efficient, but it has also created a new kind of vulnerability. When a system goes down today, whether through cyberattack, error, or simple power failure, the service stops immediately.
This is precisely why the Cyber Security and Crime Act 2021 designates critical national information infrastructure communications, banking, utilities, and emergency services as requiring mandatory protection.

To address this, the National Cyber Security Coordination Centre (NC3), and the Ministry of Communication, Technology and Innovation with support from the World Bank through the Sierra Leone Digital Transformation Project and technical support from KPMG, has developed draft Sector-Specific Critical Information Infrastructure (CII) Protection Plans for four priority sectors, Energy, Health, Education, and Defence and Security. These plans were presented for stakeholder validation at a workshop held on 26th August 2026 at the NatCA Tower, South Ridge, IMATT.

Each plan identifies the sector’s essential services, maps its specific risks and vulnerabilities, sets minimum cybersecurity baselines, and defines a governance structure showing exactly who is responsible for what, from national oversight down to the operators running the systems day to day. This builds on a first phase completed in 2025, which produced similar plans for the ICT, public administration, finance, and transport sectors.
None of these four sectors stand alone, and this is the central idea behind the entire project. The energy sector underpins the other three directly. Hospitals cannot function without power. Schools cannot run digital examination platforms without electricity and connectivity. Defence communications and surveillance systems depend on a stable power supply.
At the same time, energy itself depends on other sectors to function. It relies on the financial sector to process payments and salaries, on the ICT sector for the connectivity that supports metering and grid monitoring, and on the transport sector to move fuel from ports and depots to power stations and retail points nationwide. This is why the plans are being developed as a connected set, rather than in isolation. Failure in one system can just as easily show up as failure in another. But protecting critical infrastructure on a sector-by-sector basis only works if each sector is protected to a consistent standard and the sectors coordinate with each other when something goes wrong. The plans are directly relevant to every Sierra Leonean who depends on government services, because the plans exist to keep power flowing, records accessible, exams credible and security operations intact.

The plans will be validated with key stakeholders and presented to the Minister of Communication, Technology and Innovation, Madam Salima Monorma Bah, and subsequently to His Excellency Brigadier (Rtd.) Dr Julius Maada Bio for formal designation of these sectors under the Cyber Security Act. Once designated, operators will receive a defined timeline to implement the agreed cybersecurity baselines, with the National Cyber Security Coordination Centre providing implementation support. Compliance will then be monitored through regular audits, and operators found not to have implemented required baselines may face penalties, particularly where an unprotected system is later compromised.

The Sierra Leone Digital Transformation Project, led by the Ministry of Communication, Technology and Innovation, exists to connect more people, strengthen institutions, and deliver public services that genuinely work for citizens. The CII protection plan is not a separate undertaking from that agenda. The ministry’s investment in digital infrastructure is only as valuable as the protection built around it, and that is precisely the gap this project is designed to close.
