A Nigerian company outsources a material operation to a provider in India or the United States. The contract is signed, the congratulatory emails circulate, and somebody announces “cost optimisation” at the next town hall. Six months later, nobody can explain which subcontractor holds the customer data, whose administrator can access production, or whether “the cloud” means Virginia, Mumbai or one heroic laptop under somebody’s desk.
This is where zero-trust architecture stops being cybersecurity grammar and becomes corporate survival.
Zero trust does not mean distrusting every overseas colleague. It means refusing to treat location, employment status, network connection or an expensive vendor logo as evidence of safety. The US National Institute of Standards and Technology defines zero trust around protecting resources rather than network boundaries, with no implicit trust granted merely because a person or device appears to be “inside” the organisation. Every access request must earn its legitimacy.
That principle becomes crucial when material operations cross borders. Outsourcing the work does not outsource accountability. If a Nigerian bank, fintech, insurer or telecommunications company transfers customer operations abroad, its board cannot respond to an incident by saying, “Our vendor handles that.” Regulators rarely accept the corporate equivalent of pointing at another child when the window breaks.
The architecture must begin with an inventory of reality. What services have been outsourced? What data supports them? Where is it stored, backed up and accessed? Which vendor personnel, service accounts, application programming interfaces and subcontractors can reach it? If management cannot draw the operational and data flows, it does not have zero trust. It has zero visibility.
Next comes identity. Every human and machine identity should be uniquely attributable, strongly authenticated and granted the minimum access required for the shortest practical period. Privileged access should be time-bound, approved and recorded. Shared administrator accounts such as “operations-admin” are convenient until an incident occurs and twelve people suddenly develop the same digital fingerprint.
Access decisions must also consider device health, workload behaviour, location, sensitivity and context. An authenticated engineer using an unmanaged device at 2.17 a.m. should not inherit the same permissions as a managed workstation performing an approved daytime task. Authentication answers, “Who are you?” Zero trust continues the interrogation: “Why are you here, what are you touching, and why are you downloading 40,000 customer records before breakfast?”
Data controls must travel with the data. Organisations need classification, encryption, tokenisation, loss-prevention rules, segmented environments and restrictions on copying or local storage. Production data should not wander into development environments simply because testing with invented customers feels inconvenient. Nigerian customers did not surrender their identities to become unpaid software testers in Bengaluru.
Cross-border processing adds a legal architecture to the technical one. The Nigeria Data Protection Act 2023 places conditions around international transfers and preserves the controller’s obligations. Contracts should therefore specify permitted locations, subprocessors, security standards, breach-notification periods, audit rights, deletion requirements and assistance with regulatory investigations. A transfer mechanism without operational verification is paperwork wearing a security uniform.
Resilience deserves equal attention. If the overseas provider fails, is attacked, changes ownership or suffers geopolitical disruption, can the Nigerian organisation continue operating? Critical services need tested recovery arrangements, alternative processes, usable backups and credible exit plans. A contract stating that data will be returned “upon termination” is not an exit strategy if the format is unusable and the only engineer who understands it has resigned.
Boards should therefore demand evidence, not reassurance: live access reports, privileged-session logs, control-testing results, incident exercises, concentration-risk analysis and confirmation that terminated vendor staff lose access promptly. Zero trust is not one product purchased by the chief information security officer. It is an operating model connecting technology, procurement, privacy, legal, resilience and board oversight.
Outsourcing can reduce cost and widen access to expertise. It can also stretch an organisation’s attack surface across companies, countries and time zones. The answer is not digital nationalism or theatrical suspicion. It is disciplined verification.
Trust your partners enough to work with them. Govern them well enough that trust is never your only control.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke








Building measurable, cost-reflective tariffs in state electricity markets (5)