Africa Cyber Exercise Programme

AfCyberEx
PATCH

Prepare → Attack → Teardown → Change → Harden. A continuous capability cycle that transforms exercise findings into verified improvements in African cybersecurity practice.

Background

From an annual drill to a continuous exercise programme

AfCyberEx PATCH, formerly the Africa Cyber Drill, convenes national and sectoral CSIRTs, ministries, regulators, central banks, operators, law enforcement, prosecutorial authorities, academia and other institutions responsible for cybersecurity incidents.

Multi-stakeholder

Participation has expanded

The programme tests technical response alongside operational, legal, regulatory and strategic coordination.

Across editions

Capability grows over time

Lessons are translated into tracked change registers, revised playbooks and verified actions.

Continuous learning

The hardest gains are behavioural

PATCH identifies assumptions, habits and procedures that must stop, change or be verified.

Methodology

The PATCH capability cycle

PATCH applies vulnerability-management logic to the human and organisational layer. Technical patching fixes code; PATCH fixes practice.

PhaseLearning functionPrimary output
PrepareLearnDocumented baseline and stated assumptions.
AttackPracticeAuthentic performance data under pressure.
TeardownUnlearnNamed practices, assumptions and dependencies to improve or retire.
ChangeRelearnA change register with owners and deadlines.
HardenVerifyConfirmed remediation and a new baseline.
Objectives

Build readiness that can be demonstrated

  • Test incident detection, response and recovery against realistic regional scenarios.
  • Strengthen communication among CSIRTs, regulators, operators, law enforcement and prosecutors.
  • Retire outdated assumptions, procedures and dependencies.
  • Produce and verify an owned change register for every participating team.
  • Improve the legal, regulatory and policy interface with technical response.
Explore

AfricaCERT programmes and archives

Past Editions

Review AfricaCERT Cyberdrill and CTF editions and access their official press releases.

Explore Past Editions

AfricaCERT@AIS

Discover cybersecurity training, drills and CTF activities delivered during the Africa Internet Summit.

Explore AIS Activities

NextGenInCyber

Learn about the pathway for students and early-career professionals building Africa’s cybersecurity future.

Read the Programme

OtherExercices

Access additional practical challenges and specialised AfricaCERT cybersecurity exercises.

View Other Exercises
Concept Note

AfCyberEx — The PATCH Framework

Prepare → Attack → Teardown → Change → Harden
Africa Cyber Exercise Programme — formerly the Africa Cyber Drill.

1. Background

AfCyberEx PATCH targets participants from the Af* community, national and sectoral CSIRTs, government ministries, national regulatory authorities, central banks, ICT implementing agencies, operators, law-enforcement organisations, offices of attorneys general, academia and other stakeholders dealing with cybersecurity incidents.

Cyber drills are a critical capacity-building platform. They strengthen communication, cooperation and regional preparedness through practical exercises. Over time, the Africa Cyber Drills have become a regional platform for operational learning, information sharing and discussion of cybersecurity challenges.

2. Rationale for the transition

Participation has outgrown the label

AfCyberEx better describes a multi-stakeholder exercise programme than a purely technical drill.

Capability is built across editions

The methodology makes the translation of lessons into operational change an explicit, tracked deliverable.

The hardest gains require continuous learning

PATCH identifies what must change, assigns ownership and verifies that remediation worked.

3. Methodology

Scenarios are drawn from incidents observed in the region and are designed so that no single track can resolve them alone. Delivery may be in person, remote or hybrid using a dedicated exercise range and out-of-band communication channels.

TrackContentPrimary audience
TechnicalIncident handling, forensics, malware analysis, network defence and CTF challenges.Analysts, engineers, operators and academia.
OperationalEscalation, coordination, resource allocation and continuity.CSIRT management, ICT agencies and operators.
Legal & RegulatoryNotification, evidence, jurisdiction and cross-border cooperation.Regulators, law enforcement, AG offices and central banks.
StrategicCrisis communication, executive decisions and public messaging.Ministries and senior management.

4. Expected outcomes

  • Documented evidence of incident-response performance.
  • A change register with named owners and deadlines.
  • Formal retirement of outdated assumptions and procedures.
  • Corrected communication channels and points of contact.
  • Regional findings that inform policy and future editions.
  • Stronger trust through shared operational experience.

5. Indicators of success

IndicatorMeasure
Detection and response performanceReduction in time to detect, contain and recover between editions.
Change completionProportion of change-register items verified during Harden.
RecurrenceRate at which previously identified failures reappear.
Scenario toleranceIncrease in complexity sustained at stable performance.
CoordinationTime to establish contact and share actionable information.
CoverageNumber and diversity of institutions and countries represented.