
This working paper uses the network security principle of subnetting as a conceptual framework to explain why Africa's regional cybersecurity governance is fragmented and underperforming.
It argues that Africa's regional blocs - ECOWAS, the East African Community, SADC, and the African Union function as distinct cybersecurity zones, each with its own legal frameworks and institutional capacity.
The paper diagnoses key failures including the limited ratification of the Malabo Convention and the absence of effective inter-regional incident response mechanisms.
It further argues that cyber diplomacy functions as the connecting protocol between these zones, but is only effective when the underlying institutional infrastructure is in place.
The paper proposes tiered compliance architectures calibrated to member states' actual capacity as a more realistic path to continental cybersecurity resilience.