| Resource | Description | Link / Contact |
|---|---|---|
| CIS Controls v8 | Prioritized set of actions to protect against prevalent threats. | https://www.cisecurity.org/controls/ |
| NIST Cybersecurity Framework (CSF) | Guidance for building a resilient security program. | https://www.nist.gov/cyberframework |
| Somaliland ICT Authority – Cybersecurity Advisory (2025‑2026) | Official guidelines, reporting templates, and contact numbers. | +252 6 123 4567 (Hotline) |
| Open‑Source Incident Response Playbooks | GitHub repo with NIST‑aligned playbooks. | https://github.com/cisa/incident-response |
| Local Pen‑Testing Firms | • SecureSom (Hargeisa) – email: info@securesom.com
• HornTech Security (Berbera) – email: contact@horntech.so |
| MFA Solutions | Free options: Google Authenticator, Authy. Enterprise: Duo, YubiKey. | — |
| Control | Why It Matters | Quick Implementation Tip |
|---|---|---|
| Formal Security Policy | Sets expectations, defines roles, and creates accountability. | Draft a 5‑page “Information Security Charter” covering password policy, patching, and incident response. |
| Security Awareness Training | Human error is the most common breach vector. | Conduct a 30‑minute “Phishing & Password Hygiene” session quarterly for all staff. |
| Regular Pen‑Testing | Finds hidden weaknesses before attackers do. | Contract a regional security firm for a bi‑annual test; budget ≈ USD 10 k per test. |
| Incident‑Response Playbook | Reduces dwell time and limits damage. | Use the NIST 800‑61 framework; assign a primary and secondary responder. |
| Vendor & Supply‑Chain Vetting | Third‑party components can introduce risk. | Maintain a “trusted‑list” of libraries and enforce version lock‑files (e.g., npm package-lock.json). |
Date: April 2026
Author: [Your Name / Your Publication]
| Feature | Description |
|---|---|
| Core service | A hybrid mobile/web app that delivers localized news, weather, agricultural market prices, and community safety alerts. |
| Target audience | Rural traders, urban youth, NGOs, and local government units. |
| Tech stack (pre‑2024) | • Front‑end: React Native (Android & iOS)
• Back‑end: Node.js/Express API
• Database: MySQL (on‑premises)
• Hosting: Two on‑premise servers in Hargeisa + a small AWS EC2 instance for load‑balancing. |
| Data collected | Phone numbers, usernames, optional email addresses, location (city/region), and usage analytics. |
| Governance | Operated by Sharmuuto Ltd., a private Somali‑registered company, with informal data‑protection policies (no formal ISO 27001 or GDPR compliance at launch). |
Because the platform was widely trusted for real‑time market prices, it quickly became a critical information source for traders, especially in the livestock and agricultural sectors.
| Resource | Description | Link / Contact |
|---|---|---|
| CIS Controls v8 | Prioritized set of actions to protect against prevalent threats. | https://www.cisecurity.org/controls/ |
| NIST Cybersecurity Framework (CSF) | Guidance for building a resilient security program. | https://www.nist.gov/cyberframework |
| Somaliland ICT Authority – Cybersecurity Advisory (2025‑2026) | Official guidelines, reporting templates, and contact numbers. | +252 6 123 4567 (Hotline) |
| Open‑Source Incident Response Playbooks | GitHub repo with NIST‑aligned playbooks. | https://github.com/cisa/incident-response |
| Local Pen‑Testing Firms | • SecureSom (Hargeisa) – email: info@securesom.com
• HornTech Security (Berbera) – email: contact@horntech.so |
| MFA Solutions | Free options: Google Authenticator, Authy. Enterprise: Duo, YubiKey. | — |
| Control | Why It Matters | Quick Implementation Tip |
|---|---|---|
| Formal Security Policy | Sets expectations, defines roles, and creates accountability. | Draft a 5‑page “Information Security Charter” covering password policy, patching, and incident response. |
| Security Awareness Training | Human error is the most common breach vector. | Conduct a 30‑minute “Phishing & Password Hygiene” session quarterly for all staff. |
| Regular Pen‑Testing | Finds hidden weaknesses before attackers do. | Contract a regional security firm for a bi‑annual test; budget ≈ USD 10 k per test. |
| Incident‑Response Playbook | Reduces dwell time and limits damage. | Use the NIST 800‑61 framework; assign a primary and secondary responder. |
| Vendor & Supply‑Chain Vetting | Third‑party components can introduce risk. | Maintain a “trusted‑list” of libraries and enforce version lock‑files (e.g., npm package-lock.json). |
Date: April 2026
Author: [Your Name / Your Publication]
| Feature | Description |
|---|---|
| Core service | A hybrid mobile/web app that delivers localized news, weather, agricultural market prices, and community safety alerts. |
| Target audience | Rural traders, urban youth, NGOs, and local government units. |
| Tech stack (pre‑2024) | • Front‑end: React Native (Android & iOS)
• Back‑end: Node.js/Express API
• Database: MySQL (on‑premises)
• Hosting: Two on‑premise servers in Hargeisa + a small AWS EC2 instance for load‑balancing. |
| Data collected | Phone numbers, usernames, optional email addresses, location (city/region), and usage analytics. |
| Governance | Operated by Sharmuuto Ltd., a private Somali‑registered company, with informal data‑protection policies (no formal ISO 27001 or GDPR compliance at launch). |
Because the platform was widely trusted for real‑time market prices, it quickly became a critical information source for traders, especially in the livestock and agricultural sectors.