Vantage
All Stories

Conversations

The Lagos Instinct: How Abdullateef Tunde Abdulsalam Is Securing the UK's Cyber Supply Chain

From navigating infrastructure glitches in Nigeria to launching open-source tech in London, this cybersecurity analyst explains why his life's work is entirely free.

By Victor IkoliJuly 20262 min read
The Lagos Instinct: How Abdullateef Tunde Abdulsalam Is Securing the UK's Cyber Supply Chain
Abdullateef Tunde Abdulsalam, cybersecurity analyst and founder of Fa3Tech Limited.

Big banks spend a fortune on security. The small firms plugged into them — the suppliers, the community outfits, the two-year-old fintechs — usually don't. They get by on spreadsheets and hope, and they are sitting inside the same supply chain.

Abdullateef Tunde Abdulsalam works on that gap. By day he is a cybersecurity analyst inside a large UK financial institution. The rest of the time he runs Fa3Tech Limited, building free, open-source security tools for organisations no enterprise vendor is going to call back.

He learned the habit in Lagos. When the power and the network can go at any moment, you stop reading systems the way the documentation describes them and start watching what they actually do. In April 2012 that turned into something more serious: he watched an attacker moving around inside servers he had helped build at Starfish Mobile Nigeria Limited.

Out of that came the tools he ships now — PrepIQ, DefenceIQ, CertPulse — all under an Apache 2.0 licence so anyone can take them and use them. He has also taken the same argument to the University of Sunderland and the NatWest Accelerator network.

He spoke to Victor Ikoli about why he thinks cyber defence should be treated as public plumbing, what worries him about Nigeria's payments boom, and what Lagos still teaches him.

The Interview

Q.How did your early experiences in Lagos shape your current perspective on systems, problem-solving, and technology?

A.Lagos teaches you to improvise. Things fail. Processes break. You either work around it or nothing gets done. So I picked up the habit of ignoring how a system is meant to work and watching what it actually does — where it strains, where the holes are. That has been useful in security, because security is mostly systems under stress. And we didn't have money for the proper kit, but people still expected results, so you built with what was in front of you. I still work that way.

Q.When did cybersecurity become more than just a career path for you? Was there a defining moment?

A.April 2012. I was in IT support and operations at Starfish Mobile Nigeria Limited, a value-added service provider in telecoms. Revenue dropped off a cliff and server usage went up, which made no sense. Turned out someone had got into our infrastructure and was running their own tools on our servers. That is when it stopped being a job. You don't forget watching somebody work inside a thing you built. I wanted to know how they got in, how we could have spotted it sooner, and how to stop it happening again. I'm still on that question.

Q.What gap did you identify that led you to establish Fa3Tech Limited and begin building your own tools?

A.Inside a regulated bank you keep meeting the smaller outfits around it — suppliers, partners, young companies — and they have real problems and no way to fix them. The tools are priced for enterprises. A compliance platform at forty thousand a year is not happening for a twenty-person fintech or a community organisation. So they go without, or they use a spreadsheet. Fa3Tech is for those people. Not a cheap version of an enterprise product, something actually built for a place with no security team. Free, open source. The point is that UK cyber resilience is shared infrastructure. It isn't a competition.

Q.Why was it important to you to make these tools free and open source, despite their commercial value?

A.Because the ones who need them most can't pay. I'm not being sentimental about it, it's what I've seen in six years here. The risk isn't sitting neatly at the big institutions, it's spread down the chain to the smallest supplier. Open source means anyone can pick it up, anyone can improve it, and a government or a university can look at the code and check it. The Apache licence is on purpose — people can build commercially on top of it, no restrictions. I'd rather have wide use than revenue. And honestly it pays off anyway. If PrepIQ tightens up a few thousand UK organisations, the big banks and insurers downstream of them feel that too.

Q.Nigeria's digital payments environment is fast expanding. What excites you most, and where do you see the greatest risks?

A.What has happened in a few years is remarkable. Mobile money, Flutterwave, Paystack, the eNaira, the interbank rails — millions of people who had no access to formal finance now do. And it was built by people who understand the place: the connectivity, the trust issues, the regulator. It isn't copied from the West. The risk is underneath all of it. Look at the Remita allegations. One platform handles about 90% of government payments, and someone claims to have taken HSM keys and source code. That is national infrastructure. The security spend hasn't kept up with the growth. Not yet.

Q.What lessons may Nigeria learn from more advanced financial systems such as the United Kingdom?

A.Mostly the regulation. The FCA, the PRA, something like DORA — clear rules with consequences attached. Nigeria is getting there, the NDPA matters, but enforcement is still uneven. Firms do what they're pushed to do, and right now getting security wrong doesn't hurt enough to make everyone move.

About the author

Victor Ikoli writes long-form features for Vantage on identity, culture and the African diaspora.

More from Vantage

All stories
Vantage

© 2026 Vantage Media. All rights reserved.