A 20-year security leader and co-inventor of an AI-driven breach-prevention system argues that the weakest link in national cyber defence is the firm that cannot afford to defend itself.
When attackers look for a way into a bank, a hospital network or a government agency, they rarely knock on the front door. They come through the side entrance: a supplier, a payroll contractor, a ten-person IT vendor with network access and no one watching the logs.
That side entrance is the problem Olumide Abiola has spent much of his career working to close. A cybersecurity leader with more than two decades in IT, cloud and infrastructure security across the financial and technology sectors, Abiola has focused on a question many in the industry treat as an afterthought: how do small and medium-sized enterprises defend themselves when the tools built to protect large organisations are priced far beyond their reach?
SME Priced out of protection
Abiola identifies two barriers that leave smaller firms exposed. The first is cost. A Security Information and Event Management (SIEM) platform, the core system organisations use to monitor activity and respond to threats in real time, runs costly yearly depending on scale and requirements. For a business with a thin margin and no dedicated security budget, that figure ends the conversation before it starts.
The second barrier is people. Even firms that buy the tools struggle to hire and keep the analysts needed to run them. Skilled security professionals are in short supply, and larger employers routinely outbid smaller ones.
The result, Abiola argues, is a two-tier landscape. Large organisations invest heavily in defence, while the smaller businesses connected to them through supply chains and shared data remain soft targets. Because those businesses touch payroll, healthcare records, logistics and public contracts, their exposure does not stay contained.
An invention built for the gap
Abiola’s response has taken the form of invention and practice. He is a co-inventor of the Dynamic Threat Intelligence and Response System Integrating AI, Machine Learning, and Human-Centric Security Awareness for Identifying and Preventing Data Breaches in Real-Time, registered in Nigeria under patent number NG/PT/NC/O/2025/19343 in 2025.
The patent describes one system doing the work that usually takes several. It gathers data from endpoints, networks, cloud services and user activity, and draws on more than 150 external threat feeds supplying 2 to 5 million threat indicators a day. A machine-learning core combines several model types, including convolutional and recurrent neural networks, random forests and deep reinforcement learning, to spot signs of attack. Behavioral analytics track more than 200 attributes for each user and device, so unusual activity stands out. The patent reports detection sensitivity of 97 per cent, with false positives held to roughly 2 per cent. He coauthored the work with other top leading professionals in the field including, Obah Tawo, Martins Awofadeju, Adepeju Adeyinka, Omolola Akinola.
Two features set it apart. The first is prediction: designed to warn organisations of likely threats 15 to 30 days ahead, rather than after a breach. The second is people. An awareness platform delivers short, personalised training matched to each employee’s learning profile, aiming to turn staff from the most common point of failure into an active line of defence. When a threat is confirmed, automated responses escalate through five graduated levels, from alerting to containment, in milliseconds.
Detection speed, unified architecture, the human factor and affordability for small businesses
“For years the industry has accepted that a breach can sit undetected for around 207 days. Olumide insisted from our first design session that detection be measured in minutes, not months. That standard came from two decades of seeing what slow detection costs real organisations.” Co-inventor Obah Tawo remarks on his impact on the project.
Most organisations run their intrusion detection, endpoint protection, SIEM and behaviour analytics as separate islands, and attackers move through the gaps between them. A well designed security monitoring experience is why the system correlates every signal in one place. Coinventor Adepeju Adeyinka explains that most breaches involve human error, yet conventional awareness training is forgotten almost as soon as it is delivered. People had to be designed into the system, not bolted on afterwards. The adaptive training layer exists because it was important not to separate technology from human behaviour.
“Small businesses cannot fund a round-the-clock security operations centre or hire the analysts to run one. Designing for a 60 to 75 per cent reduction in operating cost was the best way to tackle the problem” – Co-inventor Omolola Akinola.
On the practicality of this system, Martins Awofadeju clarifies that predictions are only useful if an organisation can act on it and justify that action. With the awareness on the importance of governance, risk and compliance meant every alert had to be explainable and tied to a response a business could defend to its board and regulators. That discipline is what turns an AI model into something organisations can trust.
For the businesses Olumide Abiola worries about most, the decisive figure is cost. According to the patent, the design cuts operating costs by 60 to 75 per cent compared with a traditional security operations centre, while detecting breaches in under five minutes. If those figures hold in real deployments, round-the-clock monitoring could come within reach of firms that today have none.
“Most organisations still fight cyber threats with tools that don’t talk to each other and training that people forget within weeks. This invention brings detection, prediction, response and human awareness into a single system, so that serious protection is no longer reserved for organisations that can afford a full security operations centre” – Olumide Abiola
Two decades at the intersection of security and business
Abiola’s perspective comes from years inside large, highly matrixed organisations where security decisions carry business consequences. He has led IT, cloud, infrastructure and security initiatives across cross-functional teams in leading banks in Canada, working alongside C-level executives to translate technical risk into business decisions.
His work spans security monitoring, threat and vulnerability management, identity and access management, logging and SIEM operations, IT general controls, and regulatory compliance including the EU’s General Data Protection Regulation. Today he also advises organisations as an independent IT and cybersecurity consultant.
He holds some of the field’s most demanding credentials, including CISSP, CISM, CRISC and CISA, alongside AWS Security Specialty and Solutions Architect Professional certifications, TOGAF 9, ITIL Expert and PMP. He is an active member of ISC2, ISACA and the Project Management Institute.
The ripple effect: when one specialist tackles a national problem hiding in small businesses.
It is easy to think of cybersecurity as a contest between large institutions and sophisticated adversaries. In practice, national resilience is only as strong as the many smaller organisations woven into every critical system. A breach at a regional supplier can halt a hospital’s operations; a compromised accounting firm can expose thousands of taxpayers’ records.
That is why practitioners like Abiola matter beyond their own clients. Each organisation that moves from no monitoring to real-time detection removes an entry point that could otherwise be used against the wider economy. Work that lowers the cost of serious defence, rather than simply adding another premium product to the market, changes who gets to be secure.
There is also a human dimension. Security that depends entirely on scarce specialists will always leave someone out. By pairing automated detection with training that makes ordinary employees part of the defence, Abiola’s approach treats people as a strength to be built rather than a weakness to be managed.
Looking ahead
Threats are getting faster, cheaper to launch and more automated. Abiola believes the defence has to follow the same path: intelligent, affordable and usable by organisations that will never have a 24-hour security operations centre.
If he is right, the most important advances in cybersecurity over the next decade may not be the ones that protect the largest institutions. They may be the ones that finally protect everyone else.



