Conversations
The Lagos Instinct: How Abdullateef Tunde Abdulsalam Is Securing the UK's Cyber Supply Chain
From navigating infrastructure glitches in Nigeria to launching open-source tech in London, this cybersecurity analyst explains why his life's work is entirely free.

Decades of technical mergers, legacy networks, and rigid compliance layers leave even the most well-funded global financial institutions surprisingly fragile. While corporate giants pour millions into defensive perimeters, the small suppliers, community groups, and fintech startups feeding into their supply chains are often left out in the cold — shielding vital infrastructure with little more than spreadsheets and good intentions.
Abdullateef Tunde Abdulsalam is bridging this gap by building for the vulnerabilities nobody else is pricing for. By day, he works as a cybersecurity analyst inside a major UK financial institution. By night, he operates as the founder of Fa3Tech Limited, developing free, open-source security tools designed specifically for organisations that enterprise software budgets never intended to reach.
His unique strategic edge was forged in Lagos, Nigeria. Operating in an environment of tight resources and unpredictable infrastructure, Abdulsalam learned early on to analyse systems by how they actually behave under stress, rather than how they look on paper. That practical instinct crystallised into a lifelong calling in April 2012, when he watched an active threat actor infiltrate servers he had personally helped build at Starfish Mobile Nigeria Limited.
Today, that encounter drives a suite of live, technically serious open-source tools — including PrepIQ, DefenceIQ, and CertPulse — all released under a permissive Apache 2.0 licence to build collective resilience across the UK. Moving fluidly between practitioner and founder, Abdulsalam has brought his human-centered security perspectives to the University of Sunderland and the NatWest Accelerator network.
In this exclusive interview with Victor Ikoli, he sits down to discuss why cyber defence must become a shared public utility, the systemic infrastructure risks facing Nigeria's booming fintech ecosystem, and how the “Lagos instinct” continues to redefine his approach to global digital defence.
The Interview
Q.How did your early experiences in Lagos shape your current perspective on systems, problem-solving, and technology?
A.Lagos teaches you to improvise. Infrastructure fails, processes break down, and you either adapt fast or you don't get things done. Growing up and working there, I developed a habit of looking past how things are supposed to work and focusing on how they work — where the pressure points are, where the gaps live. That instinct has been directly useful in cybersecurity. The job is fundamentally about understanding systems under stress, and Lagos gave me an early education in that. I also came up in an environment where resources were limited and expectations were high. You learned to build with what you had. That's still how I approach product development today.
Q.When did cybersecurity become more than just a career path for you? Was there a defining moment?
A.April 2012. I was working in IT support and operations for Starfish Mobile Nigeria Limited, a value-added service provider in the telecoms sector. Our service revenue dropped sharply, and server utilisation spiked in a way that didn't make sense. Eventually, we established that a threat actor had gained unauthorised access to our infrastructure and was using it for their own purposes — running tools on our servers, quietly draining what we had built. That was the moment it became personal. You don't forget watching an adversary work inside something you helped build. I wanted to understand exactly how that happened, how it could be detected earlier, and how to stop it from happening again. That question has never really left me.
Q.What gap did you identify that led you to establish Fa3Tech Limited and begin building your own tools?
A.Working inside a regulated financial institution, I kept encountering smaller organisations — suppliers, partners, companies earlier in their journey — that had real security gaps and no realistic route to addressing them. The tools that exist are mostly built for enterprise budgets. A compliance platform that costs £40,000 a year is not accessible to a 20-person fintech, an NHS-adjacent supplier, or a community organisation. So those organisations either go without, or they manage with spreadsheets and good intentions. Fa3Tech exists to close that gap. Not by building cheaper versions of enterprise tools, but by building tools that are architecturally honest about who they're for. Free, open source, and designed from the ground up for organisations that don't have a dedicated security function. The founding insight was that cyber resilience in the UK is a collective infrastructure problem, not just a competitive advantage problem.
Q.Why was it important to you to make these tools free and open source, despite their commercial value?
A.Because the organisations that most need them are the ones least able to pay for them. That's not a sentiment — it's an observation from working in this sector for over six years in the UK. The cyber risk is not concentrated at large institutions. It's distributed across the whole supply chain, including the smallest links. Making these tools open-source means any organisation can adopt them, any developer can improve them, and any government or academic institution can audit them. The Apache 2.0 licence is deliberate — it allows commercial use, so organisations can build on the code without restriction. That's the outcome I want. Wide adoption, not revenue capture. The commercial case for open source is also real. If PrepIQ helps thousands of UK organisations improve their security posture, that has a positive effect on the whole ecosystem — including the large institutions and insurers who are downstream of those organisations in their supply chains.
Q.Nigeria's digital payments environment is fast expanding. What excites you most, and where do you see the greatest risks?
A.The scale of what's happened in a short time is genuinely remarkable. Nigeria has built one of the most dynamic payment ecosystems on the continent. Mobile money, fintechs like Flutterwave and Paystack, the eNaira experiment, and interbank infrastructure — the pace of change has been extraordinary, and millions of people who were previously excluded from formal financial services now have access. What excites me most is that the infrastructure is being built by people who understand the Nigerian context — the connectivity constraints, the trust dynamics, the regulatory environment. It's not a copy-paste of Western models. The greatest risks are at the infrastructure layer. The Remita breach allegations are instructive. When a single platform processes 90% of government payments and a threat actor claims to have extracted HSM keys and source code, that's a systemic risk to national financial infrastructure. The security investment needs to keep pace with the growth. It isn't yet.
Q.What lessons may Nigeria learn from more advanced financial systems such as the United Kingdom?
A.The UK's most valuable lesson is regulatory architecture. The FCA, PRA, and frameworks like DORA give institutions clear, enforceable standards with teeth. Nigeria's regulatory environment is maturing — the NDPA is a meaningful step — but enforcement consistency is still developing. Firms respond to incentives, and right now, the consequences for poor security practices are not yet severe enough to drive proactive, widespread investment.
About the author
Victor Ikoli writes long-form features for Vantage on identity, culture and the African diaspora.



