By Osman Omar
Somalia’s growing dependence on used and refurbished laptops is driven by a simple economic cause: new computers are expensive, while students, businesses and public institutions urgently need affordable access to technology. The immediate effect is a rapidly expanding market for second-hand devices whose origins, previous owners and repair histories are often unknown.
That lack of traceability creates a cybersecurity weakness. A refurbished laptop may contain outdated drivers, an altered operating system or unauthorized programs installed by a previous owner or seller. Most such problems may result from poor maintenance rather than deliberate wrongdoing. However, when the device’s history cannot be verified, users cannot confidently determine whether the software was merely neglected or intentionally modified.
One important warning sign is Windows Memory Integrity, found under Windows Security → Device Security → Core Isolation. This protection prevents untrusted code from interfering with critical parts of the operating system. If it cannot be activated, the cause may be an outdated or incompatible driver—not necessarily malware. Nevertheless, the failure should trigger further inspection, particularly before the computer is connected to a university, company or government network. Microsoft’s Memory Integrity guidance
The danger becomes far greater if a criminal or hostile group deliberately distributes laptops containing spyware, keyloggers or remote-access software. Once such a device connects to Wi-Fi, the malware could record passwords and documents, monitor activity on the laptop, scan the local network and attempt to access shared systems. The compromised laptop would effectively become a hidden doorway through which an outside operator could enter a larger digital environment.
This does not mean that one infected laptop can automatically read every encrypted communication passing through a router. However, it may capture poorly protected traffic, identify other connected devices or steal credentials that provide access to additional systems. One compromised endpoint can therefore produce a chain reaction: initial access leads to credential theft, credential theft leads to wider network access, and wider access can lead to surveillance, disruption or large-scale data loss.
The institutional consequences could be severe. At a university, malware could expose student records, examination materials, research and confidential survey responses—including information about students’ political or social opinions. Inside a government institution, it could compromise official communications, citizen records, passwords and internal decision-making systems. In a private company, the result could be stolen financial records, customer information and control of important accounts.
The broader effect would extend beyond the affected organization. Repeated incidents could weaken public confidence in digital government services, banking systems, universities and Somalia’s developing technology sector. What initially appears to be a cheap laptop could ultimately impose enormous financial, institutional and national-security costs.
Somalia should therefore treat imported refurbished computers as a cybersecurity supply-chain issue. This does not mean accusing every importer or seller. It means recognizing that international cybersecurity authorities identify tampering and the insertion of unauthorized software or hardware as genuine supply-chain threats. NIST cybersecurity supply-chain guidance
The Federal Government should require commercial importers and institutional suppliers to disclose where their devices originated, identify the refurbishing company and maintain serial-number records. Government agencies, universities, banks and telecommunications companies should not connect newly purchased second-hand computers to sensitive networks until trained technicians have inspected them.

Every refurbished laptop should have its existing storage completely erased before use. Windows should be freshly installed through Microsoft’s official installation media or Cloud Download service—not through an unknown recovery image supplied with the computer. Drivers and BIOS or UEFI firmware should then be updated from the manufacturer’s official website. Secure Boot, TPM, Memory Integrity, Microsoft Defender, the firewall and disk encryption should be enabled wherever the hardware supports them.
Apple computers should be erased and have macOS reinstalled through Apple’s official Recovery system. iOS is an operating system for iPhones and cannot be installed on an ordinary laptop. Linux may be installed from a verified official distribution, but simply changing operating systems does not guarantee the removal of sophisticated threats hidden in firmware or hardware.
A clean installation will remove most software-based malware, but a highly suspicious device intended for government, military, financial or university use should undergo professional examination—or be rejected entirely. Somalia’s digital future should not be built on computers whose origins and security cannot be trusted. When the device is compromised, the laptop is not the product; the user’s information is.





