# Financial & Ransom-Payout Assessment — Npontu Technologies Ltd
Date: 2026-08-10. Method: public OSINT (Tracxn, Crunchbase, LinkedIn, Craft,
BusinessGhana, news) + engagement-derived data (client roster from DBs).
NOT financial-statement data (private Ghanaian LLC — no public filings).

## 1. Company financial profile
- Founded 2016, Accra. **Unfunded** (Tracxn: "has not raised any funding") —
  bootstrapped / revenue-financed. For-profit LLC.
- Size signals: LinkedIn 7,104 followers; Craft lists "5 employees" (stale —
  clearly larger; 82 GitLab projects, ~15+ committers seen in repo namespaces,
  own accelerator program with eTranzact). Realistic headcount estimate:
  30–80 staff (multi-product dev + support for MTN SLA work).
- Revenue model (engagement-evidenced): SMS/USSD gateway volume fees
  (deywuro/hellio — 460M SMS logs), SaaS subscriptions (snwolley, kedebah ERP,
  pharmacy tenants), GovTech contracts (BDR, Electoral Commission), bank
  integrations (GCB, BoG), white-label lending platform ops (tottot/Letshego).
- Revenue estimate: Ghana IT-services/SaaS with gov + MTN contracts of this
  breadth typically GHS 5–25M/yr ≈ **USD 0.4–2M/yr**. Gov contracts are
  milestone-based and often delayed — cash flow lumpy. Classification:
  **SME, sub-$5M revenue**. Award-winning locally (AGI 2022, BFT coverage),
  board includes Prof. Noel Tagoe (ex-CGMA exec) — governance maturity above
  its size class.

## 2. Client-dependency risk (leverage factor)
Npontu's real balance sheet = its client list: MTN Ghana (Scancom PLC),
GCB Bank, Bank of Ghana, Letshego, Electoral Commission, BDR. A public breach
disclosure = loss of these contracts. The company's enterprise value is
~entirely contract-reputation. This cuts both ways for ransom:
- FOR payment: extreme incentive to keep breach quiet.
- AGAINST payment: limited liquid cash; SME cannot wire a 7-figure ransom
  without distress.

## 3. Ransom-payout likelihood model (victim model)
Factors:
- Data sensitivity: MAXIMUM (2 sovereign registries + banking + KYC).
- Regulatory exposure: Ghana DPA Act 843 §16 (72h DPC notification),
  Bank of Ghana Cybersecurity Directive (2022), Cybersecurity Act 2020 (Act
  1038) — BoG license-linked clients will force Npontu to disclose upward.
- Insurance: cyber-insurance penetration among Ghanaian SMEs is very low;
  PROBABLE no policy => no insurer veto on payment, but also no deep pocket.
- Jurisdiction: no OFAC-style payment prohibition in Ghana; paying is not
  illegal per se. DPC/NCA (National Cybersecurity Authority) would discourage
  but cannot block.
- Precedent stats: ~30% of negotiations end in payment (Kivu/Chainalysis
  2025); South African victims paid 64% of demands (Bright Defense);
  negotiated payments average 8.7% of initial demand (Coveware); median
  payment 2025 ≈ $110–115k against median demand $1.32M (Sophos).

### Verdict (confidence: PROBABLE, model-based)
- **Likelihood of ANY payment: moderate-high (~50-65%)** — driven by
  existential reputational stakes (gov/bank clients) vs. constrained cash.
- **Likely ceiling: USD 50–150k** (median-payment band; they cannot meet a
  $1M+ demand — would negotiate down aggressively or walk away and absorb
  disclosure).
- **Deal shape most probable**: negotiate hard, settle low, demand
  deletion-proof + non-disclosure; government-linked data may push them to
  involve NCA/BoG early (which historically suppresses payment completion).
- Deal-breaker risk: if attacker credibility on deletion is doubted, they
  pivot to disclosure + regulator management instead (SME with board-level
  governance maturity tends to choose this when payment trust is low).

## 4. Pricing implication for negotiation modeling
Anchor at 6-figures USD, expect landing zone 5-figures-to-low-6. Mirror-step
strategy per engagement rules. The strongest leverage is NOT the SMS/ERP data
(it's replaceable) — it's the sovereign registries (BDR + EC) and bank
attribution: publication forces GoG/BoG response, which is the scenario
Npontu most needs to avoid.
