CBN warns banks, fintechs over cyber risks

Central Bank of Nigeria Warns of Cybersecurity Risks to Financial Stability
By Emma Ujah, Abuja Bureau Chief
ABUJA — The Central Bank of Nigeria (CBN) has issued a warning to banks, fintech companies, and other financial institutions regarding the critical importance of addressing cybersecurity and third-party technology risks. The bank emphasized that vulnerabilities within a single entity could lead to widespread disruptions across the entire financial system.
Dr. Rakiya Yusuf, Director of Payments System Supervision at the CBN and Chairperson of the Nigeria Electronic Fraud Forum (NeFF), made these remarks during the 19th Annual Banking and Finance Conference organized by the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.
In her keynote address titled “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience,” Yusuf noted that the increasing dependency of financial institutions on fintechs, payment service providers, cloud operators, and other technology vendors has introduced new channels for cyber and systemic risks.
She cautioned that weaknesses in any financial institution, including banks and fintechs, could quickly propagate through interconnected networks, potentially triggering a domino effect that threatens the stability of the financial system as a whole.
Yusuf called on financial institutions to shift their focus from merely securing internal systems to enhancing protective measures across the broader financial ecosystem. She recommended that institutions regularly evaluate their dependencies and relationships with third-party technology partners to understand how disruptions could impact their operations.
Operational resilience, Yusuf stressed, involves not only preventing cyberattacks but also maintaining essential services during disruptions and recovering swiftly from incidents. She revealed that the CBN is strengthening its regulatory framework and supervisory processes to preemptively identify and address vulnerabilities that could undermine financial stability.
In line with these efforts, she announced that considerations of cyber and operational risks would now be integrated into the product approval process to ensure that new financial products do not introduce systemic weaknesses.
Furthermore, Yusuf emphasized the need for financial institutions to extend cybersecurity and risk management oversight to third-party service providers. She urged banks to assess the capabilities of their technology partners to withstand and recover from cyberattacks and significant operational failures.
Prompt reporting of cyber incidents and vulnerabilities to regulators was another key point raised by Yusuf, who highlighted that early disclosures could facilitate timely interventions and prevent isolated breaches from escalating into systemic threats. She advocated for enhanced information sharing and collaboration among financial institutions to bolster their collective ability to detect emerging threats and coordinate responses.
To improve monitoring of cyber threats, Yusuf recommended the establishment of stronger Security Operations Centres (SOCs) that can provide real-time oversight across the financial ecosystem.
Regarding the growing use of artificial intelligence, she advised that innovation must be balanced with accountability. Yusuf asserted that while AI technology can perform increasingly complex tasks, human oversight remains essential in financial decision-making.
Additionally, she encouraged financial institutions to enhance data governance and pay attention to digital sovereignty by scrutinizing the locations of critical data, access permissions, and the implications of such data on decision-making processes. Yusuf warned that placing vital data or technological capabilities beyond an institution’s control could introduce further risks to the financial system.
In conclusion, Yusuf stressed the importance of a collaborative approach among regulators, banks, fintechs, payment service providers, and technology companies to safeguard Nigeria’s financial landscape. The aim should be to create a resilient ecosystem capable of absorbing shocks, managing cyber incidents effectively, and recovering without allowing the failure of any single institution to jeopardize overall stability.






