The Central Bank of Nigeria (CBN) has warned banks, fintech companies, payment service providers and other financial institutions that cybersecurity can no longer be treated as an internal technology concern, as vulnerabilities within one institution or technology provider could spread across the interconnected financial system and threaten financial stability.
The apex bank said the financial sector’s growing reliance on fintechs, payment companies, cloud service providers and other technology vendors had created an interconnected ecosystem where a cyberattack or major operational failure affecting one participant could have consequences for others.
The CBN therefore urged financial institutions to broaden their risk-management frameworks by assessing not only the security of their internal systems but also the resilience of third-party providers and technology partners supporting critical operations.
CBN raises concerns over third-party cyber risks
The Director of the CBN’s Payments System Supervision Department and Chairperson of the Nigeria Electronic Fraud Forum, Dr. Rakiya Opemi Yusuf, gave the warning on Wednesday at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.
Yusuf spoke during a panel session titled, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience.”
She said the increasing interconnectedness of Nigeria’s financial system meant that a cyber incident could rapidly extend beyond the institution where it originated.
According to her, a vulnerability in a bank, fintech, payment service provider or technology vendor could affect other institutions connected to it, producing what she described as a “one-fire” effect across the financial ecosystem.
The warning comes as financial institutions increasingly depend on external technology providers for critical services, including payment processing, cloud computing, data management and other digital operations.
The CBN said this dependence makes it essential for institutions to understand their exposure to third-party failures and ensure that technology providers supporting critical services have adequate systems to withstand and recover from major disruptions.
Yusuf urged institutions to regularly assess their dependencies and third-party relationships to determine how a failure in one part of the ecosystem could affect their own operations.
“Resilience is not just about preventing an incident. It is about the ability to continue delivering critical services during disruption and to recover quickly afterwards.”
CBN strengthens regulatory approach to cyber resilience
Yusuf said the central bank was strengthening its policies, regulations and supervisory frameworks to ensure vulnerabilities capable of affecting financial stability were identified and addressed before they developed into wider problems.
She disclosed that risk considerations were also being incorporated into the product-approval process, indicating that financial institutions would increasingly be expected to assess cyber and operational risks before launching new products rather than waiting for vulnerabilities to emerge after deployment.
Digital banking, electronic payments and other technology-driven services have improved the speed and convenience of financial transactions, but they have also expanded the number of potential entry points through which cybercriminals or system failures can disrupt institutions and affect customers.
The CBN is therefore pushing for cybersecurity to be viewed as part of broader financial system resilience rather than solely as an institution-level responsibility.
Yusuf urged financial institutions to subject their technology partners to closer scrutiny, including assessing their capacity to withstand cyberattacks and recover from serious operational disruptions.
She warned that strong internal controls alone may not be enough to protect an institution if an external provider responsible for a critical service is compromised.
A bank, fintech or payment company could still suffer a significant disruption if a technology partner experiences a cyberattack, system failure or other operational breakdown.
CBN calls for faster incident reporting and intelligence sharing
The CBN official also called for faster reporting of cyber incidents and vulnerabilities to regulators.
She said early reporting would enable authorities to intervene before an isolated incident spreads to connected institutions and develops into a broader systemic risk.
Yusuf also advocated greater intelligence and information sharing among financial institutions.
Rather than treating cyber threats as proprietary issues to be addressed individually, she said institutions should collaborate to identify emerging threats and strengthen the sector’s collective response.
She further called for stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.
Such monitoring capabilities, she said, would improve the ability of financial institutions and regulators to detect suspicious activity, identify emerging threats and respond before incidents cause wider disruption.
According to Yusuf, institutions must prepare not only to prevent cyberattacks but also to maintain critical services during disruptions and restore normal operations as quickly as possible.
AI adoption brings new accountability concerns
The CBN’s approach also extends to the rapidly expanding use of artificial intelligence across financial services.
While AI can automate processes, strengthen fraud detection and support faster decision-making, Yusuf warned that greater automation should not remove human responsibility from financial decisions.
She described the principle as “automating accountability”, meaning institutions can deploy technology to perform increasingly sophisticated functions while retaining clear human responsibility for the decisions and outcomes generated by those systems.
The principle could become increasingly relevant as banks and fintech companies deploy AI for lending, fraud monitoring, customer service, risk assessment and other financial activities.
Yusuf stressed that greater automation must therefore be accompanied by appropriate controls and clearly defined accountability, particularly as financial institutions become more dependent on interconnected technologies and external service providers.
Comments