Konga Wordkraft
Menu Close

Cybersafety: CBN warns banks, FinTechs and OFIs against third-party tech risks

*The Central Bank of Nigeria warns banks, FinTechs, and Other Financial Institutions against the growing cybersecurity and third-party tech risks associated with the increasing interconnectivity of the financial system, stating an incident could disrupt the entire financial system

Alexander Davis | ConsumerConnect

In line with its consumer sensation and protection mandate, the Central Bank of Nigeria (CBN) has cautioned banks, Financial Technologies (FinTechs), and Other Financial Institutions (OFIs) against the growing cybersecurity and third-party tech risks associated with the increasing interconnectivity of the financial system.

The CBN cautioned that a vulnerability in an institution, or technology provider could trigger wider disruptions across the financial ecosystem in the the country.

UK invests in 68 Nigerian future leaders through Chevening and Commonwealth Scholarships

The Bankers’ Bank also urged financial institutions to strengthen safeguards beyond their respective organisations.

The Bank explained that the growing reliance on FinTechs, payment service providers, cloud operators, and other technology vendors has created additional channels through which cyber incidents could spread across the financial system.

ConsumerConnect reports Dr. Rakiya Opemi Yusuf, Director of Payments System Supervision Department of CBN and Chairperson of the Nigeria Electronic Fraud Forum, issued the warning Wednesday, September 9, 2026, during a panel session at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN), in Abuja, FCT.

Yusuf spoke on the theme, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience”.

The Director of Payments System Supervision Department also highlighted the implications of Artificial Intelligence, cyberthreats, and digital interconnectivity for financial stability in the Nigerian economy.

She equally warned stakeholders that an incident in a bank, FinTech, payment service provider or technology vendor could spread to other interconnected institutions, creating what she described as a “one-fire” effect capable of disrupting the wider financial ecosystem.

What banks, FinTechs, others must do: Official

Yusuf said financial institutions must regularly assess their dependencies, third-party relationships and technology providers to understand how a failure in one part of the ecosystem could affect their operations.

Yusuf minted resilience should not be limited to preventing cyber incidents, but should also include the ability of institutions to continue providing critical services during disruptions and recover quickly after an incident.

The Director of Payments System Supervision Department disclosed the banking sector regulator is strengthening its policies, regulations, supervisory frameworks, and other measures to ensure that vulnerabilities capable of threatening financial stability were identified and addressed before they crystallised.

Systemic risk considerations are also being taken into account during the product approval process.

Expanded cybersecurity, risk-management responsibilities

Yusuf urged financial institutions to extend their cybersecurity and risk-management responsibilities to third-party providers on which their operations increasingly depend.

She urged banks, and Other Financial Institutions to critically assess the resilience of their technology partners, including their capacity to withstand and recover from cyberattacks and major operational failures.

The Director at CBN advocated prompt reporting of cyber incidents and vulnerabilities.

According to her, timely disclosure would allow regulators to intervene before isolated incidents developed into broader systemic threats.

She as well emphasised the strategic importance of information and intelligence sharing among financial institutions.

saying greater collaboration would enable the industry to identify emerging threats and strengthen its collective response.

Yusuf further urged stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.

She urged financial institutions to strike a balance between innovation and accountability, stressing that increased automation must not eliminate human responsibility from financial decisions and processes.

Yusuf called for stronger data governance and greater attention to digital sovereignty, urging institutions to examine where critical data is stored, who has access to it, what insights can be generated from it, and how such data influences decision-making.

The banking sector regulator warned that placing critical data or technological capabilities beyond an institution’s effective control could expose it to additional risks.

Yusuf said the ultimate goal should be to build a financial ecosystem capable of absorbing shocks, containing cyber incidents and recovering rapidly without allowing the failure of a single institution or service provider to destabilise the wider system.

 

Leave a Reply

Your email address will not be published. Required fields are marked *