Home » CBN Warns Banks, Fintechs Of Systemic Cyber Risk

CBN Warns Banks, Fintechs Of Systemic Cyber Risk

by StakeBridge
0 comments 4 minutes read

By Jennete Ugo Anya

 

The Central Bank of Nigeria (CBN) is warning that rising dependence on fintechs, payment service providers, cloud operators and other technology vendors is creating new channels through which a cyber incident at one institution could spread across the financial system.

The warning comes as Nigeria’s banking sector deepens its reliance on interconnected digital infrastructure and artificial intelligence.

DEVELOPMENT:
Dr Rakiya Yusuf, Director, Payments System Supervision at the CBN and Chairperson of the Nigeria Electronic Fraud Forum, gave the warning at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.

Speaking on ‘Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience,’ Dr Yusuf said that financial institutions could no longer treat cybersecurity as an internal technology issue.

She warned that a weakness in a bank, fintech, payment service provider or technology vendor could spread rapidly through interconnected institutions, creating what she described as a “one-fire” effect capable of destabilising the financial system.

Dr Yusuf urged financial institutions to assess not only their internal systems but also their dependencies, third-party relationships and technology partners.

She also said that operational resilience must go beyond preventing cyberattacks to ensuring that critical services can continue during disruptions and that institutions can recover quickly when incidents occur.

The CBN is strengthening its regulatory framework, supervisory processes and policy measures to identify vulnerabilities capable of threatening financial stability before they materialise. Cyber and operational risk considerations are also being integrated into the approval process for new financial products.

NUMBERS:
The warning does not provide financial-loss estimates or quantify the number of cyber incidents facing Nigeria’s financial system.

Its significance instead lies in the scale of interconnectedness across the ecosystem, involving:

  • Banks
  • Fintechs
  • Payment service providers
  • Cloud operators
  • Technology vendors
  • Regulators

The CBN is also recommending stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.

SIGNIFICANCE:
For financial-sector investors and operators, the regulatory message changes the definition of cyber risk from an institution-specific threat to a potential systemic risk.

A bank may have strong internal controls and still remain exposed through a technology provider, payment partner or cloud infrastructure on which its operations depend. The risk therefore sits increasingly across the financial value chain rather than within individual institutions.

This has implications for vendor due diligence, business continuity, technology procurement, product approval and regulatory compliance.

The CBN’s emphasis on third-party resilience also means financial institutions may need to scrutinise the ability of their technology partners to withstand attacks, maintain critical services and recover from operational failures.

Dr Yusuf called for prompt reporting of cyber incidents and vulnerabilities, as well as greater intelligence and information sharing among financial institutions.

NEXT MOVE:
The immediate issue for banks and fintechs is whether their risk frameworks adequately capture vulnerabilities outside their own technology environments.

Investors should watch how the CBN translates its warning into supervisory requirements, product-approval standards and expectations around third-party technology providers.

The development of stronger Security Operations Centres, mandatory or enhanced incident reporting, cybersecurity standards for vendors and greater information sharing could become increasingly important areas of regulatory focus.

The other major variable is artificial intelligence. Dr Yusuf cautioned that increased automation must not weaken accountability in financial decision-making.

She described the required approach as “automating accountability”, meaning AI can perform increasingly sophisticated tasks, but human oversight must remain central to decisions affecting customers and the financial system.

OUR LENS:
The deeper signal is that Nigeria’s digital financial infrastructure is becoming interconnected enough for technology risk to become balance-sheet and systemic risk.

The traditional cybersecurity model asks whether an individual institution is protected. The CBN is now asking a broader question: what happens when the institution itself is secure, but one of the critical entities connected to it fails?

That changes the investment and regulatory calculus. Third-party vendors, cloud infrastructure, payment rails and data systems are no longer peripheral technology considerations. They are components of financial infrastructure.

Dr Yusuf’s warning on digital sovereignty reinforces the point. Institutions must know where critical data are stored, who controls access, what intelligence can be extracted from the data and how that information influences decisions.

The emerging regulatory principle is therefore clear: financial resilience will increasingly depend on controlling the weakest links in the digital ecosystem, not merely strengthening the strongest institutions.

 

Jennete Ugo Anya is a journalist and researcher with interests across Nigeria’s economy, public policy, business, development and strategic communications.


Discover more from StakeBridge Media

Subscribe to get the latest posts sent to your email.

You may also like

Leave a Reply

At StakeBridge Media, we go beyond headlines to provide deep, actionable insights into the issues shaping Nigeria, Africa, and the global economy.

Newsletter

@2026 – StakeBridgeIRPR| All Rights Reserved. Designed and Developed by AuspiceWeb