The Central Bank of Nigeria (CBN) is tightening the screws on cybersecurity, and this time, it wants the industry to grade itself first.The Central Bank of Nigeria (CBN) is tightening the screws on cybersecurity, and this time, it wants the industry to grade itself first.

CBN gives banks 21 days to grade their cyber defences

2026/04/01 15:50
2 min read
For feedback or concerns regarding this content, please contact us at [email protected]

The Central Bank of Nigeria (CBN) is tightening the screws on cybersecurity, and this time, it wants the industry to grade itself first.

In a circular dated March 30, the CBN directed banks, fintechs, and other financial institutions to complete a new cybersecurity self-assessment tool (CSAT), a structured supervisory instrument designed to expose how prepared, or unprepared, they are for cyber threats.

Deposit money banks have three weeks to comply. Other financial institutions, including microfinance banks, payment service providers, payment service banks, finance companies, and development finance institutions, get five weeks.

The new directive is part of the regulator’s latest effort to strengthen Nigeria’s digital banking infrastructure against a surge in cyberattacks. 

According to Check Point Software Technologies, a cybersecurity platform provider, the Nigerian banking and financial sector recorded 4,718 weekly attacks in 2024.

Also, as instant payments continue to grow,  reaching ₦284.99 trillion ($185.66 billion) in the first quarter of 2025, the cyberattack surface has widened with money flowing through web, mobile apps, and agent networks.

Data from the Financial Institutions Training Centre (FITC) shows fraud losses jumped 603% year-on-year to ₦3.29 billion ($2.37 million) in Q1 2025, with more than 12,000 cases reported during the period.

The CBN’s latest move signals a shift from reactive enforcement to proactive surveillance, at a time when Nigeria’s financial system is becoming more digital and more vulnerable.

What the CBN is asking for

The CSAT goes deep into how institutions run their security and explores cybersecurity governance, who is accountable, and how seriously it is treated. It interrogates risk management frameworks, technology and third-party risks, incident response readiness, and overall operational resilience.

Insights from the CSAT, TechCabal learnt, are meant to support risk-based supervision and enhance regulatory oversight of cybersecurity risks across the financial system.

According to the CBN, all submissions must be fully completed and accompanied by relevant supporting documentation, where applicable, and the cut-off date for the data to be provided is December 31, 2025.

The CBN noted that all submissions must be accurate, complete, and verifiable. 

False or misleading data will attract sanctions, it stressed. 

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.4977
$0.4977$0.4977
+1.65%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity