Nigeria’s rapid shift towards digital payments has created a financial ecosystem that is expanding faster than its ability to protect itself from cyber threats, cybersecurity expert Akinwumi Opeoluwa Ayodele, CISSP, has warned.
Ayodele said Nigeria’s cashless economy had moved beyond being a government policy ambition and had become the foundation of everyday economic activity, with billions of electronic transactions now flowing through the country’s financial infrastructure.
“Nigeria’s cashless economy is no longer a policy aspiration. It is the economy,” Ayodele said.
Data from the Central Bank of Nigeria showed that more than 22.4 billion electronic payment transactions worth about ₦1.56 quadrillion were recorded in the first half of 2024, highlighting the scale at which Nigerians are adopting digital channels for financial activities.
The Nigeria Inter-Bank Settlement System Plc, which operates the country’s major payment infrastructure, also reported that close to 11 billion transactions were processed through Nigeria’s real-time payment system in 2024.
According to Ayodele, the growth reflects the success of financial inclusion efforts, with digital platforms enabling faster movement of money and extending access to financial services across the country.
However, he warned that the same infrastructure driving payment growth has also expanded the potential entry points for cybercriminals.
“Every financial rail built to move money faster is also a rail an attacker can use,” he said.
The cybersecurity expert said Nigeria’s challenge was no longer whether digital finance would continue expanding, but whether the security and resilience of the ecosystem could develop at the same pace.
Fraud losses decline, but threats evolve
Nigeria’s financial industry has recorded progress in reducing payment fraud losses, suggesting that investments in monitoring, identity management and security controls are beginning to deliver results.
The Nigeria Inter-Bank Settlement System reported that digital payment fraud losses declined by 51 per cent in 2025, falling from ₦52.26bn to ₦25.85bn.
Ayodele said the decline was encouraging because it showed that coordinated industry action and stronger security measures could reduce exposure.
However, he cautioned that lower losses should not create a false sense of security, as cybercriminals were changing tactics.
“Fraudsters do not need to break through a bank’s strongest technical perimeter if they can compromise an agent, deceive a customer, exploit a privileged employee, abuse an API or compromise a weaker third-party provider,” he said.
The shift, he said, means that cybersecurity can no longer focus only on protecting banks’ internal systems but must extend across the wider financial ecosystem.
A decade ago, much of Nigeria’s financial activity was concentrated around banks and physical branches.
Today, consumers interact with a broader network of banks, fintech companies, payment processors, mobile-money operators, agent banking networks, USSD platforms, wallets, cloud providers and application programming interfaces.
Ayodele said financial inclusion had succeeded partly because it created more access points into the financial system, but each additional connection introduced another asset, identity or integration that required protection.
“The weakest link may no longer be the bank itself. It may be the ecosystem around the bank,” he said.
Agency banking, he noted, demonstrates both the opportunity and risk created by digital financial expansion.
POS terminals have become critical financial access points, allowing millions of Nigerians, particularly in communities underserved by traditional banking infrastructure, to access payment services.
However, the model also creates thousands of distributed endpoints that must be secured.
A compromised device, weak authentication process or insider collusion at the agent level could create losses that affect customers and financial institutions, Ayodele said.
The same challenge applies to APIs, which allow financial institutions and fintech companies to connect their services.
While APIs have improved speed and interoperability, weaknesses in authentication, excessive permissions, poor configurations or weak governance around integrations could create systemic risks.
Beyond technology failures, Ayodele said human behaviour remained one of the biggest challenges facing Nigeria’s digital financial ecosystem.
He said attackers increasingly relied on social engineering techniques rather than attempting to break through sophisticated technical systems.
NIBSS has identified social engineering and insider involvement among major fraud concerns, while phishing, account compromise and SIM-swap attacks continue to evolve.
Ayodele said security programmes that focus only on firewalls, endpoint protection and vulnerability scanning may fail to address attacks that begin with employees or customers being manipulated.
“Technology remains essential, but technology cannot compensate for weak identity governance, poor privileged-access controls, inadequate awareness, weak segregation of duties or insufficient monitoring of human behaviour,” he said.
Nigeria’s financial institutions operate under increasing regulatory requirements around cybersecurity, payments security, fraud management and operational resilience.
Ayodele said regulation was necessary but warned organisations against treating compliance as the final measure of security preparedness.
“A compliance certificate cannot stop an attacker. A policy cannot recover a payment platform. And a risk assessment that sits in a document repository cannot reassure customers during a live incident,” he said.
Instead, he argued that institutions should view regulation as a baseline while building stronger capabilities to anticipate, contain and recover from cyber incidents.
The key question, he said, should be whether organisations can maintain critical services and protect customer confidence during disruption.
Cybersecurity moves to boardroom agenda
Ayodele said cybersecurity should no longer be viewed solely as a technology department responsibility but as a business risk requiring board-level attention.
A major cyber incident at a bank or financial services company could trigger operational disruption, financial losses, regulatory consequences, data protection issues and reputational damage simultaneously.
In an interconnected financial ecosystem, he said, an incident affecting one institution could create consequences for customers and partners across the wider market.
Boards, he said, did not need to understand the technical details of every cyberattack but should be able to assess whether their organisations understood their most significant risks and had tested their ability to respond.
He identified four questions financial institutions should continuously address:
First, how many third parties, agents and APIs have access to customer funds or sensitive data, and are they governed under consistent security standards?
Second, are privileged identities and internal access monitored with the same attention given to external threats?
Third, if a major fraud incident or system outage occurred, how quickly could the organisation detect, contain, communicate and recover?
Fourth, has cyber risk appetite been translated into financial and business terms that executives and boards can evaluate?
Ayodele said cybersecurity investment should not be viewed as a barrier to innovation or financial inclusion.
Instead, he argued that security was necessary to sustain Nigeria’s digital finance expansion.
“It is tempting to see cybersecurity investment as a brake on the speed and convenience that have made Nigeria’s digital-payment ecosystem so successful. That is the wrong choice. Security is an enabler of sustainable growth,” he said.
He pointed to the Central Bank of Nigeria’s efforts to strengthen payment resilience, including measures aimed at improving terminal oversight and reducing dependence on single payment channels, as evidence that the industry was recognising the importance of resilience.
According to him, the goal should not be to create a financial system where attacks never occur, but one where attacks are harder to execute, losses are contained, critical services continue operating and recovery happens quickly enough to preserve public confidence.
Ayodele urged financial institutions to place cyber risk on enterprise risk registers alongside financial, operational and reputational risks.
He also called for institutions to measure cyber exposure in business terms, including potential financial losses, service disruption, customer impact and recovery time rather than relying only on technical severity scores.
He said third-party, agent and API risks should be treated as part of an institution’s own security responsibility because weaknesses among partners could become direct threats.
Institutions, he added, should test resilience through recovery exercises, crisis simulations and executive-level preparedness drills rather than relying only on documented policies.
“Speed to market is valuable, but avoidable security debt eventually becomes a business cost,” he said.
Nigeria has built one of Africa’s most dynamic digital financial ecosystems, Ayodele said, but protecting that growth requires recognising cybersecurity as a systemic business issue rather than an isolated technology challenge.
“The future of Nigeria’s cashless economy will not be determined only by how quickly we can move money. It will be determined by how confidently Nigerians can trust the rails moving that money,” he said.
“Cashless growth without cyber resilience creates fragility. Cashless growth with cyber resilience creates durable economic infrastructure.”
Follow Us on Google News
Follow Us on Google Discover