GDN DESKTOP 1

Advertisement

CBN warns cyber breach in one institution could destabilise financial system

CBN Governor, Olayemi Cardoso

The Central Bank of Nigeria (CBN) has warned that a cybersecurity breach in a single bank, fintech, payment service provider or technology vendor could trigger wider disruption across the interconnected financial ecosystem.

The apex bank said financial institutions must move beyond protecting their individual organisations and begin treating cybersecurity, third-party technology risks and business continuity as issues of financial-system stability.

The Director, Payments System Supervision Department of the CBN and Chairperson of the Nigeria Electronic Fraud Forum, Dr Rakiya Opemi Yusuf, gave the warning yesterday during a panel session at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.

The session, ‘Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience,’ examined the implications of artificial intelligence, cyber threats and growing digital interconnectivity for Nigeria’s financial system.

Advertisement

Yusuf warned that increasing dependence on fintechs, payment service providers, cloud operators and other technology vendors was creating new channels through which cyber incidents could spread across the system.

She described the potential contagion as a ‘one-fire’ effect, where a weakness or failure in one part of the financial ecosystem could spread rapidly to interconnected institutions.

EFN Non Oil Export

According to her, financial institutions must therefore regularly map and assess their dependencies, third-party relationships and technology providers to understand how one entity’s failure could affect other parts of the ecosystem.

“It is no longer enough for an institution to say, ‘My organisation is protected.’ We have to look at the ecosystem,” she said, stressing the need for institutions to understand the risks posed by their interconnectedness.

Advertisement

Yusuf said resilience should also not be defined solely by the ability to prevent cyberattacks.

She explained that a resilient financial institution must be able to continue providing critical services during a disruption and recover quickly after an incident, even when preventive controls fail.

She said the CBN was strengthening its policies, regulations and supervisory frameworks to ensure that vulnerabilities capable of threatening financial stability were identified and addressed before they crystallised into systemic problems.

The apex bank, she added, was increasingly considering such risks at the product-approval stage, particularly as new financial products and services become more dependent on digital infrastructure and third-party technology.

Yusuf urged banks and other financial institutions to extend cybersecurity and risk-management responsibilities to their technology partners, rather than treating third-party providers as outside their risk perimeter.

She said institutions should critically examine the resilience of technology vendors, including their capacity to withstand cyberattacks, maintain essential services and recover from major operational failures.

The CBN director also called for prompt reporting of cyber incidents and vulnerabilities, warning that delays in reporting could give isolated breaches time to develop into broader threats.

She advocated greater intelligence and information sharing among financial institutions, saying collective awareness would strengthen the industry’s ability to detect emerging threats and coordinate responses.

Yusuf further called for stronger Security Operations Centres (SOCs) capable of monitoring threats across the financial ecosystem in real time, arguing that the growing sophistication of cyber threats required more proactive surveillance and faster responses.

On the effects of Artificial Intelligence on the financial landscape, Yusuf urged financial institutions to balance rapid technological innovation with accountability.

Advertisement

She said the increasing deployment of AI and automation must not remove human responsibility from financial decisions and processes.

She stressed that while machines could increasingly execute sophisticated functions, humans would remain responsible for the decisions and outcomes generated through financial services.

The CBN official also urged financial institutions to strengthen data governance and pay greater attention to digital sovereignty.

She said institutions needed to know where critical data was stored, who had access to it, what insights could be extracted from it and how those insights were being used to influence decisions.

According to her, dependence on critical data or technological capabilities that are effectively outside an institution’s control could introduce additional operational, regulatory and systemic risks.

She therefore called for a collective approach to resilience involving regulators, banks, fintechs, payment service providers and technology companies.

Yusuf said the ultimate objective should be to build a financial ecosystem capable of absorbing shocks, containing cyber incidents and recovering rapidly, without allowing the failure of a single institution or technology provider to destabilise the wider financial system.

Join Our Channels

Taboola Recommendation Widget