News

Cybersecurity: CBN warns banks, fintechs against third-party technology risks

…says one incident could disrupt entire financial system

Central Bank of Nigeria (CBN) has cautioned banks, fintechs and other financial institutions against the growing cybersecurity and third-party technology risks associated with the increasing interconnectivity of the financial system.

  • …says one incident could disrupt entire financial system
  • ALSO READ:National Library issues 89,195 ISBNs, registers 272,172 users in five years — Anunobi

The apex bank warned that a vulnerability in one institution or technology provider could trigger wider disruptions across the financial ecosystem, urging financial institutions to strengthen safeguards beyond their individual organisations.

The CBN said the growing reliance on fintechs, payment service providers, cloud operators and other technology vendors had created additional channels through which cyber incidents could spread across the financial system.

ALSO READ:National Library issues 89,195 ISBNs, registers 272,172 users in five years — Anunobi

The Director, Payments System Supervision Department of the CBN and Chairperson of the Nigeria Electronic Fraud Forum, Dr Rakiya Opemi Yusuf, gave the warning on Wednesday during a panel session at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria in Abuja.

Speaking on the theme, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience,” Yusuf highlighted the implications of artificial intelligence, cyber threats and digital interconnectivity for Nigeria’s financial stability.

She warned that a weakness in one bank, fintech, payment service provider or technology vendor could spread to other interconnected institutions, creating what she described as a “one-fire” effect capable of disrupting the wider financial system.

Yusuf said financial institutions must regularly assess their dependencies, third-party relationships and technology providers to understand how a failure in one part of the ecosystem could affect their operations.

She said resilience should not be limited to preventing cyber incidents, but should also include the ability of institutions to continue providing critical services during disruptions and recover quickly after an incident.

The CBN director said the apex bank was strengthening its policies, regulations, supervisory frameworks and other measures to ensure that vulnerabilities capable of threatening financial stability were identified and addressed before they crystallised.

She added that systemic risk considerations were also being taken into account during the product approval process.

Yusuf urged financial institutions to extend their cybersecurity and risk-management responsibilities to third-party providers on which their operations increasingly depend.

She advised banks and other institutions to critically assess the resilience of their technology partners, including their capacity to withstand and recover from cyberattacks and major operational failures.

The CBN director also called for prompt reporting of cyber incidents and vulnerabilities, noting that timely disclosure would allow regulators to intervene before isolated incidents developed into broader systemic threats.

She stressed the importance of information and intelligence sharing among financial institutions, saying greater collaboration would enable the industry to identify emerging threats and strengthen its collective response.

Yusuf further advocated stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.

She urged financial institutions to strike a balance between innovation and accountability, stressing that increased automation must not eliminate human responsibility from financial decisions and processes.

The CBN director also called for stronger data governance and greater attention to digital sovereignty, urging institutions to examine where critical data is stored, who has access to it, what insights can be generated from it, and how such data influences decision-making.

She warned that placing critical data or technological capabilities beyond an institution’s effective control could expose it to additional risks.

Yusuf said the ultimate goal should be to build a financial ecosystem capable of absorbing shocks, containing cyber incidents and recovering rapidly without allowing the failure of a single institution or service provider to destabilise the wider system.