News
CBN Warns Cyberattack On One Financial Institution Could Trigger System-Wide Crisis
Central Bank of Nigeria (CBN), on Wednesday warned that cybersecurity could no longer be treated as an internal responsibility of individual banks, stressing that a vulnerability in one institution or technology provider can cascade through the country’s increasingly interconnected financial system.
CBN urged banks, fintechs, payment service providers, and other financial institutions to adopt a collective approach to cybersecurity, third-party technology risks, and business continuity to prevent isolated incidents from developing into threats to financial stability.
Director, Payments System Supervision Department of CBN/Chairperson, Nigeria Electronic Fraud Forum, Dr. Rakiya Opemi Yusuf, gave the warning during a panel session at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.
The session was titled, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience.”
It examined the growing exposure of the financial system to cyber threats, artificial intelligence, and technology-driven interconnectedness.
Yusuf said the increasing dependence of financial institutions on fintechs, payment service providers, cloud operators, and other technology vendors had created more pathways for the spread of operational failures and cyber incidents.
She stressed that a weakness in a bank, fintech, payment provider, or technology vendor could have consequences beyond the affected organisation, creating what she described as a “one-fire” effect across interconnected institutions.
According to her, financial institutions must consequently look beyond their own systems and understand the vulnerabilities embedded in their wider technology and service-provider networks.
Yusuf urged institutions to regularly assess their dependencies and third-party relationships, particularly the ability of technology partners to withstand cyberattacks, operational failures, and other disruptions.
She stressed that resilience should not be measured only by an institution’s ability to prevent an attack, but also by its capacity to maintain critical services during a disruption and restore normal operations within the shortest time possible.
She said CBN was responding to the emerging risks through stronger policies, regulations, and supervisory frameworks aimed at detecting vulnerabilities capable of threatening financial stability before they materialised.
The CBN director added that systemic-risk considerations were increasingly being incorporated into the approval of new financial products, reflecting the regulator’s focus on preventing vulnerabilities from being embedded in the financial system.
Yusuf also called for faster reporting of cyber incidents and vulnerabilities by financial institutions, stressing that early notification would give regulators and other stakeholders a better chance of containing threats before they spread.
She advocated stronger intelligence and information sharing across the industry, saying financial institutions can collectively respond to emerging threats more effectively if they shared relevant information on attacks, vulnerabilities, and evolving methods used by cybercriminals.
Yusuf equally pushed for stronger Security Operations Centres capable of providing real-time monitoring of threats across the financial ecosystem.
On the growing deployment of artificial intelligence in financial services, Yusuf cautioned institutions against allowing automation to weaken human responsibility.
She described the principle as “automating accountability”, stressing that while AI can increasingly undertake sophisticated functions, responsibility for decisions and their consequences must remain with humans.
The CBN official also highlighted the importance of data governance and digital sovereignty. She urged financial institutions to establish greater clarity over where critical data was stored, who could access it, what intelligence could be extracted from it, and how the resulting insights were used in decision-making.
She further cautioned that institutions could face additional vulnerabilities when critical data or technological capabilities were placed outside their effective control.
Yusuf said the financial sector must build resilience around the entire ecosystem rather than around individual institutions.
She called for closer coordination among regulators, banks, fintechs, payment service providers, and technology companies to identify interconnected risks and develop stronger mechanisms for containing disruptions.
The ultimate objective, she said, should be a financial system capable of absorbing shocks, containing cyber incidents, and recovering rapidly without allowing the failure of a single institution or service provider to destabilise the wider ecosystem.
Related











