CBN warns banks, fintechs over cyber attacks

The Central Bank of Nigeria (CBN), has warned banks, fintech companies, payment service providers and other financial institutions that cybersecurity can no longer be treated as an internal technology problem, saying a weakness in one institution or technology provider could spread across the interconnected financial system and threaten financial stability.

The apex bank said the growing dependence of financial institutions on fintechs, payment companies, cloud service providers and other technology vendors had created a network in which a cyber-attack or major operational failure affecting one participant could have consequences for others.

The CBN therefore urged financial institutions to widen their risk-management approach by examining not only the security of their own systems but also the resilience of the third parties and technology providers on which their businesses depend.

The Director, Payments System Supervision Department of the CBN and Chairperson of the Nigeria Electronic Fraud Forum, Dr. Rakiya Opemi Yusuf, gave the warning on Wednesday at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.

Yusuf spoke during a panel session titled, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience.”

She said the increasing interconnectedness of Nigeria’s financial system meant that a cyber incident could quickly move beyond the institution where it started.

Nigeria News Subscription

According to her, a weakness in a bank, fintech, payment service provider or technology vendor could affect other institutions connected to it, creating what she described as a “one-fire” effect across the financial ecosystem.

The warning comes as financial institutions increasingly rely on external technology providers for critical services, including payments, cloud computing, data management and other digital operations.

This growing dependence, according to the CBN, means that institutions must understand their exposure to third-party failures and ensure that the companies providing critical technology services have adequate systems to withstand and recover from major disruptions.

Yusuf said institutions should regularly examine their dependencies and third-party relationships to determine how a failure in one part of the ecosystem could affect their own operations.

She said, “Resilience is not just about preventing an incident. It is about the ability to continue delivering critical services during disruption and to recover quickly afterwards.”

The CBN director said the central bank was strengthening its policies, regulations and supervisory frameworks to ensure that vulnerabilities capable of affecting financial stability were detected and dealt with before they became larger problems.

She disclosed that risk considerations were also being taken into account at the product-approval stage, suggesting that institutions would need to consider cyber and operational risks before new financial products are introduced rather than waiting until vulnerabilities emerge after deployment.

Digital banking, electronic payments and other technology-driven services have increased the speed and convenience of financial transactions, but they have also created more points through which criminals or system failures can affect financial institutions and their customers.

The CBN is now calling for a broader approach in which cybersecurity is considered part of the stability of the entire financial system.

Yusuf urged financial institutions to subject their technology partners to closer scrutiny, including examining their ability to withstand cyberattacks and recover from serious operational failures.

She said financial institutions could not afford to assume that their systems were safe simply because their own internal controls were strong.

A bank, fintech or payment company could still experience a major disruption if an external provider supporting a critical service suffered a cyberattack, system failure or other operational breakdown.

The CBN official also called for faster reporting of cyber incidents and vulnerabilities to regulators.

She said early reporting would give the authorities an opportunity to intervene before an isolated incident spreads to other institutions and develops into a wider systemic problem.

Yusuf also called for greater intelligence and information sharing among financial institutions.

Rather than treating cyber threats as proprietary problems that should be handled individually, she said institutions needed to work together to identify emerging threats and strengthen the industry’s collective response.

She also advocated stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.

Such monitoring systems, she said, would improve the ability of institutions and regulators to detect suspicious activity, identify emerging threats and respond before incidents cause wider disruption.

Yusuf said institutions must be prepared not only to prevent attacks but also to continue providing critical services when disruptions occur and restore normal operations as quickly as possible.

The CBN’s approach also extends to the rapidly growing use of artificial intelligence in financial services.

While AI can automate processes, improve fraud detection and support faster decision-making, Yusuf warned that automation should not remove human responsibility from financial decisions.

She described the principle as “automating accountability”, meaning that institutions can use technology to perform sophisticated functions but must still maintain clear human responsibility for the decisions and outcomes produced by those systems.

The position could become increasingly important as banks and fintech companies deploy AI for lending, fraud monitoring, customer service, risk assessment and other financial functions.

According to Yusuf, greater automation must therefore be matched with adequate controls and clear accountability.

Financial institutions, she said, must know who remains responsible when an automated system makes a decision that affects customers or the institution itself.

The CBN official also raised concerns about data governance and digital sovereignty, urging financial institutions to pay greater attention to where their critical data is stored, who can access it and how the information is being used.

She said institutions should also understand what insights can be generated from their data and how those insights influence financial decisions.

The concern is that institutions could expose themselves to additional risks if critical data or technological capabilities are placed outside their effective control.

The CBN is asking financial institutions to understand their entire technology ecosystem rather than concentrating solely on their internal networks.

The approach places greater responsibility on institutions to examine the security and resilience of vendors that provide critical services.

For fintechs and payment service providers, the message is equally important because their platforms are increasingly integrated with banks and other financial institutions.

A weakness in one technology platform could therefore create problems for several institutions that depend on it.

The same principle applies to cloud service providers and other technology companies that support financial operations.

Yusuf said the financial sector must adopt a collective approach to resilience involving regulators, banks, fintechs, payment service providers and technology companies.

The objective, she said, should be to create a financial ecosystem capable of absorbing shocks, containing cyber incidents and recovering quickly without allowing the failure of one institution or service provider to destabilise the wider system.

SOURCE: The Nation Nigeria

Social
Comments (0)
Add Comment