CBN Gives Banks Three Weeks for Cybersecurity Audit

Governor of the Central Bank of Nigeria, Olayemi Cardoso - National News

By Our Correspondent

National News – The Central Bank of Nigeria (CBN) has ordered banks across the country to complete a compulsory cybersecurity self-assessment within three weeks as part of efforts to strengthen the security of Nigeria’s financial system.

The directive, issued by the apex bank and signed under the leadership of Olayemi Cardoso, requires all Deposit Money Banks to submit their cybersecurity reports within 21 days, while other regulated financial institutions have five weeks to comply.

The order was communicated in a circular dated March 30, 2026, and published on the bank’s official website.

According to the CBN, the assessment will be carried out using a newly introduced Cybersecurity Self-Assessment Tool (CSAT), designed to evaluate the level of cyber risk exposure among financial institutions.

The tool will review key areas such as governance frameworks, risk management structures, technological infrastructure, third-party security exposure, incident response capabilities, and overall operational resilience.

The regulator explained that the initiative is backed by its statutory responsibilities under the Banks and Other Financial Institutions Act 2020.

It added that the move aims to strengthen cybersecurity resilience across the financial sector as digital banking transactions and cyber threats continue to grow in Nigeria.

The apex bank also warned institutions against submitting inaccurate or incomplete information, stressing that misleading disclosures would constitute a regulatory breach and could attract sanctions.

Industry observers say the directive signals stricter cybersecurity oversight by the CBN as Nigeria’s banking sector continues its rapid shift toward digital financial services.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may like