📖 ABSTRACT/OVERVIEW
Nigerian commercial banks are among the most targeted institutions for cyberattacks in Africa, and systematic professional evaluation of cybersecurity risk management practices across the sector is needed to inform regulatory and institutional improvement. This study conducts a professional assessment of cybersecurity risk management frameworks in Nigerian commercial banks. A structured audit questionnaire covering 12 control domains based on ISO 27001 and the NIST Cybersecurity Framework was administered to IT security managers at 20 deposit money banks operating in Lagos and Abuja. Supplementary interviews with five Chief Information Security Officers deepened analysis of governance and risk culture dimensions. Assessment results were benchmarked against CBN Cybersecurity Framework 2021 requirements and international banking sector standards. Findings reveal that all 20 banks meet basic perimeter security standards (firewall deployment, antivirus management) but show significant gaps in advanced threat detection, staff security awareness programmes, incident response planning, and third-party vendor security assessment. Only 35 percent of banks demonstrated documented and tested incident response plans. Security awareness training reaches all staff annually in only 40 percent of banks. The study proposes a Nigerian Banking Cybersecurity Maturity Model with five levels and nine capability domains, adapted to the CBN regulatory context. Recommendations include mandatory bi-annual third-party penetration testing, board-level cybersecurity literacy programmes, and a bank-wide threat intelligence sharing platform managed by the CBN.
Keywords: cybersecurity, risk management, Nigerian banks, ISO 27001, CBN Cybersecurity Framework
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬