An Original Investigation into the Theoretical Basis for Cybersecurity Risk Quantification in Nigerian Financial Institutions

📖 ABSTRACT/OVERVIEW

Cybersecurity risk quantification translates technical vulnerabilities into business-relevant financial exposure metrics, enabling security investment decisions that are both defensible to executives and empirically grounded. Developing an original quantification framework for Nigerian financial institutions, where risk data and threat calibration sources are limited, represents an important theoretical and methodological contribution. This study developed an original cybersecurity risk quantification framework for Nigerian financial institutions. A theory-building and empirical methodology was employed: systematic review of risk quantification approaches (68 publications, 2018 to 2024), empirical data collection on historical cybercrime loss frequency and severity from CBN supervisory data and EFCC case statistics across 5 years, and expert validation. The systematic review confirmed that Factor Analysis of Information Risk (FAIR) and probabilistic risk approaches required adaptation for Nigerian contexts due to absent threat event frequency data, locally specific loss magnitude distributions, and Nigerian banking regulatory risk appetite definitions. Original empirical work calibrated loss event frequency distributions for six Nigerian financial cybercrime categories using maximum likelihood estimation on available incident data. The original Nigerian Financial Institution Cyber Risk Quantification Framework proposes adaptations to FAIR methodology for Nigeria: locally calibrated threat event frequency tables, Nigerian regulatory penalty loss magnitude functions, and a Bayesian updating mechanism for incorporating NFIU threat intelligence into risk estimates. Expert review by 14 risk quantification and financial security specialists confirmed the framework's theoretical originality.

Keywords: cybersecurity risk quantification, FAIR methodology, Nigerian financial institutions, Bayesian risk, original framework

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬
Departments# Cyber Security