📖 ABSTRACT/OVERVIEW
Commercial banks are among the most cyber-targeted institutions in Nigeria, and assessing their incident response capabilities provides evidence for regulatory benchmarking and industry risk management improvement. This study assessed the cybersecurity incident response capabilities of commercial banks operating in Lagos Island and Victoria Island, Lagos State, South West Nigeria. A descriptive survey was conducted with 80 IT security officers and managers from 16 commercial banks using structured questionnaires. Dimensions assessed included incident detection speed, response team composition, incident classification protocols, regulatory reporting compliance, post-incident review practices, and Business Continuity Planning alignment. Results showed that 87.5 percent of banks had formal incident response plans. Mean detection-to-response time was 4.8 hours for major incidents. Regulatory reporting to CBN within the required 24-hour window was practised by 68.8 percent. Post-incident forensic review was conducted by 75.0 percent. However, tabletop exercise frequency was inadequate (less than twice annually) in 62.5 percent of banks. Cross-bank information sharing on threat intelligence was practised by only 31.3 percent. The study concludes that while formal capabilities exist, incident response maturity varies significantly across the sector, with key gaps in threat intelligence sharing and exercise frequency. Recommendations include CBN minimum incident response exercise requirements, a banking sector cyber threat intelligence sharing platform, and integration of incident response metrics into NDIC supervisory assessments.
Keywords: incident response, commercial banks, Lagos, cybersecurity capability, threat intelligence
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬