Regulation 2018
CBN Risk-Based Cybersecurity Framework and Guidelines
Issued by Central Bank of Nigeria
Effective: 1 Jan 2019
Last amended: 1 Jul 2024
Plain-English summary
The CBN Risk-Based Cybersecurity Framework and Guidelines are a legally binding subsidiary legislation enacted through the powers vested in it via BOFIA 2020, which seeks to put in place the minimum cybersecurity requirements for financial institutions in Nigeria. While the initiative was initially launched on January 1, 2019, for large commercial banks before being expanded to other financial institutions, the framework operates within the ambit of a highly revamped 10-point framework, which took effect on July 1, 2024. This framework compels the banks and fintechs to have an independent Chief Information Security Officer (CISO) as well as undertake vulnerability assessments and have real-time threat intelligence. Under the tight leash of the CBN, firms are expected to submit data through the automated Cybersecurity Self-Assessment Tool (CSAT) by February 28 each year or suffer very stern enforcement measures like million-naira administrative fines and loss of operating license.
Who it applies to
Banking · Payments & Fintech
Topics
Cybersecurity & IT Risk
Latest news
No related news yet. We publish updates as regulators act.