
Nigeria’s financial system has become too connected for cybersecurity to remain a private problem inside one bank or fintech. That is the real message behind the Central Bank of Nigeria’s latest warning to financial institutions.
Rakiya Opemi Yusuf, director of the CBN’s Payments System Supervision Department and chairperson of the Nigeria Electronic Fraud Forum, told banks, fintechs and other financial institutions to treat cybersecurity, technology-vendor failures and business continuity as financial-stability risks. The warning came during a banking and finance conference in Abuja.
The important phrase is systemic risk. Nigeria’s payment system now depends on banks, fintechs, switching companies, payment service providers, cloud vendors, identity systems, telecoms networks and third-party software providers. If one weak link fails, the impact can spread faster than it would have ten years ago.
This is why cyber risk is no longer only about whether a customer’s account is hacked. It is about whether a bank can keep critical services running during an attack, whether a fintech can recover after a vendor outage, whether payment rails can isolate a compromised participant and whether regulators are informed early enough to stop contagion.
The CBN also pointed to artificial intelligence as a new layer of risk. That is a necessary point. Banks and fintechs are already using AI for fraud detection, customer support, credit scoring, compliance checks and operational automation. But if AI systems make or influence financial decisions, human accountability cannot disappear behind the software.
That lesson feels more urgent after recent incidents in Nigerian finance. Zenith Bank’s customer-information warning showed how a limited data exposure can still create phishing and social-engineering risk for millions of customers. We explained that customer-facing angle in our Zenith Bank cyberattack warning article.
The AI angle also matters because attackers are getting faster. AI can help defenders detect unusual behaviour, but it can also help criminals write better phishing messages, automate reconnaissance and scale attacks across many targets. A bank that treats AI only as a productivity tool may miss the risk it creates for operations and trust.
Yusuf’s call for faster incident reporting and stronger cyber-intelligence sharing is practical. Silence helps attackers. If one institution sees a live campaign and others find out days later, the system loses valuable time. A mature financial ecosystem should be able to share threat signals without waiting for reputational damage to force disclosure.
Third-party risk may be the hardest part. Nigerian financial institutions increasingly rely on outside technology providers, but many customers still blame the bank or fintech when something breaks. Regulators will therefore need clearer standards for resilience testing, vendor mapping, cloud concentration and recovery timelines.
The CBN’s warning should be read as a shift in tone. Digital finance has helped Nigeria move faster, but speed without resilience creates a fragile system. The next phase of fintech growth will not be judged only by downloads, transaction volumes or valuation. It will be judged by whether the system can absorb shocks and keep public trust when cyber pressure rises.







