Home » CBN Introduces Cybersecurity Assessment for Banks

CBN Introduces Cybersecurity Assessment for Banks

By Ayomide Otitoju

The Central Bank of Nigeria (CBN) on Monday directed Deposit Money Banks (DMBs) to complete a mandatory cybersecurity self-assessment within three weeks as part of efforts to strengthen resilience across the financial system.

In a letter dated March 30, 2026, and published on its website Tuesday, the apex bank introduced the Cybersecurity Self-Assessment Tool (CSAT) for banks, selected financial institutions, and payment service providers. Other regulated entities are required to submit their assessments within five weeks.

“The Central Bank of Nigeria, in furtherance of its statutory mandate under the Banks and Other Financial Institutions Act 2020 and consistent with its commitment to strengthening cybersecurity resilience across the financial sector, hereby notifies all Deposit Money Banks, Payment Service Banks, Microfinance Banks, Payment Service Providers, Finance Companies, and Development Finance Institutions of the deployment of its Cybersecurity Self-Assessment Tool,” the letter stated.

The CBN said the CSAT will assess institutions’ cybersecurity posture across key areas, including governance structures, risk management frameworks, technology systems, third-party risk exposure, incident response capacity, and operational resilience. Insights from the exercise will support risk-based supervision and improve regulatory oversight of cyber threats within Nigeria’s financial ecosystem.

All institutions are required to submit completed assessments through a dedicated portal using credentials provided to their Chief Information Security Officers and other relevant officials. Data must reflect positions as of December 31, 2025, and must be accurate, complete, and verifiable. The CBN warned that false or incomplete disclosures would constitute a regulatory breach and attract sanctions.

The apex bank also plans to validate submissions through off-site reviews and supervisory engagements to ensure reliability. The directive, effective immediately, underscores heightened regulatory scrutiny of cyber risks in the banking sector amid growing digital transactions and rising exposure to cyber threats.

Comments (0)

Your email address will not be published. Required fields are marked *