The Central Bank of Nigeria has urged banks, fintechs and other financial institutions to treat cybersecurity and third-party technology risks as core issues of financial stability. The regulator cautioned that a vulnerability in a single institution could spread rapidly across the system and cause widespread disruption.
Dr Rakiya Yusuf, Director of Payments System Supervision at the CBN and Chairperson of the Nigeria Electronic Fraud Forum, delivered the warning at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria in Abuja. She spoke during a session titled “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience.”
The ‘One-Fire’ Risk
Yusuf said the growing dependence of financial institutions on fintechs, payment service providers, cloud operators and other technology vendors has created new pathways for cyber and systemic risks. A weakness in a bank, fintech, payment provider or technology partner could spread quickly through interconnected institutions, producing what she described as a “one-fire” effect capable of destabilising the entire financial system.
Her message to operators was direct. Protecting internal systems is no longer sufficient. Institutions must reinforce safeguards across the wider financial ecosystem and continually assess their dependencies, third-party relationships and technology partners to understand how a disruption elsewhere could affect their own operations.
She stressed that operational resilience goes beyond preventing cyberattacks. Institutions must also keep critical services running during disruptions and recover quickly when incidents occur.
Regulatory Response
Yusuf said the Central Bank is strengthening its regulatory framework, supervisory processes and policy measures to identify and address vulnerabilities that could threaten financial stability before they materialise. Cyber and operational risk considerations are now being built into the product approval process so that new financial products do not introduce systemic weaknesses.
She also called on banks to extend cybersecurity and risk-management oversight to third-party service providers, assessing whether their technology partners can withstand and recover from cyberattacks and major operational failures.
On incident reporting, she urged prompt disclosure of cyber incidents and vulnerabilities to regulators. Early reporting, she said, would enable timely intervention before isolated breaches escalate into systemic threats. She further advocated greater intelligence and information sharing among financial institutions and recommended stronger Security Operations Centres capable of monitoring cyber threats across the financial ecosystem in real time.
AI, Data and Accountability
Turning to artificial intelligence, Yusuf cautioned that innovation must be matched with accountability. Automation should not remove human responsibility from financial decisions. She described the required approach as “automating accountability,” explaining that while AI can perform increasingly sophisticated tasks, human oversight must remain central to decisions that affect customers and the financial system.
She urged institutions to strengthen data governance and pay closer attention to digital sovereignty by examining where critical data are stored, who has access to them, what intelligence can be drawn from them and how that data shapes decision-making. Placing critical data or key technological capabilities beyond an institution’s effective control, she warned, could expose the financial system to additional risks.
Yusuf maintained that protecting Nigeria’s financial system requires a collective effort involving regulators, banks, fintechs, payment service providers and technology companies. The objective, she said, is a resilient ecosystem that can absorb shocks, contain cyber incidents and recover swiftly without allowing the failure of one institution to threaten the stability of the entire system.







