The Central Bank of Nigeria (CBN) has warned that a cyber vulnerability in one bank or financial institution could spread through interconnected networks and trigger wider disruption across Nigeria’s financial system.
The apex bank urged banks, fintechs and other financial institutions to strengthen cybersecurity, manage third-party technology risks and improve business continuity measures to prevent isolated incidents from developing into systemic threats.
The CBN said financial institutions must treat cybersecurity, third-party technology risks and business continuity as matters of financial-system stability, stressing that vulnerabilities in one institution could have consequences across the interconnected financial ecosystem.
The bank noted that growing reliance on fintechs, payment service providers, cloud operators and other technology vendors had created additional channels through which cyber and systemic risks could spread.
The Director of the CBN’s Payments System Supervision Department and Chairperson of the Nigeria Electronic Fraud Forum, Dr Rakiya Opemi Yusuf, gave the warning on Wednesday during a panel session at the 19th Annual Banking and Finance Conference of the Chartered Institute of Bankers of Nigeria (CIBN) in Abuja.
The session, titled, “Navigating Cyber and Systemic Risks in the AI-Driven Future of Banking: Implications for Financial Stability and Business Resilience,” examined the impact of artificial intelligence, cyber threats and digital interconnectivity on Nigeria’s financial system.
Yusuf warned that a weakness in a bank, fintech, payment service provider or technology vendor could potentially spread to other connected institutions, creating what she described as a “one-fire” effect capable of disrupting the wider financial system.
She therefore urged institutions to regularly assess their dependencies, third-party relationships and technology providers to determine how a failure in one part of the ecosystem could affect their operations.
According to her, resilience was not limited to preventing cyber incidents, as financial institutions must also be able to continue providing critical services during disruptions and recover quickly after an incident.
Yusuf said the CBN was strengthening its policies, regulations, supervisory frameworks and other measures to ensure vulnerabilities capable of threatening financial stability were identified and addressed before they developed into major problems.
She added that these risk considerations were also being taken into account during the product-approval stage.
The CBN director urged financial institutions to extend their cybersecurity and risk-management responsibilities beyond their internal systems to third-party providers that their operations increasingly rely on.
She said banks and other institutions should assess the resilience of their technology partners, including their ability to withstand and recover from cyberattacks and major operational failures.
Yusuf also called for the prompt reporting of cyber incidents and vulnerabilities, saying early disclosure would give regulators an opportunity to intervene before isolated incidents became broader systemic threats.
She stressed the importance of information and intelligence sharing among financial institutions, arguing that greater collaboration would help the sector identify emerging threats and strengthen its collective response.
The CBN official also advocated stronger Security Operations Centres capable of monitoring threats across the financial ecosystem in real time.
On artificial intelligence, Yusuf urged financial institutions to balance innovation with accountability, stressing that increasing automation must not eliminate human responsibility from financial decisions and processes.
She described the principle as “automating accountability”, noting that while AI could perform increasingly sophisticated functions, humans would remain responsible for decisions and outcomes involving financial services.
Yusuf further urged institutions to strengthen data governance and pay closer attention to digital sovereignty by examining where critical data is stored, who can access it, what insights can be generated from it and how the information influences decision-making.
She warned that placing critical data or technological capabilities beyond an institution’s effective control could expose organisations to additional risks.
Yusuf said the financial sector must adopt a collective approach to resilience by bringing regulators, banks, fintechs, payment service providers and technology companies into a stronger framework for managing cyber and systemic risks.
She maintained that the goal should be to build a financial ecosystem capable of absorbing shocks, containing cyber incidents and recovering rapidly without allowing the failure of one institution or service provider to destabilise the wider system.
Source: CBN






