CBN Nigeria

June 30, (THEWILL) – The Central Bank of Nigeria (CBN) has released the Risk-Based Cyber-security Framework and Guidelines for Other Financial Institutions (OFIs).

The bank said the action became necessary as a result of the recent increase in the number and sophistication of cyber-security threats against financial institutions.

The CBN also set January 1, 2023 as the effective date for full compliance with the provisions of the guidelines.

Ask ZiVA 728x90 Ads

The circular dated June 29, 2022, and signed by the CBN Director, OFIs Department, Nkiru Asiegbu was addressed to all OFIs under the regulation of the banking sector regulator.

The apex bank added that the guidelines represented the minimum requirements to be put in place by all OFIs.

The apex bank added that the guidelines represented the minimum requirements to be put in place by all OFIs.

The regulator stressed that the safety and soundness of OFIs required that they operate in a safe and secure environment, hence the platform on which information is processed and transmitted should be managed in a way that ensures confidentially, integrity and availability of information as well as the avoidance of financial loss and reputation risks among others

The CBN noted that considering the reliance of financial institutions on information and communications technology (ICT) to operate their business and the rising incidences of cyber threats and attacks targeted at financial institutions, it became necessary to implement cyber-security measures to mitigate against those risks.

The bank specifically noted that threats including ransomware, targeted phishing attacks and Advanced Persistent Threats (APT) had become prevalent, demanding that financial institutions boost cyber resilience as well as take proactive steps to secure their critical information assets to ensure their safety and soundness.

The objective of the guidelines is to among other things create a safer and more secure cyber environment that supports information system security and promote stability of the OFI sub-sector.

It also seeks to promote and maintain public trust and confidence in the sub-sector as well as contribute towards the prevention and combating of cybercrime in the OFI sub-sector.

The document further spelt out the roles of board of directors in relation to cyber-security as well as appointment and responsibilities of the Chief Information Security Officer (CISO) among others

The framework made elaborate provisions for risk-based approach to managing cyber-security risk and consists of six parts including Cyber-security Governance, and Oversight, Cyber-security Risk Management System, Cyber Resilience Assessment, Cyber-security Operational Resilience, Cyber-Threat Intelligence and Metrics, , Monitoring and Reporting.

Sam Diala is a Bloomberg Certified Financial Journalist with over a decade of experience in reporting Business and Economy. He is Business Editor at THEWILL Newspaper, and believes that work, not wishes, creates wealth.

THEWILL APP ADS 2