Introduction
On 29 June 2022, the Central Bank of Nigeria (the “CBN”) approved and issued the risk-based cybersecurity framework guidelines for other financial institutions (“OFIs”) in Nigeria (the “Guidelines”). The Guidelines have been issued further to the CBN’s effort to strengthen the cyber resilience of OFIs especially following the increase in the number and sophistication of cybersecurity threats and attacks against OFIs.
The Guidelines outline the minimum requirements that OFIs are required to observe in developing and implementing strategies, policies, procedures, and related activities aimed at mitigating the risks of cyber threats and attacks.
All OFIs are expected to fully comply with the provisions of the Guidelines from 1 January 2023 (the “Effective Date”).