Headlines

What Nigerian companies, regulators, others must do to prevent prevailing cyber attacks – Experts

Weak identity and access management remain one of the leading causes of unauthorised access to corporate systems, according to the cybersecurity expert.

Cybersecurity experts have suggested areas in which Nigerian companies, regulators, and other entities can strengthen their digital resilience and prevent prevailing cyber attacks.

The experts spoke against the backdrop of recent incidents of cyber attacks recorded across the country.

The rapid adoption of digital technology has transformed Nigeria’s corporate landscape, making financial services, business registration, and other transactions faster and more convenient.

However, this digital transformation has also exposed organisations to growing cybersecurity threats, with public and private institutions reportedly experiencing cyber incidents in recent months.

Among the most prominent cases are allegations by a hacker known as ByteToBreach, who claimed responsibility for attacks targeting organisations including Remita, Sterling Bank, Zenith Bank, the Oyo State Government, Leadway Assurance, GetBumpa, Ahmadu Bello University (ABU), Zaria, and the Corporate Affairs Commission (CAC).

The hacker also claimed to possess more than three terabytes of sensitive data allegedly obtained from the affected organisations.

Based on cybersecurity experts’ analysis of ByteToBreach’s claims, the alleged attacks involved an unpatched internet-facing server, weak credential management, poor network segmentation, trusted third-party integrations, weak access controls, predictable user identifiers, and insecure system design from the affected companies.

Checks showed that these cyber incidents and technical claims were not publicly confirmed by the organisations involved. In many cases, the only official announcement came from the Nigeria Data Protection Commission (NDPC), which disclosed that it had initiated investigations.

Nigerian institutions also rarely notify customers when their personal data may have been compromised, nor do they typically issue public apologies or explain the measures being taken to address such breaches.

In April, NDPC announced that it had commenced an investigation into the alleged data breaches involving Remita Payment Services Ltd., Sterling Bank, the CAC, and other entities.

Under Nigeria’s legal framework, companies are not generally required by the Constitution or the Cybercrimes Act to notify customers after every cyberattack.

However, the Nigeria Data Protection Act (NDPA) 2023 requires organisations to notify the NDPC within 72 hours of becoming aware of a personal data breach that is likely to pose a risk to individuals.

Where such a breach is likely to result in a high risk to the rights and freedoms of affected individuals, organisations are also required to notify those individuals without undue delay.

The law therefore requires organisations to assess the nature and potential impact of a personal data breach before determining whether customer notification is mandatory.

The CAC, for instance, was very careful in its data breach announcement, stating that there had been “unauthorised access to limited aspects of its information systems,” but the artefacts published by the hackers claimed the hackers possessed over 25 million documents from the CAC’s system.

The breach at the CAC extends beyond the commission itself. As Nigeria’s corporate registry, it maintains sensitive records on millions of registered businesses, including company registration details, directors’ and shareholders’ information, beneficial ownership records, registered addresses, incorporation documents, and statutory filings.

If accessed by malicious actors, such information could be exploited for corporate fraud, identity theft, phishing attacks, and the impersonation of businesses or company officials.

Meanwhile, the Federal Government has only disclosed plans in April to establish a Cybersecurity Coordination Council with private-sector participation to strengthen Nigeria’s collective cyber resilience in response to evolving cyber threats across the public and private sectors.

Cybersecurity experts have criticised Nigeria’s approach to cybersecurity oversight, arguing that regulators have historically placed greater emphasis on regulatory compliance than on the actual effectiveness of organisations’ security controls, allowing vulnerable institutions to manage sensitive data.

They also contend that regulators rely too heavily on organisations’ self-assessments of their cybersecurity posture instead of conducting independent and transparent evaluations, describing the approach as more performative than effective.

For instance, in March 2026, the Central Bank of Nigeria (CBN) introduced a mandatory Cybersecurity Self-Assessment Tool (CSAT), requiring banks and other regulated financial institutions to assess and report their cybersecurity posture as part of efforts to strengthen cyber resilience and enhance regulatory oversight.

Speaking to PREMIUM TIMES on the vulnerabilities the attackers claimed to have exploited, cybersecurity expert and Senior Data Analyst at Ceresense Training Institute, Samuel Tomori, said the recent cyber incidents involving major Nigerian institutions reveal a more fundamental problem than sophisticated hacking.

“The recent wave of cyberattacks on major Nigerian institutions, including Sterling Bank, the CAC, and Remita, is a brutal wake-up call. But if you look at how these breaches actually happened, the frustrating reality is that the attackers did not use futuristic, unpreventable exploits. They basically walked through doors that were left unlocked,” he said.

According to Mr Tomori, the incidents suggest that many organisations continue to prioritise regulatory compliance over building genuinely secure systems.

“It is not like the attackers are using any sophisticated tools. The fallout shows that too many companies across the country are relying on basic compliance checklists rather than examining how their networks actually operate. If they do not fix the underlying architecture, these headlines will just keep happening,” he said.

Mr Tomori argued that one of the biggest changes Nigerian organisations need to make is abandoning the assumption that systems within their networks or those of trusted partners are automatically secure.

“Nigerian institutions need to stop assuming ‘internal’ means ‘safe.’ For years, the standard playbook has been to build a strong perimeter. They assumed that if a partner network, such as a bank, connected to an aggregator like Remita, that connection was safe because they knew who they were.

“The Sterling-to-Remita link showed exactly why this model is dead,” he said, referring to ByteToBreach’s claim that Remita was accessed through Sterling Bank.

He explained that once attackers gain access through a seemingly insignificant server, they can exploit trusted connections to move into more sensitive systems.

“Once an attacker breaches a minor, non-critical server on one side, they can use that trusted pipeline to slide straight into core systems.