Home / Current Issue / Paper 1716597
Cybersecurity Threats in Nigerian Banks: Implications for Human Security and Strategic Responses in the 21st Century
Subject area: Arts, Social Sciences and Humanities · Area of research: Cybersecurity, Peace and Conflict
DOI: https://doi.org/10.64388/IREV9I10-1716597
Abstract
Nigeria’s banking sector has undergone rapid digitalisation, driven by the Central Bank of Nigeria’s cashless economy policies and pandemic-accelerated adoption, significantly expanding the attack surface available to cybercriminals. Despite a growing cybersecurity literature, the intersection of cyber threats with human security within the Nigerian context remains critically underexplored. This study examines cybersecurity threats facing Tier-1 commercial banks in Lagos State, analyses their human security implications, and evaluates strategic mitigation responses. Employing a cross-sectional survey design, 460 respondents comprising 230 bank staff and 230 customers were sampled from First Bank of Nigeria, United Bank for Africa, Guaranty Trust Bank, Access Bank, and Zenith Bank. Data were analysed using descriptive statistics, Pearson correlation, regression analysis, and ANOVA, within a dual theoretical framework integrating Risk Management Theory and Systems Theory. Findings confirm a severe threat environment, with mobile banking expansion identified as the primary vulnerability catalyst (M=3.62), alongside phishing, ransomware, DDoS attacks, and high insider threat perception (M=3.59). Cyberattacks were found to erode customer confidence (M=3.60), disrupt financial services for vulnerable populations (M=3.59), and impose significant psychological pressure on employees (M=4.02), empirically validating cybersecurity as a human security issue. While banks demonstrate strong multi-factor authentication adoption (M=4.05), a critical Effectiveness Paradox emerges: customers feel secure (M=4.09), yet attack frequency remains largely unreduced (M=2.97). An Expertise Paradox further revealed that IT and risk professionals hold significantly lower confidence in security measures than operational staff. The study repositions cybersecurity as a macro-prudential and social equity imperative, recommending Zero Trust architecture, AI-driven threat analytics, mandated inter-institutional intelligence sharing, and national digital literacy campaigns.
Keywords
Cybersecurity, Nigerian Banking Sector, Human Security, Strategic Responses, Digital Financial Inclusion, Cyber Resilience, Emerging Economies
References
[1] Adegbite, A. O., Akinwolemiwa, D. I., Uwaoma, P. U., Kaggwa, S., Akindote, O. J., & Dawodu,
[2] S. O. (2023). Review of cybersecurity strategies in protecting bank infrastructure: Perspectives from the USA. Computer Science & IT Research Journal, 4(3), 200–219. https://doi.org/10.51594/csitrj.v4i3.658
[3] Adelekan, I. (2020). Lagos: A critical driver of Nigeria's economy. Lagos Business School Review.
[4] Adeniyi, J. (2024). Nigerian banks hit by cyberattacks: Hope Payment Service Bank loses N10 billion. BusinessDay. https://businessday.ng
[5] Agwulonu, C., & Ijaseun, T. (2024). Phishing attacks and bank customer authentication in Nigeria. Journal of Cybersecurity Research, 6(1), 12–28.
[6] Ajufo, G., & Qutieshat, A. (2023). An examination of the human factors in cybersecurity: Future direction for Nigerian banks. Indonesian Journal of Information Systems, 6(1), 1–16.
[7] Anderson, R., & Moore, T. (2007). The economics of information security. Science, 314(5799), 610–613.
[8] Aven, T. (2016). Risk analysis: Assessing uncertainties beyond expected values and probabilities. John Wiley & Sons.
[9] Björck, F., Henkel, M., Stirna, J., & Zdravkovic, J. (2015). Cyber resilience—fundamentals for a definition. Proceedings of the 8th International Conference on Availability, Reliability, and Security, 35–43.
[10] Brower, D., & McCormick, J. (2021). The Colonial Pipeline ransomware attack: Lessons for future cyber defence. Journal of Security Studies, 16(3), 204–210.
[11] Central Bank of Nigeria. (2018). Risk-based cybersecurity framework and guidelines for deposit money banks and payment service providers. CBN. https://www.cbn.gov.ng
[12] Central Bank of Nigeria. (2019). Guidelines on information security management for banks and other financial institutions. CBN.
[13] Central Bank of Nigeria. (2020). Payment systems vision 2025. CBN.
[14] Central Bank of Nigeria. (2022). Annual report on cybercrime and cybersecurity. CBN.
[15] Checkland, P. (1999). Systems thinking, systems practice. John Wiley & Sons.
[16] Chen, S., Fan, L., Meng, G., Su, T., Xue, M., Xue, Y., & Xu, L. (2020). An empirical assessment of security risks of global android banking apps. Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering, 1310–1322.
[17] Chuang, T., Chang, S., & Huang, C. (2022). Cybersecurity risk management in banking: A framework and empirical validation. International Journal of Information Management, 63, 102–116.
[18] Creswell, J. W. (2014). Research design: Qualitative, quantitative, and mixed methods approaches (4th ed.). SAGE Publications.
[19] Dandurand, L., & Serrano, O. S. (2013). Towards improved cyber security information sharing.
[20] Proceedings of the 5th International Conference on Cyber Conflict, 2(1), 37–50.
[21] Daraojimba, C., Onunka, O., Alabi, A. M., Okafor, C. M., Obiki-Osafiele, A. N., & Onunka, T. (2023). Cybersecurity in US and Nigeria banking and financial institutions: Review and assessing risks and economic impacts. Acta Informatica Malaysia, 7(1), 54–62.
[22] Eling, M., & Schnell, W. (2016). Hacking events, the number of data records affected, and the economic impact of cybercrime. Journal of Risk and Insurance, 83(3), 475–500.
[23] Etikan, I., & Bala, K. (2017). Sampling and sampling methods. Biometrics & Biostatistics International Journal, 5(6), 215–217.
[24] Fadare, O., Odukoya, E., & Olatunji, S. (2023). Digital adoption, cybercrime, and the enforcement gap in Nigeria's post-pandemic banking sector. African Journal of Cybersecurity, 11(2), 44–61.
[25] Familoni, B. T., & Shoetan, P. O. (2024). Cybersecurity in the financial sector: A comparative analysis of the USA and Nigeria. Computer Science & IT Research Journal, 5(4), 850–877.
[26] Federal Republic of Nigeria. (2015). Cybercrimes (Prohibition, Prevention, etc.) Act. Government Press.
[27] Field, A. (2018). Discovering statistics using IBM SPSS statistics (5th ed.). SAGE Publications.
[28] Gao, Z., Xu, J., & Li, Y. (2021). Challenges in cybersecurity compliance in developing economies.
[29] Journal of Information Technology Management, 33(4), 203–215.
[30] Hassan, A. O., Ewuga, S. K., Abdul, A. A., Abrahams, T. O., Oladeinde, M., & Dawodu, S. O.
[31] (2024). Cybersecurity in banking: A global perspective with a focus on Nigerian practices. Computer Science & IT Research Journal, 5(1), 41–59.
[32] Hirschheim, R., & Klein, H. (2012). Balancing security and productivity in organisations. Journal of Information Security, 8(4), 304–316.
[33] Hoffman, D., Wills, T., & Pereira, J. (2020). Systemic weaknesses in cybersecurity governance. Journal of Cybersecurity Policy, 4(1), 55–74.
[34] Houghton, L., & Smith, A. (2021). The systems perspective on cybersecurity: Developing a unified approach. Computers & Security, 104, 102–114.
[35] IBM Security. (2023). Cost of a data breach report 2023. IBM.
[36] https://www.ibm.com/security/data-breach
[37] Inkster, B., Knibbs, C., & Bada, M. (2023). Cybersecurity: A critical priority for digital mental health. Frontiers in Digital Health, 5, 1242264.
[38] Interpol. (2022). Ransomware: Global threat report. Interpol.
[39] Japan's Ministry of Economy, Trade and Industry. (2018). Basic Act on Cybersecurity. Government of Japan.
[40] Kaspersen, A., & Lindsey, N. (2014). Cybercrime and human security: Emerging threats in the digital economy. International Security Review, 18(3), 78–94.
[41] Kaspersky Lab. (2015). The great bank robbery: Carbanak APT. Kaspersky Lab.
[42] Kim, S. (2022). The Lazarus Group and North Korea's global cybercriminal activities. Cybersecurity Journal, 5(2), 45–58.
[43] Koops, B.-J., & Leenes, R. (2014). Privacy regulation in the EU and global influence of GDPR. Computer Law & Security Review, 30(5), 487–497.
[44] Kovács, K., & Spalek, S. (2016). Cyber threats and the erosion of human security: Evidence from financial systems. European Journal of Security Studies, 9(2), 112–130.
[45] Levin, K. A. (2006). Study design III: Cross-sectional studies. Evidence-Based Dentistry, 7(1), 24–25.
[46] Lottu, O. A., Abdul, A. A., Daraojimba, D. O., Alabi, A. M., John-Ladega, A. A., & Daraojimba, C. (2023). Digital transformation in banking: A review of Nigeria's journey to economic prosperity. International Journal of Advanced Economics, 5(8), 215–238.
[47] Mahbub ul Haq, M. (1995). Reflections on human development. Oxford University Press.
[48] Maleks Smith, K., Brown, P. M., & Evans, A. G. (2020). The global economic impact of cybercrime. Economic Perspectives, 64(2), 34–46.
[49] Matsuura, J. (2016). Strategic responses to cybersecurity: An integrated framework. International Journal of Digital Security, 3(1), 77–92.
[50] Natalucci, F., Qureshi, M. S., & Suntheim, F. (2024, April 9). Rising cyber threats pose serious concerns for financial stability. International Monetary Fund.
[51] National Information Technology Development Agency. (2019). Nigeria Data Protection Regulation (NDPR). NITDA.
[52] NeFF. (2024). Nigeria Electronic Fraud Forum annual report 2023. CBN.
[53] Nigerian Communications Commission. (2023). State of cybersecurity in Nigeria. NCC.
[54] Nosrati, L., & Bidgoli, A. M. (2016). A review of mobile banking security. 2016 IEEE Canadian Conference on Electrical and Computer Engineering, 1–5.
[55] Obi, O. C., Akagha, O. V., Dawodu, S. O., Anyanwu, A. C., Onwusinkwue, S., & Ahmad, I. A. I. (2024). Comprehensive review on cybersecurity: Modern threats and advanced defence strategies. Computer Science & IT Research Journal, 5(2), 293–310.
[56] Ololade, B. M., Salawu, M. K., & Adekanmi, A. D. (2020). E-fraud in Nigerian banks: Why and how? Journal of Financial Risk Management, 9(3), 211–228.
[57] Olukoya, J. (2022). Cybersecurity compliance and resilience in Nigerian banks: Regulatory gaps and challenges. Journal of Banking Regulation, 10(2), 140–158.
[58] Onyekachi, E. (2024). Cybersecurity skills gap in Nigerian banking sector. African Journal of Information Technology, 19(1), 45–52.
[59] Oyewole, A. T., Okoye, C. C., Ofodile, O. C., & Ugochukwu, C. E. (2024). Cybersecurity risks in online banking: A detailed review and preventive strategies application. World Journal of Advanced Research and Reviews, 21(3), 625–643.
[60] Polit, D. F., & Beck, C. T. (2012). Nursing research: Generating and assessing evidence for nursing practice (9th ed.). Lippincott Williams & Wilkins.
[61] Reis, O., Oliha, J. S., Osasona, F., & Obi, O. C. (2024). Cybersecurity dynamics in Nigerian banking: Trends and strategies review. Computer Science & IT Research Journal, 5(2), 336–364.
[62] Ruan, K., Carthy, J., Kechadi, T., & Baggili, I. (2019). Cloud forensics definitions and critical criteria for cloud forensic capability: An overview of survey results. Digital Investigation, 10(1), 34–43.
[63] Santos, L. (2021). Public-private partnerships and cybersecurity in Brazil. Brazilian Journal of Public Policy, 17(2), 110–123.
[64] Sarumi, J., & Omotosho, O. M. (2022). A review of network security strategies employed by the Nigerian banking sector: Case study of Access Bank PLC, Bariga, Lagos, Nigeria. Advances in Multidisciplinary and Scientific Research Journal Publication, 8, 1–10.
[65] Singh, A. (2021). Cybersecurity risks and regulatory frameworks in India. South Asian Cybersecurity Review, 8(3), 23–34.
[66] Siponen, M., & Vance, A. (2010). Neutralization: New insights into the problem of employee information systems security policy violations. MIS Quarterly, 34(3), 487–502.
[67] Sitorus, R. S., Hutagaol, B. J., & Simanjuntak, D. M. (2024). Capability-based API gateway technology selection analysis for banking cybersecurity solution using AHP method. Sinkron: Jurnal dan Penelitian Teknik Informatika, 9(1), 338–347.
[68] Sue, V. M., & Ritter, L. A. (2012). Conducting online surveys (2nd ed.). SAGE Publications.
[69] Takemura, M. (2022). Information-sharing challenges in Japan's cybersecurity framework. Journal of Information Technology and Policy, 19(1), 13–26.
[70] Tavakol, M., & Dennick, R. (2011). Making sense of Cronbach's alpha. International Journal of Medical Education, 2, 53–55.
[71] United Nations Development Programme. (1994). Human development report 1994: New dimensions of human security. UNDP.
[72] Von Bertalanffy, L. (1968). General system theory: Foundations, development, applications. George Braziller.
[73] Von Solms, R., & Van Niekerk, J. (2013). From information security to cybersecurity. Computers & Security, 38(2), 97–102.
[74] Wang, V., Nnaji, H., & Jung, J. (2020). Internet banking in Nigeria: Cyber security breaches, practices and capability. International Journal of Law, Crime and Justice, 62, 100415.
[75] Williams, R. (2017). The future of cybersecurity in financial services. Journal of Financial Services Technology, 14(4), 29–42.
[76] World Economic Forum. (2022). Global risks report 2022. WEF.
[77] World Economic Forum. (2023). Global risks report 2023. WEF.
[78] Wu, Y., Cheng, X., & Zhang, Y. (2023). Bank cybersecurity crisis management: International experience, analytical framework and path selection. Sage Publications, 11(2222-1735).
How to cite this paper
@article{1716597,
author = {Taelolu, Omotunde Oluwasesan, Prof. Isiaka Alani Badmus, Dr. Ogundele A. T.},
title = {Cybersecurity Threats in Nigerian Banks: Implications for Human Security and Strategic Responses in the 21st Century},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {10},
pages = {3474-3484},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1716597.pdf},
abstract = {Nigeria’s banking sector has undergone rapid digitalisation, driven by the Central Bank of Nigeria’s cashless economy policies and pandemic-accelerated adoption, significantly expanding the attack surface available to cybercriminals. Despite a growing cybersecurity literature, the intersection of cyber threats with human security within the Nigerian context remains critically underexplored. This study examines cybersecurity threats facing Tier-1 commercial banks in Lagos State, analyses their human security implications, and evaluates strategic mitigation responses. Employing a cross-sectional survey design, 460 respondents comprising 230 bank staff and 230 customers were sampled from First Bank of Nigeria, United Bank for Africa, Guaranty Trust Bank, Access Bank, and Zenith Bank. Data were analysed using descriptive statistics, Pearson correlation, regression analysis, and ANOVA, within a dual theoretical framework integrating Risk Management Theory and Systems Theory. Findings confirm a severe threat environment, with mobile banking expansion identified as the primary vulnerability catalyst (M=3.62), alongside phishing, ransomware, DDoS attacks, and high insider threat perception (M=3.59). Cyberattacks were found to erode customer confidence (M=3.60), disrupt financial services for vulnerable populations (M=3.59), and impose significant psychological pressure on employees (M=4.02), empirically validating cybersecurity as a human security issue. While banks demonstrate strong multi-factor authentication adoption (M=4.05), a critical Effectiveness Paradox emerges: customers feel secure (M=4.09), yet attack frequency remains largely unreduced (M=2.97). An Expertise Paradox further revealed that IT and risk professionals hold significantly lower confidence in security measures than operational staff. The study repositions cybersecurity as a macro-prudential and social equity imperative, recommending Zero Trust architecture, AI-driven threat analytics, mandated inter-institutional intelligence sharing, and national digital literacy campaigns.},
keywords = {Cybersecurity, Nigerian Banking Sector, Human Security, Strategic Responses, Digital Financial Inclusion, Cyber Resilience, Emerging Economies},
month = {April},
doi = {https://doi.org/10.64388/IREV9I10-1716597}
}