Home / Current Issue / Paper 1722621
Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape
Subject area: Science,Engineering and Technology · Area of research: Cyber Risk Management
DOI: https://doi.org/10.64388/IREV5I2-1722621
Abstract
This review critically examines the maturity of cyber risk management within Nigeria’s insurance sector, with particular attention to the extent to which organisational practices align with prevailing supervisory, data-protection, and resilience expectations. It seeks to determine whether insurers are progressing beyond formal compliance toward embedded, measurable, and adaptive cyber-risk capabilities. The study adopts a structured narrative review approach, synthesising scholarly literature, regulatory instruments, industry guidance, and established cybersecurity maturity frameworks to evaluate governance, threat exposure, privacy protection, incident management, operational resilience, workforce capability, and regulatory alignment. The findings indicate that cyber maturity within the sector is shaped by the quality of board oversight, integration of cyber risk into enterprise risk management, effectiveness of technical and organisational controls, third-party governance, and the ability to detect, respond to, and recover from disruptive events. The review further identifies significant barriers, including fragmented accountability, uneven security investment, skills shortages, weak security cultures, legacy systems, inconsistent control measurement, and gaps between documented compliance and operational effectiveness. It also establishes that regulatory conformity alone is insufficient to demonstrate resilience where controls are not continuously tested, monitored, and improved. The study concludes that a more mature cyber-risk posture requires coordinated governance, risk-based supervision, measurable maturity assessments, stronger privacy-by-design practices, continuous monitoring, and tested incident-response and recovery capabilities. It recommends enhanced board accountability, sector-wide threat intelligence, structured third-party assurance, sustained cybersecurity workforce development, and closer alignment between supervisory expectations and evidence-based resilience metrics. These measures are essential for strengthening policyholder protection, operational continuity, regulatory confidence, and the long-term stability of Nigeria’s increasingly digital insurance ecosystem amid increasingly sophisticated cyber threats.
Keywords
cyber risk management; cyber maturity; nigerian insurance sector; NAICOM; data protection; operational resilience
References
[1] Adler, R.M. (2013) ‘A dynamic capability maturity model for improving cyber security’, in 2013 IEEE International Conference on Technologies for Homeland Security (HST). IEEE, pp. 230 –235. 10.1109/THS.2013.6699005. (Science Publishing Corporation)
[2] Adu, K.K. and Adjei, E. (2018) ‘The phenomenon of data loss and cyber security issues in Ghana’, Foresight, 20(2), pp. 150–161. Publishing)
[3] Agrafiotis, I., Nurse, J.R.C., Goldsmith, M., Creese, S. and Upton, D. (2018) ‘A taxonomy of cyber-harms: Defining the impacts of cyber- attacks and understanding how they propagate’, Journal of Cybersecurity, 4(1), tyy006. 10.1093/cybsec/tyy006. (OUP Academic)
[4] Ahmad, A., Maynard, S.B., Desouza, K.C., Kotsias, J., Whitty, M.T. and Baskerville, R.L. (2021) ‘How can organizations develop situation awareness for incident response: A case study of management practice’, Computers & Security, 101, 102122. 10.1016/j.cose.2020.102122. (Monash University)
[5] Alayo, J.G., Mendoza, P.N., Armas-Aguirre, J. and Molina, J.M. (2021) ‘Cybersecurity maturity model for providing services in the financial sector in Peru’, in 2021 7th Congreso Internacional de Innovación y Tendenciasen Ingeniería (CONIITI). IEEE, pp. 1–4. 10.1109/CONIITI53815.2021.9619733. (UPC)
[6] Aliyu, A., Maglaras, L., He, Y., Yevseyeva, I., Boiten, E., Cook, A. and Janicke, H. (2020) ‘A holistic cybersecurity maturity assessment framework for higher education institutions in the United Kingdom’, Applied Sciences, 10(10), p. 3660. (ResearchGate)
[7] Al-Matari, O.M.M., Helal, I.M.A., Mazen, S.A. and Elhennawy, S. (2021) ‘Adopting security maturity model to the organizations’ capability model’, Egyptian Informatics Journal, 22(2), pp. 193–199. (ScienceDirect)
[8] Alshaikh, M. (2020) ‘Developing cybersecurity culture to influence employee behavior: A practice perspective’, Computers & Security, 98, 102003. (ScienceDirect)
[9] Benz, M. and Chatterjee, D. (2020) ‘Calculated risk? A cybersecurity evaluation tool for SMEs’, Business Horizons, 63(4), pp. 531–540. 10.1016/j.bushor.2020.03.010. (ScienceDirect)
[10] Biener, C., Eling, M. and Wirfs, J.H. (2015) ‘Insurability of cyber risk: An empirical analysis’, The Geneva Papers on Risk and Insurance—Issues and Practice, 40(1), pp. 131– 158.
[11] Bohnert, A., Fritzsche, A. and Gregor, S. (2019) ‘Digital agendas in the insurance industry: The importance of comprehensive approaches’, The Geneva Papers on Risk and Insurance—Issues and Practice, 44(1), pp. 1–19. 10.1057/s41288-018-0109-0. (Springer)
[12] Bouveret, A. (2018) ‘Cyber risk for the financial sector: A framework for quantitative assessment’, IMF Working Papers, 2018(143), pp. 1–29.
[13] Cram, W.A., Proudfoot, J.G. and D’Arcy, J. (2017) ‘Organizational information security policies: A review and research framework’, European Journal of Information Systems, 26(6), pp. 605–641. 0059-9. (Taylor & Francis Online)
[14] Da Veiga, A. and Eloff, J.H.P. (2007) ‘An information security governance framework’, Information Systems Management, 24(4), pp. 361–372. (ACM Digital Library)
[15] De Bruin, R. and Von Solms, S.H. (2016) ‘Modelling cyber security governance maturity’, in 2015 IEEE International Symposium on Technology and Society (ISTAS). IEEE, Article 7439415. (University of Johannesburg)
[16] Drivas, G., Chatzopoulou, A., Maglaras, L., Lambrinoudakis, C., Cook, A. and Janicke, H. (2020) ‘A NIS Directive compliant cybersecurity maturity assessment framework’, in 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC). IEEE, pp. 1641–1646. 10.1109/COMPSAC48688.2020.00-20. (CONCORDIA)
[17] Dupont, B. (2019) ‘The cyber-resilience of financial institutions: Significance and applicability’, Journal of Cybersecurity, 5(1), tyz013. Academic)
[18] Eckles, D.L., Hoyt, R.E. and Miller, S.M. (2014) ‘The impact of enterprise risk management on the marginal cost of reducing risk: Evidence from the insurance industry’, Journal of Banking & Finance, 43, pp. 247–261. (IDEAS/RePEc)
[19] Ejofodomi, O.A., Gideon, E.N., Oladipo, G.O. and Oshomah, E.R. (2014) ‘Automated detection of architectural detection in mammograms using template matching’, International Journal of Biomedical Science and Engineering, 2(1), pp. 1 –6. 10.11648/j.ijbse.20140201.11. (Science Publishing Group)
[20] Eling, M. and Lehmann, M. (2018) ‘The impact of digitalization on the insurance value chain and the insurability of risks’, The Geneva Papers on Risk and Insurance—Issues and Practice, 43(3), pp. 359–396. 10.1057/s41288-017-0073-0. (EconPapers)
[21] Eling, M. and Schnell, W. (2016) ‘What do we know about cyber risk and cyber risk insurance?’, The Journal of Risk Finance, 17(5), pp. 474–491. (IDEAS/RePEc)
[22] Erin, O.A., Kolawole, A.D. and Noah, A.O. (2020) ‘Risk governance and cybercrime: The hierarchical regression approach’, Future Business Journal, 6, Article 12. 10.1186/s43093-020-00020-1. (Springer)
[23] Falemi, A., Akhigbe, R. and Akin-Oluyomi, O.T. (2020) ‘A conceptual supply chain talent development model for capability building across distributed operations’, International Journal of Multidisciplinary Research and Growth Evaluation, 1(5), pp. 439–456. 10.54660/.IJMRGE.2020.1.5.439-456. (All Multidisciplinary Journal)
[24] Furnell, S. and Bishop, M. (2020) ‘Addressing cyber security skills: The spectrum, not the silo’, Computer Fraud & Security, 2020(2), pp. 6–11. (ScienceDirect)
[25] Garba, A.A., Bade, A.M., Yahuza, M. and Nuhu, Y. (2020) ‘Cybersecurity capability maturity models review and application domain’, International Journal of Engineering & Technology, 9(3), pp. 779–784. 10.14419/ijet.v9i3.30719. (Science Publishing Corporation)
[26] Gkotsopoulou, O., Charalambous, E., Limniotis, K., Quinn, P., Kavallieros, D., Sargsyan, G., Shiaeles, S. and Kolokotronis, N. (2019) ‘Data protection by design for cybersecurity systems in a smart home environment’, in Proceedings of the 2019 IEEE Conference on Network Softwarization (NetSoft). IEEE, pp. 101–109. (University of Portsmouth)
[27] Gonzalez-Granadillo, G., Menesidou, S.A., Papamartzivanos, D., Romeu, R., Navarro- Llobet, D., Okoh, C., Nifakos, S., Xenakis, C. and Panaousis, E. (2021) ‘Automated cyber and privacy risk management toolkit’, Sensors, 21(16), p. 5493. (MDPI)
[28] Gordon, L.A., Loeb, M.P. and Sohail, T. (2003) ‘A framework for using insurance for cyber-risk management’, Communications of the ACM, 46(3), pp. 81 –85. 10.1145/636772.636774. (ACM Digital Library)
[29] Grima, S. and Marano, P. (2021) ‘Designing a model for testing the effectiveness of a regulation: The case of DORA for insurance undertakings’, Risks, 9(11), Article 206, pp. 1– 12. Latvia)
[30] Haislip, J., Lim, J.H. and Pinsker, R. (2021) ‘The impact of executives’ IT expertise on reported data security breaches’, Information Systems Research, 32(2), pp. 318–334. 10.1287/isre.2020.0986. (PubsOnline)
[31] Hasan, S., Ali, M., Kurnia, S. and Thurasamy, R. (2021) ‘Evaluating the cyber security readiness of organizations and its influence on performance’, Journal of Information Security and Applications, 58, 102726. 10.1016/j.jisa.2020.102726. (ScienceDirect)
[32] Hausken, K. (2020) ‘Cyber resilience in firms, organizations and societies’, Internet of Things, 11, 100204. (ScienceDirect)
[33] Hoyt, R.E. and Liebenberg, A.P. (2011) ‘The value of enterprise risk management’, Journal of Risk and Insurance, 78(4), pp. 795–822. 10.1111/j.1539-6975.2011.01413.x. (Wiley Online Library)
[34] Iorliam, A. (2019) Cybersecurity in Nigeria: A Case Study of Surveillance and Prevention of Digital Crime. Cham: Springer. 10.1007/978-3-030-15210-9. (Springer)
[35] Kamiya, S., Kang, J.K., Kim, J., Milidonis, A. and Stulz, R.M. (2021) ‘Risk management, firm reputation, and the impact of successful cyberattacks on target firms’, Journal of Financial Economics, 139(3), pp. 719–749. Scholars Hub)
[36] Karanja, E. (2017) ‘The role of the chief information security officer in the management of IT security’, Information and Computer Security, 25(3), pp. 300–329. 10.1108/ICS-02-2016-0013. (Emerald Publishing)
[37] Kashyap, A.K. and Wetherilt, A. (2019) ‘Some principles for regulating cyber risk’, AEA Papers and Proceedings, 109, pp. 482–487.
[38] Li, Q., Wu, Y., Ojiako, U., Marshall, A. and Chipulu, M. (2014) ‘Enterprise risk management and firm value within China’s insurance industry’, Acta Commercii, 14(1), Article 198, pp. 1 –10. 10.4102/ac.v14i1.198. (Acta Commercii)
[39] Linkov, I., Eisenberg, D.A., Plourde, K., Seager, T.P., Allen, J. and Kott, A. (2013) ‘Resilience metrics for cyber systems’, Environment Systems and Decisions, 33(4), pp. 471–476. (ResearchGate)
[40] Makulilo, A.B. (2015) ‘Myth and reality of harmonisation of data privacy policies in Africa’, Computer Law & Security Review, 31(1), pp. 78 –89. 10.1016/j.clsr.2014.11.005.
[41] Mantelero, A., Vaciago, G., Esposito, M.S. and Monte, N. (2020) ‘The common EU approach to personal data and cybersecurity regulation’, International Journal of Law and Information Technology, 28(4), pp. 297–328. 10.1093/ijlit/eaaa021. (OUP Academic)
[42] Markopoulou, D. (2021) ‘Cyber-insurance in EU policy-making: Regulatory options, the market’s challenges and the US example’, Computer Law & Security Review, 43, 105627. Universiteit Brussel)
[43] Marotta, A., Martinelli, F., Nanni, S., Orlando, A. and Yautsiukhin, A. (2017) ‘Cyber-insurance survey’, Computer Science Review, 24, pp. 35– 61. (ScienceDirect)
[44] Mbanaso, U.M., Abrahams, L. and Apene, O.Z. (2019) ‘Conceptual design of a cybersecurity resilience maturity measurement (CRMM) framework’, The African Journal of Information and Communication, 23, pp. 1–26. 10.23962/10539/27535. (SciELO)
[45] Miron, W. and Muita, K. (2014) ‘Cybersecurity capability maturity models for providers of critical infrastructure’, Technology Innovation Management Review, 4(10), pp. 33–39. 10.22215/timreview/837. (TIM Review)
[46] Mohammed, S. and Kurawa, J.M. (2021) ‘Board attributes and value of listed insurance companies in Nigeria: The mediating effect of earnings quality’, International Journal of Management Science and Business Administration, 8(1), pp. 7–23. 10.18775/ijmsba.1849-5664- 5419.2014.81.1001.
[47] Moodley, A.J. (2019) ‘Digital transformation in South Africa’s short-term insurance sector: Traditional insurers’ responses to the Internet of Things (IoT) and Insurtech’, The African Journal of Information and Communication, 24, pp. 1–16.
[48] Mukhopadhyay, A., Chatterjee, S., Saha, D., Mahanti, A. and Sadhukhan, S.K. (2013) ‘Cyber-risk decision models: To insure IT or not?’, Decision Support Systems, 56, pp. 11–26. (ScienceDirect)
[49] Nel, F. and Drevin, L. (2019) ‘Key elements of an information security culture in organisations’, Information & Computer Security, 27(2), pp. 146–164. 10.1108/ICS-12-2016-0095. (ScienceDirect)
[50] Nocco, B.W. and Stulz, R.M. (2006) ‘Enterprise risk management: Theory and practice’, Journal of Applied Corporate Finance, 18(4), pp. 8–20. (Wiley Online Library)
[51] Odusote, A. (2021) ‘Data misuse, data theft and data protection in Nigeria: A call for a more robust and more effective legislation’, Beijing Law Review, 12(4), pp. 1284–1298. 10.4236/blr.2021.124066.
[52] Omotubora, A. (2021) ‘How (not) to regulate data processing: Assessing Nigeria’s Data Protection Regulation 2019 (NDPR)’, Global Privacy Law Review, 2(3), pp. 186–199. 10.54648/GPLR2021024. (ResearchGate)
[53] Osho, O. and Onoja, A.D. (2015) ‘National cyber security policy and strategy of Nigeria: A qualitative analysis’, International Journal of Cyber Criminology, 9(1), pp. 120–143. 10.5281/zenodo.22390. (Zenodo)
[54] Pieterse, H. (2021) ‘The cyber threat landscape in South Africa: A 10-year review’, The African Journal of Information and Communication, 28, pp. 1–21.
[55] Pomerleau, P.-L. and Lowery, D.L. (2020) Countering Cyber Threats to Financial Institutions: A Private and Public Partnership Approach to Critical Infrastructure Protection. Cham: Palgrave Macmillan. 3-030-54054-8. (Springer)
[56] Radanliev, P., De Roure, D., Nurse, J.R.C., Montalvo, R.M., Cannady, S. and Santos, O. (2020) ‘Future developments in standardisation of cyber risk in the Internet of Things (IoT)’, SN Applied Sciences, 2, Article 169. 10.1007/s42452-019-1931-0.
[57] Rea-Guaman, A.M., San Feliu, T., Calvo- Manzano, J.A. and Sanchez-Garcia, I.D. (2017) ‘Comparative study of cybersecurity capability maturity models’, in Mas, A., Mesquida, A., O’Connor, R.V., Rout, T. and Dorling, A. (eds.) Software Process Improvement and Capability Determination. Communications in Computer and Information Science, Vol. 770. Cham: Springer, pp. 100–113. 319-67383-7_8. (OUCI)
[58] Romanosky, S., Ablon, L., Kuehn, A. and Jones, T. (2019) ‘Content analysis of cyber insurance policies: How do carriers price cyber risk?’, Journal of Cybersecurity, 5(1), tyz002.
[59] Romanou, A. (2018) ‘The necessity of the implementation of Privacy by Design in sectors where data protection concerns arise’, Computer Law & Security Review, 34(1), pp. 99–110. (ScienceDirect)
[60] Schinagl, S. and Shahim, A. (2020) ‘What do we know about information security governance? “From the basement to the boardroom”: Towards digital security governance’, Information and Computer Security, 28(2), pp. 261–292. 10.1108/ICS-02-2019-0033. (Emerald Publishing)
[61] Schlette, D., Vielberth, M. and Pernul, G. (2021) ‘CTI-SOC2M2 – The quest for mature, intelligence-driven security operations and incident response capabilities’, Computers & Security, 111, 102482. 10.1016/j.cose.2021.102482. (University of Regensburg)
[62] Schmitz, C., Schmid, M., Harborth, D. and Pape, S. (2021) ‘Maturity level assessments of information security controls: An empirical analysis of practitioners’ assessment capabilities’, Computers & Security, 108, 102306. (ACM Digital Library)
[63] Shameli-Sendi, A., Aghababaei-Barzegar, R. and Cheriet, M. (2016) ‘Taxonomy of information security risk assessment (ISRA)’, Computers & Security, 57, pp. 14–30. 10.1016/j.cose.2015.11.001. (DBLP)
[65] Shittu, H.A., Shittu, M.A., Adeleke, O.J. and Adedokun, O.J. (2021) ‘Blockchain-based energy trading models for peer-to-peer renewable microgrids’, International Journal of Research in Electrical and Electronics Engineering, 4(3), pp. 1 –19. 10.34218/IJREEE_04_03_001. (IAEME Publication)
[66] Shittu, M.A., Adeniji, I.O., Shittu, H. and Opara, I.S. (2020) ‘Grounding system design optimization for medium-voltage distribution networks in emerging power markets’, IRE Journal, 3, pp. 11 –19. 10.64388/IREV3I11-1714040.
[67] Soomro, Z.A., Shah, M.H. and Ahmed, J. (2016) ‘Information security management needs more holistic approach: A literature review’, International Journal of Information Management, 36(2), pp. 215–225. 10.1016/j.ijinfomgt.2015.11.009. (ScienceDirect)
[68] Spiekermann, S. and Cranor, L.F. (2009) ‘Engineering privacy’, IEEE Transactions on Software Engineering, 35(1), pp. 67–82. 10.1109/TSE.2008.88. (ACM Digital Library)
[69] Srinivas, J., Das, A.K. and Kumar, N. (2019) ‘Government regulations in cyber security: Framework, standards and recommendations’, Future Generation Computer Systems, 92, pp. 178–188. (Publications Repository)
[70] Stoeckli, E., Dremel, C. and Uebernickel, F. (2018) ‘Exploring characteristics and transformational capabilities of InsurTech innovations to understand insurance value creation in a digital world’, Electronic Markets, 28(3), pp. 287–305. 0304-7. (Springer)
[71] Sunday, E.A. and Omoegun, G.O. (2018) ‘Integrating solar power solutions in small-scale manufacturing industries in Nigeria’, International Journal of Scientific Research in Science, Engineering and Technology, 4(8), pp. 832–853. (IJRSET)
[72] Sunday, E.A. and Omoegun, G.O. (2019) ‘Optimizing electrical load distribution for hybrid solar installations in developing economies’, International Journal of Scientific Research in Mechanical and Materials Engineering, 3(6), pp. 27–47.
[73] Sunday, E.A., Omoegun, G.O., Essien, M.A. and Oluokun, O.A. (2019) ‘Thermodynamic efficiency and control strategies in residential air conditioning systems’, International Journal of Scientific Research in Civil Engineering, 3(3), pp. 52–76. (IJRCE)
[74] Sutherland, E. (2017) ‘Governance of cybersecurity – the case of South Africa’, The African Journal of Information and Communication, 20, pp. 83–112. 10.23962/10539/23574. (SciELO)
[75] Tikkinen-Piri, C., Rohunen, A. and Markkula, J. (2018) ‘EU General Data Protection Regulation: Changes and implications for personal data collecting companies’, Computer Law & Security Review, 34(1), pp. 134–153. 10.1016/j.clsr.2017.05.015. (ScienceDirect)
[76] Tøndel, I.A., Line, M.B. and Jaatun, M.G. (2014) ‘Information security incident management: Current practice as reported in the literature’, Computers & Security, 45, pp. 42– 57. (ScienceDirect)
[77] Turel, O. and Bart, C. (2014) ‘Board-level IT governance and organizational performance’, European Journal of Information Systems, 23(2), pp. 223–239. (Taylor & Francis Online)
[78] Udoh, V. (2021) ‘Data protection in Nigeria: A review of the Nigerian Data Protection Regulation 2019’, SSRN Electronic Journal.
[79] Varga, S., Brynielsson, J. and Franke, U. (2021) ‘Cyber-threat perception and risk management in the Swedish financial sector’, Computers & Security, 105, 102239. 10.1016/j.cose.2021.102239. (ScienceDirect)
[80] von Solms, S.H.B. (2015) ‘A maturity model for part of the African Union Convention on Cyber Security’, in 2015 Science and Information Conference (SAI). IEEE, pp. 1316– 1320. Xplore)
[81] Warikandwa, T.V. (2021) ‘Personal data security in South Africa’s financial services market: The Protection of Personal Information Act 4 of 2013 and the European Union General Data Protection Regulation compared’, Potchefstroom Electronic Law Journal, 24, pp. 1–32. 3781/2021/v24i0a10727. (Per Journal)
[82] Woods, D., Agrafiotis, I., Nurse, J.R.C. and Creese, S. (2017) ‘Mapping the coverage of security controls in cyber insurance proposal forms’, Journal of Internet Services and Applications, 8, Article 8, pp. 1–13. 10.1186/s13174-017-0059-y. (Springer)
How to cite this paper
@article{1722621,
author = {Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji},
title = {Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape},
journal = {Iconic Research And Engineering Journals},
year = {2021},
volume = {5},
number = {2},
pages = {401-420},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722621.pdf},
abstract = {This review critically examines the maturity of cyber risk management within Nigeria’s insurance sector, with particular attention to the extent to which organisational practices align with prevailing supervisory, data-protection, and resilience expectations. It seeks to determine whether insurers are progressing beyond formal compliance toward embedded, measurable, and adaptive cyber-risk capabilities. The study adopts a structured narrative review approach, synthesising scholarly literature, regulatory instruments, industry guidance, and established cybersecurity maturity frameworks to evaluate governance, threat exposure, privacy protection, incident management, operational resilience, workforce capability, and regulatory alignment. The findings indicate that cyber maturity within the sector is shaped by the quality of board oversight, integration of cyber risk into enterprise risk management, effectiveness of technical and organisational controls, third-party governance, and the ability to detect, respond to, and recover from disruptive events. The review further identifies significant barriers, including fragmented accountability, uneven security investment, skills shortages, weak security cultures, legacy systems, inconsistent control measurement, and gaps between documented compliance and operational effectiveness. It also establishes that regulatory conformity alone is insufficient to demonstrate resilience where controls are not continuously tested, monitored, and improved. The study concludes that a more mature cyber-risk posture requires coordinated governance, risk-based supervision, measurable maturity assessments, stronger privacy-by-design practices, continuous monitoring, and tested incident-response and recovery capabilities. It recommends enhanced board accountability, sector-wide threat intelligence, structured third-party assurance, sustained cybersecurity workforce development, and closer alignment between supervisory expectations and evidence-based resilience metrics. These measures are essential for strengthening policyholder protection, operational continuity, regulatory confidence, and the long-term stability of Nigeria’s increasingly digital insurance ecosystem amid increasingly sophisticated cyber threats.},
keywords = {cyber risk management; cyber maturity; nigerian insurance sector; NAICOM; data protection; operational resilience},
month = {August},
doi = {https://doi.org/10.64388/IREV5I2-1722621}
}