International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722621

1722621 Vol 5 · Issue 2 Download Paper

Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape

Samuel Fadero Stanley Nwakamma Demilade Jooda Serif Oyindamola Oyesiji

Subject area: Science,Engineering and Technology  ·  Area of research: Cyber Risk Management

Abstract

This review critically examines the maturity of cyber risk management within Nigeria’s insurance sector, with particular attention to the extent to which organisational practices align with prevailing supervisory, data-protection, and resilience expectations. It seeks to determine whether insurers are progressing beyond formal compliance toward embedded, measurable, and adaptive cyber-risk capabilities. The study adopts a structured narrative review approach, synthesising scholarly literature, regulatory instruments, industry guidance, and established cybersecurity maturity frameworks to evaluate governance, threat exposure, privacy protection, incident management, operational resilience, workforce capability, and regulatory alignment. The findings indicate that cyber maturity within the sector is shaped by the quality of board oversight, integration of cyber risk into enterprise risk management, effectiveness of technical and organisational controls, third-party governance, and the ability to detect, respond to, and recover from disruptive events. The review further identifies significant barriers, including fragmented accountability, uneven security investment, skills shortages, weak security cultures, legacy systems, inconsistent control measurement, and gaps between documented compliance and operational effectiveness. It also establishes that regulatory conformity alone is insufficient to demonstrate resilience where controls are not continuously tested, monitored, and improved. The study concludes that a more mature cyber-risk posture requires coordinated governance, risk-based supervision, measurable maturity assessments, stronger privacy-by-design practices, continuous monitoring, and tested incident-response and recovery capabilities. It recommends enhanced board accountability, sector-wide threat intelligence, structured third-party assurance, sustained cybersecurity workforce development, and closer alignment between supervisory expectations and evidence-based resilience metrics. These measures are essential for strengthening policyholder protection, operational continuity, regulatory confidence, and the long-term stability of Nigeria’s increasingly digital insurance ecosystem amid increasingly sophisticated cyber threats.

Keywords

cyber risk management; cyber maturity; nigerian insurance sector; NAICOM; data protection; operational resilience

How to cite this paper

Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji "Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape" Iconic Research And Engineering Journals Volume 5 Issue 2 2021 Page 401-420
Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji "Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape" Iconic Research And Engineering Journals, vol. 5, no. 2, Aug. 2021
Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji (2021). Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape. Iconic Research And Engineering Journals, 5(2).
Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji "Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape" Iconic Research And Engineering Journals, vol. 5, no. 2, Aug. 2021.
@article{1722621,
      author = {Samuel Fadero, Stanley Nwakamma, Demilade Jooda, Serif Oyindamola Oyesiji},
      title = {Cyber Risk Management Maturity in Nigeria's Insurance Sector: An Assessment Against the NAICOM and NDPR Regulatory Landscape},
      journal = {Iconic Research And Engineering Journals},
      year = {2021},
      volume = {5},
      number = {2},
      pages = {401-420},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722621.pdf},
      abstract = {This review critically examines the maturity of cyber risk management within Nigeria’s insurance sector, with particular attention to the extent to which organisational practices align with prevailing supervisory, data-protection, and resilience expectations. It seeks to determine whether insurers are progressing beyond formal compliance toward embedded, measurable, and adaptive cyber-risk capabilities. The study adopts a structured narrative review approach, synthesising scholarly literature, regulatory instruments, industry guidance, and established cybersecurity maturity frameworks to evaluate governance, threat exposure, privacy protection, incident management, operational resilience, workforce capability, and regulatory alignment. The findings indicate that cyber maturity within the sector is shaped by the quality of board oversight, integration of cyber risk into enterprise risk management, effectiveness of technical and organisational controls, third-party governance, and the ability to detect, respond to, and recover from disruptive events. The review further identifies significant barriers, including fragmented accountability, uneven security investment, skills shortages, weak security cultures, legacy systems, inconsistent control measurement, and gaps between documented compliance and operational effectiveness. It also establishes that regulatory conformity alone is insufficient to demonstrate resilience where controls are not continuously tested, monitored, and improved. The study concludes that a more mature cyber-risk posture requires coordinated governance, risk-based supervision, measurable maturity assessments, stronger privacy-by-design practices, continuous monitoring, and tested incident-response and recovery capabilities. It recommends enhanced board accountability, sector-wide threat intelligence, structured third-party assurance, sustained cybersecurity workforce development, and closer alignment between supervisory expectations and evidence-based resilience metrics. These measures are essential for strengthening policyholder protection, operational continuity, regulatory confidence, and the long-term stability of Nigeria’s increasingly digital insurance ecosystem amid increasingly sophisticated cyber threats.},
      keywords = {cyber risk management; cyber maturity; nigerian insurance sector; NAICOM; data protection; operational resilience},
      month = {August},
  }