How Nigerian Businesses Can Fight Cyber Attacks - Experts

How Nigerian Businesses Can Fight Cyber Attacks - Experts

By Aproko Man· 24 Jul 2026(updated 6m ago)· 6 min read· 👁 16 views
Sponsored — In Article

Cybersecurity experts are talking about how Nigerian companies, regulators, and other groups can boost their online safety. They aim to help prevent the increasing number of cyber attacks happening in the country.

These experts shared their views after a rise in cyber incidents across Nigeria. The quick growth of digital technology has changed how businesses operate, making services like banking and registration faster and easier.

But this digital shift has also created new cybersecurity challenges. Both public and private organizations have faced cyber attacks in recent months. Many of these incidents have raised serious concerns.

One of the notable cases is by a hacker called ByteToBreach. This hacker claimed responsibility for attacks on several organizations, including Remita, Sterling Bank, Zenith Bank, the Oyo State Government, Leadway Assurance, GetBumpa, Ahmadu Bello University (ABU), Zaria, and the Corporate Affairs Commission (CAC).

ByteToBreach also claimed to have over three terabytes of sensitive data allegedly taken from these organizations. Cybersecurity experts looked into these claims and found that the attacks involved issues like unpatched servers, poor management of passwords, and weak access controls in the affected companies.

While investigations are ongoing, it’s important to note that the organizations involved have not publicly confirmed these cyber incidents. The Nigeria Data Protection Commission (NDPC) is the only body that has officially announced an investigation into this matter.

Nigerian institutions often do not inform customers when their personal data is at risk. They rarely apologize or explain how they are addressing any data breaches.

In April, the NDPC announced it started looking into the alleged breaches involving Remita Payment Services Ltd., Sterling Bank, the CAC, and others. According to Nigeria's laws, companies do not always have to notify customers after cyber attacks.

Yet, under the Nigeria Data Protection Act (NDPA) 2023, organizations must inform the NDPC within 72 hours if they discover a personal data breach that could harm individuals. If the breach poses a high risk to people’s rights, companies must also notify those affected quickly.

The CAC was cautious in its announcement about a data breach. They said there was “unauthorised access to limited aspects of its information systems.” But the hacker claimed they had over 25 million documents from the CAC's system.

The CAC handles Nigeria’s corporate registry, holding sensitive information about millions of registered businesses. If this data falls into the wrong hands, it could lead to fraud, identity theft, and other crimes.

In response to these threats, the Federal Government revealed plans to create a Cybersecurity Coordination Council with private sector partners to improve Nigeria's cyber resilience.

Cybersecurity experts are critical of the current approach to cybersecurity in Nigeria. They argue that regulators focus more on compliance than on the real effectiveness of security measures in companies, leaving many vulnerable.

They also believe that regulators depend too much on companies' self-assessments instead of conducting thorough evaluations. This method has been labeled as more for show than for real security improvement.

In March 2026, the Central Bank of Nigeria (CBN) launched a Cybersecurity Self-Assessment Tool (CSAT) that requires banks and financial firms to assess their cybersecurity status to strengthen oversight.

Samuel Tomori, a cybersecurity expert from Ceresense Training Institute, commented on the weaknesses that attackers used. He believes the recent cyber incidents show a deeper problem than just skilled hacking.

He said, “The recent wave of cyberattacks on major Nigerian institutions, including Sterling Bank, the CAC, and Remita, is a brutal wake-up call. But if you look at how these breaches actually happened, the frustrating reality is that the attackers did not use futuristic, unpreventable exploits. They basically walked through doors that were left unlocked.”

Tomori explained that many organizations focus more on following rules than on creating secure systems. He noted that attackers are not using advanced tools. Instead, many companies depend on basic compliance instead of looking closely at their systems.

He warned that Nigerian institutions should stop thinking that systems within their networks are always safe. For years, they believed that if a partner network was connected, it was secure.

He pointed out that the connection between Sterling Bank and Remita showed why this belief is wrong. Once attackers exploit a small, unimportant server, they can use that access to reach more sensitive systems.

Tomori emphasized that organizations need to adopt a Zero Trust mindset. Every request for access must prove its identity every time, even if it comes from a trusted source.

He also highlighted the dangers of poor password management. He said it is like leaving a house key in an obvious place. “Most institutions usually leave their house key under the mat,” he said.

Cybersecurity expert Iretioluwa Akerele also commented on the attacks. She noted that these incidents are not the work of extremely advanced hackers.

She said, “The common thread across the reported incidents is clear. These attacks did not depend on sophisticated nation-state capabilities. Instead, they exploited fundamental gaps in cyber hygiene, governance, and security controls.”

Akerele believes Nigerian organizations need to see cybersecurity as a risk management issue, not just a compliance task. She said regular testing and updates are key to protecting systems.

She advised firms to conduct vulnerability assessments, keep an updated inventory of assets, and monitor their systems for exposed services. This approach aligns with the NDPA 2023, which requires companies to implement strong measures to protect personal data.

Weak identity and access management is a major cause of unauthorized access to systems. Akerele suggested using multi-factor authentication (MFA) for important access, limiting user rights, and quickly removing access for former employees.

She also urged organizations to separate critical systems from user networks and restrict network traffic. Adopting a Zero Trust security model where no user or device is trusted by default is vital.

Akerele warned about the risks of third-party relationships. As businesses rely on vendors, cybersecurity risks can spread beyond their networks. Companies must ensure vendors meet security standards and comply with data protection requirements.

She stressed that organizations remain responsible for protecting personal data, even when using outside services. Cybersecurity should not be an afterthought in software development.

She recommended that security be integrated into every stage of development and that developers follow recognized standards.

“Security should be built into systems by design, not retrofitted after deployment,” she stated.

Akerele also suggested establishing continuous security monitoring and conducting regular training for employees on cybersecurity awareness.

She emphasized that technology cannot fix poor security practices. Organizations should create incident response teams and define clear procedures for handling cybersecurity incidents.

Her goal is not just to stop attacks but also to help organizations recover quickly if they happen. Effective governance is key to improving cyber resilience.

She urged organizations to align their cybersecurity efforts with the NDPA, NDPC Guidelines, and international standards. Regular risk assessments are also necessary to identify potential threats and compliance gaps.

Akerele concluded, “Organizations are most often compromised through known and preventable weaknesses, not advanced attack techniques.”

Sponsored — Mid Article
Did you enjoy this gist?
A
Aproko Man

Bringing you the latest from the Politics and Metro desks.

Drop your comment

Your email won't be shown publicly. Comments may be reviewed before posting.

No comments yet — be the first to drop the gist 👇

Keep Reading