Cybersecurity_Basics_Every_Nigerian_CEO_Should_Understand_-_No_Techical_Jargon

Cybersecurity for Nigerian CEOs: 10 Things You Need to Understand

Share
Tweet
Share
Chat
Chat
Email

Nigeria’s fraud picture is improving, and the shape of the improvement tells you where to focus.

NIBSS reported digital payment fraud losses of ₦25.85 billion in 2025 — down 51% from ₦52.26 billion the year before. Case volumes fell only 4%, to 67,518. Internet banking fraud led by value at ₦13.37 billion across 4,507 cases. Lagos accounted for 63% of fraud volumes. Over a longer window, the CBN’s Nigeria Payments System Vision 2028 document put attempted fraud at ₦187.79 billion and actual losses at ₦134.48 billion between 2020 and 2025.

Read those numbers carefully and one thing stands out: cases are flat while value swings wildly. NIBSS noted that the 2024 spike was driven largely by a single ₦31.1 billion incident at one entity. That is the modern risk profile — not a constant drizzle of small losses, but a small number of well-targeted, high-value attacks aimed at whoever can authorise a large payment.

In most Nigerian SMEs, that person is you. This article is in three parts: your own exposure as CEO, the controls you are accountable for even though you will never configure them, and the decisions only you can make. You do not need to become an expert. You need to know what to ask and what to decide.

Part 1: You are part of the attack surface

Most cybersecurity advice written for CEOs is really staff advice with a CEO label on it. This part is not. These four items are about your position specifically.

1. You are the most impersonated person in your company

Criminals do not need to breach your systems to steal from you. They need one employee to believe a message came from you.

The pattern is consistent: fraudsters send messages impersonating the CEO, mark them as urgent, time them to coincide with your travel or board meetings, and request a transfer or a change to a supplier’s bank details. It works because it exploits the two things your position creates — authority and the reluctance of a junior employee to question you. The variant that costs Nigerian businesses the most is the supplier bank-detail change: an email from a real supplier’s compromised account, or a convincing lookalike domain, notifying you of new account details ahead of a legitimate invoice you were already expecting.

The control that works is procedural, not technical: any payment above a threshold you set and any change to bank details require verification through a second channel — a phone call to a number already on file, never a number supplied in the message itself. Make this a company-wide rule: employees must verify any instruction that appears to come from the CEO, and clearly state that no employee will face penalties for verifying such a request. Without that second part, the rule does not survive contact with a genuinely urgent payment.

Ask your team: What procedure do we use to verify payment instructions and changes to bank details, and when did we last test it?

2. The exemption you asked for is the hole in your defences

This one is uncomfortable and worth saying plainly. In many organizations, senior executives have the weakest account security because they find multi-factor authentication inconvenient and ask IT teams to exempt them from using it.

Your account has the broadest access in the business, sends the most trusted instructions, and is the most valuable single target. An exemption for you is not a minor convenience. It is a targeted removal of protection from the highest-value account in the company. The same applies to shadow arrangements: forwarding work email to a personal Gmail account so it is easier to read at home, sharing a login with an assistant instead of granting proper delegated access, or keeping company documents in a personal cloud account. Each is understandable and each sits entirely outside your organisation’s security controls, audit logs and legal protections.

Ask your team: which accounts are currently exempt from our security policies, and why?

3. Your travel and your devices are part of the risk

Executives work from airports, hotels and personal phones more than anyone else in the business. That is not a failing — it is the job. But it means your devices need to be managed rather than merely owned.

The practical questions are simple. If your phone or laptop is stolen tomorrow, can company data be wiped remotely? Is the device encrypted and properly secured? Is it enrolled in your organisation’s device management system, or is it simply a personal phone with the company’s email app installed? Also, has your travel itinerary been discussed on communication channels that unauthorised individuals could potentially access? After all, knowing that “the CEO is abroad” can make impersonation attempts much more convincing.

Ask your team: if my phone were stolen this evening, what exactly would happen?

4. Your calendar and public profile are reconnaissance material

Targeted attacks begin with research. Your LinkedIn profile, conference appearances, press interviews, the name of your executive assistant, your supplier relationships and your travel schedule are all publicly available and all useful to someone building a convincing impersonation.

You cannot and should not go dark — visibility is part of running a business. But it is worth knowing that the more public your profile, the more plausible an impersonation of you becomes, and the more your organisation needs the verification habit in item 1.

Part 2: The controls you are accountable for

You will never configure any of these. You are still accountable for whether they exist, because each requires budget or a decision that only you can authorise.

5. Your people are the most common entry point

Most incidents start with an ordinary mistake — a clicked link, an opened attachment, an approved login prompt nobody initiated, a password reused from a personal account that appeared in a breach years ago.

Training reduces this, but only the kind that is regular, practical and safe to fail. Annual slide decks change nothing. Simulated phishing with a blame-free reporting route changes a great deal, because the goal is not to catch people out — it is to make reporting a suspected mistake the fastest reflex in the building. The most expensive incidents are usually the ones where someone realised at 4pm and said nothing until the following morning.

6. Access matters more than passwords

Password advice has moved on. Length and uniqueness matter more than complexity, forced rotation is now discouraged because it drives predictable patterns, and a password manager solves the practical problem for a whole team at negligible cost.

But the honest position is that passwords matter less than they used to, precisely because multi-factor authentication matters so much more. MFA is the single highest-return control available to a business of your size. It should be enforced — not offered — on email, cloud storage, financial platforms, administrative accounts and social media, including for you. Where your platforms support passkeys, they are stronger still and easier to use than what you have now.

One nuance worth knowing: attackers have adapted to MFA by simply flooding people with approval prompts until someone taps yes. Number matching and app-based approval defeat this; SMS codes are the weakest option and worth moving away from where you can.

7. Know who has access — especially who used to

When someone joins, they get access. When they leave, the removal is often partial, delayed or forgotten entirely. Former employees retaining access to email, shared drives, customer databases or financial platforms is one of the most common findings in any access review, and one of the easiest to exploit.

The fix is to treat joiners, movers and leavers as a defined process with a checklist and an owner, rather than as an informal request to IT. Movers matter as much as leavers: someone who has changed roles three times in five years usually still holds the access from all three.

Ask your team: run a list of every active account and show me which ones belong to people who have left.

8. Customer information should be on a need-to-know basis

Not everyone in your organisation needs access to customer records, payroll, board papers or financial data. In most SMEs they effectively have it anyway, because years of “just share it with everyone so nobody gets blocked” have left shared drives far more open than anyone intends.

This has become more urgent with AI tools. Assistants like Microsoft 365 Copilot and Google Gemini operate within your existing permissions — which means they will cheerfully surface the salary spreadsheet to anyone who asks the right question, because technically that person always had access and simply never found the file. AI does not break your permissions. It makes them visible.

9. Backups only count if you have restored one

Most businesses have backups. Far fewer have ever tested a restore, and a backup that has never been restored is a hypothesis rather than a control.

Three questions decide whether yours would survive a serious incident: how much data would you lose (how far back does the last good copy go), how long would a full restore take, and is at least one copy isolated so that ransomware reaching your network cannot reach the backups too. That last point is where most businesses are exposed — backups sitting on the same network, with the same credentials, get encrypted alongside everything else.

Ask your team: when did we last perform a full test restore, and how long did it take?

10. Your vendors’ weaknesses become yours

Your accountant, payroll provider, software vendors, marketing agency and IT contractor may hold your customer data or hold access to your systems. Their security failures land on you — commercially, reputationally and, where personal data is involved, legally.

Before granting access, establish what data they can reach, what protections they maintain, whether they would tell you promptly about a breach on their side, and what the contract actually says about it. For anyone processing personal data on your behalf, that last point is a regulatory requirement, not just good practice.

Keeping software updated belongs here too — it is unglamorous, it is the reason a large share of successful attacks succeed, and it needs an owner and a schedule rather than good intentions.

Part 3: The decisions only you can make

This is the part that genuinely cannot be delegated. Each of these is a business judgement, not a technical one, and each is far cheaper to make now than during an incident.

11. Who owns cyber risk, and how often do you hear about it?

In most Nigerian SMEs the honest answer is that nobody owns it and it is discussed when something breaks. Name an owner at senior management level — not necessarily technical — and put a short standing item on your management meeting agenda. What you measure gets attention.

12. The 72-hour clock

Under the Nigeria Data Protection Act, the NDPC must be notified within 72 hours of your organisation becoming aware of a personal data breach. Three days is short. It includes the time spent working out what happened, which is usually most of it. If nobody has decided in advance who assesses the incident, who drafts the notification and who signs it off, the deadline will pass while people are still assembling facts.

Notification also has commercial consequences — customers may need to be told, and how that is handled affects whether they stay. This is a CEO decision, made in advance. Read our insight: Guide to NDPA and GAID 2025 Compliance

13. Would you pay a ransom?

Decide this before it happens, with your board and your counsel, not at 2am with systems down. Consider that payment does not guarantee recovery, may carry legal exposure, and marks you as a business that pays. Consider equally that tested backups are what make refusing realistic. The decision and the backup strategy are the same conversation.

14. Cyber insurance — and what it excludes

Cyber cover is increasingly available to Nigerian businesses and is worth evaluating. Read the exclusions before you rely on it. Policies commonly exclude losses arising from unpatched systems, absent multi-factor authentication, or misrepresentation on the application form — and authorised-payment fraud, where an employee was tricked into sending money legitimately, is often treated very differently from a system breach. Insurance is a complement to controls, never a substitute, and insurers increasingly price on whether the controls exist.

15. Who speaks, and to whom?

During an incident, someone must talk to staff, customers, the bank, the regulator and possibly the press — and the worst time to work out who is while the phones are ringing. Write down the names and the order. Include your bank’s fraud desk number and your legal contact. Keep the list somewhere that does not depend on the systems that may be unavailable.

16. What is a proportionate budget?

There is no universal percentage. The usable test is whether your spend is proportionate to what a serious incident would cost you — a week of downtime, the regulatory exposure, the customer losses, the recovery. Most Nigerian SMEs are underspending relative to that number, but the answer is rarely to buy more tools. It is usually to configure properly what you already own, since most businesses on Microsoft 365 or Google Workspace are paying for security capabilities they have never switched on.

The ten questions to ask your IT team

You do not need to understand the answers technically. You need to notice when there isn’t one.

  1. What are our most important business systems and data, and where do they live?
  2. Who has access to them — and which accounts belong to people who have left?
  3. Is multi-factor authentication enforced on every account, including mine and every administrator?
  4. When did we last perform a full test restore from backup, and how long did it take?
  5. What is our verification procedure for payment instructions and changes to supplier bank details?
  6. How do we train staff to spot threats, and how do they report a mistake without fear?
  7. What exactly happens to access when someone leaves or changes role?
  8. Which third parties can reach our systems or our customer data?
  9. Could we detect a breach and notify the NDPC within 72 hours — and who would do it?
  10. When was our security last reviewed by someone who does not work for us?

A short pause on any of these is more informative than the answer. The ones that most often produce silence are questions 2, 4 and 9.

Cybersecurity is a business responsibility

None of this requires you to become technical. It requires you to accept that the tone comes from the top; how seriously the organisation treats security, what gets funded, whether an employee feels able to question an urgent instruction that appears to come from you, and whether anyone has thought about the first hour of a bad day before it arrives.

For a Nigerian business, cybersecurity is not really about protecting computers. It is about protecting money, customers, reputation and continuity — and those have always been the CEO’s job.

Frequently asked questions

What is CEO fraud, and how do Nigerian businesses lose money to it?

CEO fraud, a form of business email compromise, is when a criminal impersonates a senior executive, supplier or business partner to trick an employee into transferring money or releasing information. The message typically claims urgency and often arrives when the executive is known to be unavailable. The most costly Nigerian variant is the fraudulent change of supplier bank details ahead of a genuine invoice. The effective control is procedural: verify payment instructions and bank-detail changes through a separately-held phone number, never one supplied in the message.

How quickly must a Nigerian business report a data breach?

Under the Nigeria Data Protection Act, the NDPC must be notified within 72 hours of the organisation becoming aware of a personal data breach. Because most of that window is consumed establishing what actually happened, decide in advance who assesses an incident, who drafts the notification and who approves it.

How much did Nigerian businesses lose to fraud recently?

NIBSS reported digital payment fraud losses of ₦25.85 billion in 2025, down 51% from ₦52.26 billion in 2024, across 67,518 cases. Internet banking fraud led by value at ₦13.37 billion. Lagos accounted for 63% of fraud volumes. The CBN’s Nigeria Payments System Vision 2028 document recorded ₦134.48 billion in actual losses between 2020 and 2025. Notably, case volumes have been broadly flat while values swing sharply — the risk is concentrated in a small number of high-value, well-targeted attacks.

Should the CEO be exempt from multi-factor authentication?

No. The CEO account has the broadest access and is the single most valuable target in the organisation, so an exemption removes protection from precisely the account that most needs it. If the friction is genuinely unworkable, the answer is a better authentication method — app-based approval with number matching, or passkeys — not an exemption.

Does cyber insurance cover business email compromise?

Sometimes, but it varies substantially and authorised-payment fraud is often treated very differently from a system breach. Policies also commonly exclude losses arising from unpatched systems or missing multi-factor authentication. Read the exclusions before relying on cover, and treat insurance as a complement to controls rather than a replacement for them.

What is the single most valuable security control for a Nigerian SME?

Enforced multi-factor authentication on every account, with no exemptions. It is the highest-return control relative to cost, it is usually already included in the Microsoft 365 or Google Workspace subscription you are paying for, and it defeats the large majority of credential-based attacks. Prefer app-based approval with number matching over SMS codes.

Do AI tools like Copilot create a security risk?

They do not weaken your permissions, but they expose whatever those permissions already allow. Because these assistants operate within existing access rights, they can surface sensitive files to employees who technically always had access but never located them. Audit sharing across your file storage before deploying AI assistants, not afterwards.

Where to start

We help Nigerian businesses close the gap between the security they are paying for and the security they actually have — because in most cases the controls are already included in the Microsoft 365 or Google Workspace licences on the invoice, and simply were never switched on.

Book a free 30-minute cybersecurity review. We will look at how access, multi-factor authentication, sharing and backup are configured in your environment and send you a plain-language summary of what we find — written for you, not for your IT team.

Read related insights

Leave a Comment

Your email address will not be published. Required fields are marked *

Our Latest Insights

Have Questions Speak to Uplicom Specialist

Let's work together on your business requirements

Contact Uplicom Sales Form