Staff training built for NDPA, CBN, and the fraud Nigerian teams actually see
From BVN and OTP scams to POS "wrong transfer" fraud and SIM-swap attacks, Nigerian organizations face a specific threat pattern. Cyberwareness pairs that reality with the data-protection and sector regulatory pressure your compliance team is already tracking.
Two regulations are pushing training up the priority list
NDPA 2023 + GAID 2025
The Nigeria Data Protection Act requires appropriate technical and organizational measures to protect personal data, and the NDPC's enforcement activity, including compliance notices reported to have reached 1,368 organizations, signals this is being actively checked, not just written into policy documents.
NDPA staff training page →CBN Risk-Based Cybersecurity Framework
Banks and payment service providers operate under a CBN framework that expects a risk-based security program, including staff cybersecurity awareness training as a control, not a one-off event.
CBN cybersecurity awareness page →Training mapped to your regulator and your fraud pattern
Banks
Deposit money banks under the CBN Risk-Based Cybersecurity Framework.
View training →Fintechs, PSPs & MFBs
Payment service providers, microfinance banks, and licensed fintechs.
View training →Insurance
Insurers and brokers handling sensitive personal and financial data.
View training →Pension PFAs
Pension fund administrators under PenCom oversight.
View training →Telcos
Telecom operators handling subscriber data under NCC guidance.
View training →Fraud patterns that are specific to Nigeria, taught as dedicated modules
- POS & bank-alert fraud - recognizing fake POS alerts and "wrong transfer, please refund" scams.
- SIM-swap fraud - spotting a SIM swap in progress and protecting the mobile line tied to banking.
- BVN/NIN/OTP scams - never sharing a BVN, NIN, or OTP with anyone, including someone claiming to be bank staff.
- Fake recruitment & loan-app scams - spotting fraudulent job offers and predatory loan apps that harvest contacts and data.
- Impersonation of CBN/EFCC - recognizing fake regulator calls or letters demanding payment or account access.
Frequently asked questions
Does NDPA require staff cybersecurity training?
The Nigeria Data Protection Act 2023 requires data controllers and processors to implement appropriate technical and organizational measures, which training programs commonly support. The NDPC General Application and Implementation Directive (GAID) 2025 addresses accountability obligations in more detail. We treat "at least yearly" staff training as a cautious planning assumption rather than a quoted legal requirement, since the exact clause on training frequency is something we recommend you verify directly with the NDPC or your compliance advisor.
What did the NDPC compliance notices in 2026 cover?
Reporting indicates the Nigeria Data Protection Commission sent compliance notices to a large number of organizations (1,368 firms, by public reporting) as part of its enforcement push. This is a strong signal that data protection accountability, including staff training, is an active regulatory priority, not a box to check once.
Does the CBN cybersecurity framework require awareness training?
Yes. The CBN Risk-Based Cybersecurity Framework and Guidelines for banks and payment service providers calls for staff cybersecurity awareness training as part of a risk-based security program. The framework has been updated over time; verify the current circular and clause number with your compliance team before citing a specific section to an examiner.
Is this training only for banks?
No. We built sector-specific modules for banks, fintechs, insurance, pensions, and telcos, plus Nigeria-wide spotlights on POS fraud, SIM-swap fraud, BVN/NIN/OTP scams, and fake recruitment or loan-app scams that apply to any Nigerian organization.