Banking

Security awareness training built around the CBN cybersecurity framework

Deposit money banks carry the heaviest regulatory expectation for staff cybersecurity awareness in Nigeria. Frontline, operations, and IT staff all need training that matches both the CBN framework and the fraud patterns customers report every day.

What bank staff actually face

  • Phishing and BEC-style emails targeting operations and finance staff, often impersonating internal departments or known vendors.
  • Customers reporting "wrong transfer, please refund" and fake POS alert scams that frontline and call-center staff must recognize and correctly route.
  • SIM-swap attempts targeting both customers and staff whose mobile line is tied to internal MFA or banking apps.
  • Callers impersonating CBN or law enforcement, pressuring staff to bypass normal verification steps.
  • Social engineering aimed at branch and call-center staff who have standing access to customer account data.

CBN Risk-Based Cybersecurity Framework

The CBN framework expects banks to run a risk-based cybersecurity program, including staff awareness training. We map modules openly to this framework and recommend you verify the current circular and clause number with your compliance team before citing it to an examiner.

Read the full CBN cybersecurity awareness page →

Ready to see this training in action?

Book a free demo and we'll show you the exact modules your team would complete.

Frequently asked questions

Does this training satisfy CBN cybersecurity training requirements?

It is built to support the staff-awareness expectations in the CBN Risk-Based Cybersecurity Framework. We recommend confirming the exact current clause wording with your compliance or legal team before representing this as satisfying a specific examiner requirement.

Can frontline and call-center staff get a shorter, role-specific version?

Yes. All-Staff Core covers the shared fraud patterns (phishing, POS fraud, SIM-swap, BVN/OTP scams) in short modules, and the Financial Services Add-On layers on frontline-specific content without duplicating the basics.

How do you handle sensitive banking scenarios in training without real customer data?

All phishing and fraud scenarios use fictional names, banks, and domains. No real customer data, logos, or live links are used in simulations.