CBN framework

CBN cybersecurity awareness training for banks and payment service providers

The Central Bank of Nigeria's Risk-Based Cybersecurity Framework and Guidelines expects banks and payment service providers to run a risk-based security program. Staff awareness training is a named control in that program, not a box to check once a year.

What we can confirm, and what still needs verification

Confirmed

The CBN Risk-Based Cybersecurity Framework and Guidelines (originally issued 2018 for deposit money banks and payment service providers) establishes a general obligation for staff cybersecurity awareness training as part of a risk-based security program.

Verify before citing as a hard requirement

References to a "2024 update" and its exact circular number are not independently confirmed in our source review. Verify the current circular and clause number on cbn.gov.ng, or with your compliance team, before citing a specific section number to an examiner.

Role-based training that maps to a risk-based program

Frontline & operations

All-Staff Core plus Financial Services Add-On: phishing, POS and SIM-swap fraud, PCI DSS essentials, and CBN framework basics.

Finance & payments

Business email compromise, wire fraud, and a documented callback rule for any change to payment details.

IT & admins

Ransomware first-60-minutes response, privileged-account hygiene, and hardened MFA against push-bombing.

See frontline-ready training before your next review

Book a free demo and we'll show the exact modules mapped to your risk-based program.

Frequently asked questions

What does the CBN Risk-Based Cybersecurity Framework require of staff training?

The framework, issued by the Central Bank of Nigeria for deposit money banks and payment service providers, calls for a risk-based cybersecurity program that includes staff cybersecurity awareness training. The general staff-awareness obligation is well established; the exact current circular number and any 2024 update details should be verified directly on cbn.gov.ng before citing a specific section to an examiner.

Who does the CBN framework apply to?

Primarily deposit money banks and licensed payment service providers regulated by the CBN. Many fintechs, PSPs, and microfinance banks operate under related or adjacent CBN oversight; confirm your specific regulatory category with your compliance team.

How often should frontline staff be trained?

A risk-based program favors ongoing, frequent, short training over a single annual session, which matches the micro-learning approach: an All-Staff Core baseline, then monthly short lessons plus phishing simulations throughout the year.

Does phishing simulation count toward this?

Simulations are widely used as evidence that awareness training is working, not just delivered. Pairing short lessons with a rotating simulation library, each followed by an immediate teachable moment, gives you both the training record and a measurable behavior signal.