Learning Objectives:
-
Understand the specific responsibilities of the Board of Directors for cybersecurity oversight.
-
Identify the responsibilities of Senior Management in implementing cybersecurity programmes.
-
Recognise the importance of board composition and expertise in cybersecurity.
-
Understand reporting and accountability requirements for cyber risk oversight.
2.1 The Board’s Role in Cybersecurity Oversight
The Board of Directors bears ultimate responsibility for the institution’s cybersecurity programme. The Central Bank of Nigeria’s Framework states that “the Board, through the Board Risk or Information Technology committee, shall have oversight and responsibility for the SFI’s cybersecurity programme” . The board shall provide leadership, direction, and resources for the effective conduct of required processes and ensure that cybersecurity governance is integrated into the organisational structure .
The board’s specific responsibilities include:
Board Composition and Expertise: At least two Non-Executive Directors (NEDs), one of whom shall be an Independent NED, shall have requisite knowledge and experience in innovative financial technology, Information Communication Technology (ICT), and/or cybersecurity . This requirement reflects the recognition that effective cybersecurity oversight requires directors with relevant expertise.
Strategic Oversight: The board is responsible for the institution’s cybersecurity strategy and shall ensure that the strategy provides direction on how to achieve the cybersecurity goals, mitigate cyber-risk, and comply with all legal, contractual, statutory, and regulatory requirements . The approved cybersecurity framework should align with business objectives and technological approaches to mitigate cyber risks and clearly define key cybersecurity roles and responsibilities .
Policy Approval: The board shall ensure that the cybersecurity policy clearly conveys its intent and the institution’s approach to achieving cybersecurity objectives . The policy should be reviewed annually at a minimum, or when there are significant changes to the institution’s cyber-risk exposure .
Resource Allocation:Â The board shall approve a stand-alone cybersecurity budget that is distinct from the budget of other functions (e.g., Information Technology or Risk Management)Â . This ensures that cybersecurity receives dedicated resources and attention.
Risk Appetite: The board shall ensure that the cybersecurity risk appetite is defined in the institution’s Enterprise-wide Risk Management (ERM) framework .
Reporting and Monitoring: Quarterly reports detailing the overall status of the cybersecurity programme must be presented by Senior Management . The reports shall include cyber risk assessment reports, status of security initiatives, incidents recorded, vulnerability management reports, compliance status, and status of compliance with examination recommendations .
2.2 Senior Management’s Implementation Responsibilities
Senior Management is responsible for implementing the board-approved cybersecurity policies, programmes, and standards. The Central Bank of Nigeria’s Framework assigns several specific responsibilities to Senior Management :
Implementation: Senior Management shall be responsible for implementing Board-approved cybersecurity policies, programmes, standards and the delineation of cybersecurity responsibilities .
CISO Appointment: Senior Management shall recommend to the Board the appointment of a CISO that meets the regulatory requirements .
Reporting: Senior Management shall provide periodic reports (at a minimum quarterly) to the Board on the overall status of the cybersecurity programme .
Training: Senior Management shall ensure that staff of the Information Security function attend relevant training programmes regularly .
Risk Integration: Senior Management shall incorporate cyber-risk management in the ERM framework and governance requirements to ensure consistent management of risk across the institution . They shall also drive cyber risk management processes to ensure adherence to cybersecurity risk appetite .
2.3 The Role of Board Committees
The Board typically delegates cybersecurity oversight to specialised committees. The Central Bank of Nigeria’s Framework notes that the Board, through the Board Risk or Information Technology committee, shall have oversight and responsibility for the institution’s cybersecurity programme .
The committee structure ensures focused attention on cybersecurity issues. The board shall ensure that the audit function is independent and staffed with skilled professionals who possess relevant qualifications and experience . This independent audit function provides assurance that cybersecurity controls are operating effectively.
2.4 Accountability and Reporting
Regulators have established clear accountability expectations for boards and senior management regarding cybersecurity. The Central Bank of Nigeria’s Framework requires quarterly reports from Senior Management to the Board covering the overall status of the cybersecurity programme . These reports must include detailed information on risk assessments, security initiatives, incidents, vulnerability management, compliance status, and status of compliance with examination recommendations .
The board is also responsible for ensuring that cybersecurity management processes are conducted in line with business requirements, applicable laws, and regulations while ensuring security targets are defined and met across the institution . Senior Management provides central oversight for the cybersecurity programme, assigns responsibilities, and ensures the effectiveness of the cybersecurity management processes .