Top cyber threats listed by the United State’s Federal Bureau of Investigation (FBI) are hacktivism, crime, insider, espionage, terrorism and warfare. The world is no longer witnessing an era of changes; it is actually the change of an era, as security becomes cyber security.
Internet of things has become the Internet of bad things, the Internet of threat, and the Internet of everything.
What was seen as emerging threats on Windows are now targeting Android devices, turning mobile security into a high priority.
All infrastructures that are widely used are inherently vulnerable.
Cyberspace has been declared as the fifth territory of war, as the next 9/11 will most likely not happen physically but it will only involve a keyboard on the other side of the world.
There is a lot of work to do but not enough people: there are 1 million unfilled jobs worldwide in the cyber security industry.
What is the state of Nigeria’s preparedness for cyber threats? Is the country putting in place right policies and required infrastructure to align itself with the rest of the world?
These and other questions were analyzed at the ISACA 7th Annual International Conference hosted by its Abuja chapter recently.
While welcoming the attendees to the event, Chimenka Ezeribe, chairman of the conference announced that the theme of the conference, “Cyber security: Aligning Nigeria with the rest of the world”, was adopted with a view to considering the pros and cons of cyber security situation in Nigeria, and other parts of the world, and to provide a way for compliance to international standards and best practices.
Opeyemi Onifade, president and board chairman, ISACA Abuja, explained that Nigeria as a member of the global society is insulated from the opportunities and threats of globalization.
“As the use of IT becomes pervasive and more and more organizations in Nigeria leverage on the Internet to transact and interact with citizens, residents, customers, employees, suppliers and partners, it has become imperative to address our collective capacity to respond to the inevitability of cyber threats, especially Advanced Persistent Threats, APT,” he said.
He admonished the country, saying, “We need to understand that we cannot succeed by accident. The cyberspace is now recognized as the fifth domain of warfare in addition to land, air, sea and space. Unfortunately in Nigeria, our cyberspace domain is still a neglected and unprotected territory whereas we have come to depend so much on mobile telecommunications, electronic banking and e-commerce for our socio-economic for survival.”
Basil Udotai, managing partner, Technology Advisors and a foremost ICT lawyer, spoke on the duties of financial institutions in combating cybercrime.
According to him, Section 19 of the new cyber law prohibits financial institutions to give posting and authorizing access to any single employee while section 20 punishes fraudulent issuance of e-instructions.
He said Section 30 says that any person who manipulates an ATM machine or POS with the intention of defrauding commits an offence.
Also, section 35 deals with sales and purchase of another person’s card; under section 36 any person who with intent to defraud uses any device or attachment email or obtain information of a cardholder commits an offence.
Udotai also revealed that the new law frowns at not disclosure of cyber threat.
According to him, reporting cases of cyber threat is mandatory.
Section 21 of the new law says any person or institution, which operates a computer system or a network, whether public or private, must immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attacks, intrusions and other disruptions liable to hinder the functioning of another computer system or network, so that the National CERT can take the necessary measures to tackle the issues.
“Any person or institution, who fails to report any such incident to the National CERT within 7 days of its occurrence, commits an offence and shall be liable to denial of internet services. Such persons or institution shall in addition, pay a mandatory fine of N2,000,000.00 into the National Cyber Security Fund”.
He said that the Cybercrime Act, though long in coming and beset with certain challenging components, may be applied to effective tackle Nigeria’s cybercrime and cyber security challenges.
However, the key players; ONSA and the OAGF, working with stakeholders, should make deliberate effort to make this a reality
Taiye Lambo, chief information security officer, Office of Information Security City of Atlanta, United State of America, spoke about the critical success factors in aligning Nigeria with global best practices. He argued that there must be visible support and commitment from top management; which he termed a top down approach.
He said institution’s information security policies, objectives and activities must reflect business objectives and there is an approach to implementing information security that is consistent with organizational culture must be put in place.
He said a good understanding of the security requirements, risk assessment and risk management and distribution of guidance on information security policy and standards to all employees and contractors are very critical.
Besides, he recommended a comprehensive and balanced system of measurement, which is used to evaluate performance in information security management and feedback suggestions for improvement.
In his contribution, Iyke Ezeugo, a business intelligence expert revealed that businesses in the country are under pressure to cope with new business trends, challenges and opportunities.
According to him, they need to deal effectively with the emerging big data – transforming the raw data into meaningful and useful information.
They require capacity for interpreting large amounts of unstructured data to help identify, develop and otherwise create new strategic business opportunities.
Osioke Ojior, NIBSS’s chief risk officer, said risk management is a comprehensive process that requires NIBSS to frame risk (that is establish the context for risk-based decisions), assess risk, respond to risk once determined, and monitor risk on an ongoing basis using effective organizational communications and a feedback loop for continuous improvement in the risk-related activities of organizations.
He explained that risk framing produces a risk management strategy that addresses how NIBSS intends to assess, respond and monitor risk - making explicit and transparent the risk perceptions that organizations routinely use to make investment and operational decisions.
According to him, risk assessment identifies threats to operations, assets, individuals or threats directed through the organization or industry against other organizations or the nation.
He averred that risk could also be internal and external vulnerabilities to the payment system, the harm (i.e., consequences and impact) to the payment system that may occur given the potential for threats exploiting vulnerabilities; and the likelihood that harm will occur.
The result is a determination of risk (i.e., the degree of harm and likelihood of harm occurring).
He explained that risk response provides a consistent, organization-wide, response to risk in accordance with the organizational risk frame by developing alternative courses of action for responding to risk; evaluating the alternative courses of action; determining appropriate courses of action consistent with organizational risk tolerance and implementing risk responses based on selected courses of action.
Professor Daniel Okunbor, University of Abuja, in his paper disclosed that the rising usage of social media in Africa has serious security implications.
He argued thatthat Africa caught on social media much quickly than she has been with so many other modem technologies is clearly not a surprise.
Social media penetration in Africa could attributed be largely to the relative cost of the technologies, easy of operations and availability of relevant applications.
He explained that social media platforms are increasingly being used by enterprises to engage with customers, build their brands and communicate information to the rest of the world.
However, social media for enterprises is not all about \'liking,\' \'friending,\' \'up-voting\' or \'digging.\' For organizations, there are real risks to using social media, ranging from damaging the brand to exposing proprietary information to inviting lawsuits.
Cyber Security: Aligning Nigeria With Rest Of The World

Top cyber threats listed by the United State’s Federal Bureau of Investigation (FBI) are hacktivism, crime, insider, espionage, terrorism and warfare. The world is no longer witnessing an era of…
Comms Week
Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

Google Issues Urgent Chrome Update to Block Active Attacks

RockPay Launches, Targets Digital Payments through Social Finance

NDIC Still Paying Depositors of 46 Failed MFBs — Sunday

NITDA Inaugurates Taskforce to Drive Sovereign Cloud Implementation

SEC Proposes N2bn Capital Requirement, N30m Registration Fee for Crypto Firms




