Skip to main content

INDUSTRIES

Financial Services

Commercial banks, microfinance banks, mortgage banks, insurers and fintechs rely on us for branch connectivity, managed security operations, payment integration and the evidence packs their regulators and auditors demand.

Where Technology Bites in Nigerian Banking

The Central Bank of Nigeria’s Risk-Based Cybersecurity Framework changed the conversation in Nigerian banking. A board-approved cyber policy, a functioning security operations capability, defined incident reporting windows, periodic penetration testing and an accountable Chief Information Security Officer are no longer aspirations for the tier-one banks alone; they apply to microfinance and mortgage banks whose entire IT department may be four people. Most institutions in that position cannot justify a 24-hour in-house security operations centre, but they still have to answer the examiner. That gap is the single most common reason a financial institution first calls us.

The second pressure is the payment rails. Nigerian retail finance runs on NIBSS Instant Payments, the BVN framework and the card schemes, and customers judge an institution entirely on whether a transfer completes. A branch link that flaps for forty seconds during a settlement window produces failed transactions, duplicate debits, an angry contact centre and a dispute queue that takes days to clear. Agent banking multiplies the exposure: thousands of terminals in markets and filling stations, each one a transaction endpoint, each one subject to onboarding, limit and geolocation record-keeping rules that must be demonstrable on request.

Third is the cost of card compliance. Any institution that stores, processes or transmits cardholder data faces PCI DSS v4.0 — network segmentation, encryption and key management, logging, quarterly approved scanning vendor scans and an annual assessment. The technical work is unglamorous and the evidence collation is worse, but a lapsed attestation can cost a card scheme relationship. We do segmentation design, remediation and evidence assembly for the assessor, and we run the monitoring that keeps the environment in scope-compliant condition between assessments.

What We Deliver for Financial Institutions

Five offerings, all of them things we run in production for Nigerian financial services clients today.

Financial Services Delivery

4

Licensed Banks

Live on one shared platform

7

Delivered Systems

Banking, payments and foreign exchange

12

Currencies Supported

Eight fiat and four crypto in the FX platform

1

Shared Codebase

With database-per-tenant isolation

Regulatory Obligations We Work Against

What Nigerian financial regulation requires of your technology function, and the specific work we do to satisfy it.

Requirement Regulator or standard What it obliges What we provide
Risk-Based Cybersecurity Framework Central Bank of Nigeria Board-approved policy, security operations capability, incident reporting within defined windows, periodic penetration testing 24/7 monitored SOC, quarterly vulnerability assessment, annual penetration test, incident reports in the prescribed format
Cardholder data security PCI DSS v4.0 and the card schemes Segmentation, encryption and key management, logging, quarterly ASV scans, annual assessment Scoping and segmentation design, remediation, scan management and evidence collation for the assessor
Instant payment participation NIBSS scheme rules Availability, response time and dispute-handling obligations on the NIP rails Redundant links to NIBSS, monitored transaction queues, replay and reconciliation tooling
Customer identity CBN and NIBSS BVN framework Enrolment, verification and periodic refresh of customer identity records BVN validation service integration with audit logging and exception queues
Agent banking CBN Guidelines for the Regulation of Agent Banking Agent onboarding records, transaction limits, geolocation and reporting Agent management module with geotagged transactions, limit enforcement and regulator-ready extracts
Business continuity CBN Guidelines on Business Continuity Management Documented recovery objectives and tested failover Recovery site design, RTO and RPO measurement, twice-yearly live failover test with written report
Customer data protection Nigeria Data Protection Act 2023; NDPC Lawful basis, impact assessment, breach notification, annual audit filing Data protection impact assessment, ISO/IEC 27001:2022 aligned controls, documented breach runbook
Outsourcing oversight CBN guidelines on outsourcing in the financial sector Due diligence, defined service levels and right of audit over service providers Contracted SLAs with penalties, quarterly service review, right-of-audit clause and our ISO certificates on file

Reference Deployment: Four Licensed Microfinance Banks

Nigerian microfinance banks hold a core banking licence and a core banking system, and very often have no practical way to put a modern application into a customer’s hand. Licensing a channel platform per bank is unaffordable at their scale, and commissioning a bespoke build per bank is worse, because each one then carries its own security posture, its own integration defects and its own maintenance burden.

We built one multi-tenant middleware that sits between customer channels and the core banking system, and four CBN-licensed banks run on it: Ultra Pay Microfinance Bank, Tudun Wada Microfinance Bank, Kura Microfinance Bank and Quantum Microfinance Bank. Each is isolated at the database level with its own secrets, its own branded portal and its own institution code for inter-bank settlement, while sharing one codebase, one deployment pipeline and one security posture.

The platform handles tiered know-your-customer onboarding to the Central Bank of Nigeria model, account services, intra-bank and inter-bank transfers with name enquiry, and loan products with amortisation and loss classification. Every state-changing operation writes to an append-only, hash-chained audit log, because a bank that cannot reconstruct exactly what happened cannot answer its examiner, and an audit trail that can be edited is not an audit trail.

  • Four CBN-licensed microfinance banks live on a single shared codebase
  • Database-per-tenant isolation, with separate secrets and separate branded portals
  • CBN tiered KYC, with bank verification and national identity number interfaces
  • Intra-bank and inter-bank transfers with name enquiry, plus loans and deposits
  • Append-only, hash-chained audit log across every state-changing operation
  • Mobile and internet banking channels delivered per bank on the shared platform
Reference Deployment: Four Licensed Microfinance Banks

Questions Financial Services Clients Ask

We are a microfinance bank. Is a managed SOC affordable at our size?
Yes. Our security operations service is priced by monitored endpoint and log volume, not by institution size, so a bank with 40 endpoints pays a fraction of what a 60-branch commercial bank pays. For most microfinance banks the monthly cost is well below that of a single dedicated security analyst, and it comes with 24-hour coverage that one analyst cannot provide.
Will you sign our outsourcing and right-of-audit agreement?
We do routinely. We hold ISO 9001:2015 and ISO/IEC 27001:2022 certification, we accept contractual service levels with financial penalties, and we accommodate client and regulator audits of the services we provide. Our compliance team at [email protected] maintains the standing due-diligence pack most institutions request at onboarding.
Can you work alongside our existing core banking vendor?
Almost always, and that is the normal arrangement. We do not sell a core banking application, which makes us a neutral integrator. We build and operate the middleware between your core, the payment rails and third-party platforms, and we are happy to sit in a tripartite service review with the core vendor so that incidents are resolved rather than passed between suppliers.
How quickly can you respond to a security incident out of hours?
Priority-1 incidents are acknowledged within 15 minutes and worked continuously until contained; our measured mean response across FY2025 was 11 minutes. Containment actions agreed in advance — isolating a host, disabling an account, blocking a destination — are executed under a standing authority so the analyst does not wait for a callback at 03:00.
Do you handle the PCI DSS assessment itself?
No, and no honest provider should. The assessment must be performed by a qualified security assessor independent of the party that built the controls. We do the readiness work — scoping, segmentation, remediation, logging, scan management — and assemble the evidence so that the assessor’s time on site is short and productive. We can recommend assessors we have worked with.
What happens to our data if we end the contract?
Logs, configurations and any data we hold on your behalf are returned in open formats within 30 days of termination, and we provide a written certificate of secure destruction thereafter. Exit assistance is a contracted deliverable, not a favour, and we will run a documented transition with an incoming provider.

Talk to our financial services team

Chinedu Okafor Nwosu, Regional Director for Lagos and Financial Services, leads this practice from Victoria Island. Ask for a posture review against the CBN framework.