Project – Effectiveness of Cybersecurity Controls in Preventing Electronic Financial Fraud in the Nigerian Banking Sector
CHAPTER ONE
INTRODUCTION
1.1 Background of the Study
The banking industry is one of the most technology-dependent sectors of the modern economy. Banks perform critical functions involving deposit mobilisation, credit creation, payment processing, fund transfers, investment and financial intermediation. The increasing adoption of information and communication technologies has transformed these functions from predominantly branch-based activities into highly interconnected digital operations. Customers can now access banking services through automated teller machines (ATMs), point-of-sale (POS) terminals, internet banking, mobile banking applications, USSD platforms, electronic funds transfer systems and other digital channels. This transformation has significantly improved the speed, convenience and accessibility of financial services, but it has also expanded the opportunities available to individuals and organised groups seeking to exploit technological vulnerabilities for financial gain.
Electronic financial fraud refers broadly to fraudulent activities carried out through electronic, digital or computer-mediated financial systems with the intention of obtaining money or other financial benefits unlawfully. It may involve phishing, identity theft, account takeover, card fraud, SIM-swap fraud, malware, social engineering, unauthorised electronic transfers, insider manipulation and other forms of cyber-enabled financial crime. The increasing sophistication of digital banking has consequently created a parallel increase in the sophistication of threats confronting financial institutions. NIBSS (2021) observed that the growth in transaction speed and the availability of multiple electronic payment channels create additional vectors through which fraudulent transactions can occur.
The scale of Nigeria’s digital financial ecosystem illustrates the significance of this challenge. Electronic payment transactions in Nigeria reached approximately ₦1.07 quadrillion in 2024, while the volume of transactions increased to about 11.2 billion, compared with 9.7 billion in 2023 (NIBSS, 2026). This rapid expansion means that enormous volumes of financial transactions are processed electronically every day. While digitalisation enhances financial inclusion and operational efficiency, it simultaneously increases the volume of financial data and transactions that cybercriminals can target.
The growth in digital transactions has been accompanied by substantial financial losses arising from fraud. According to NIBSS data reported at the 2026 Nigeria Electronic Fraud Forum, actual losses to digital payment fraud declined from ₦52.26 billion in 2024 to ₦25.85 billion in 2025, representing a 51 percent reduction. Nevertheless, the 2025 loss remained substantial, while 67,518 fraud incidents were reported during the year. Lagos alone accounted for approximately 63.43 percent of reported fraud activity, highlighting the importance of Lagos as a major centre of electronic financial activity and fraud risk (NIBSS, 2026).
The preceding statistics demonstrate two important realities. First, cybersecurity controls can make a measurable difference in reducing financial fraud. The substantial decline in losses between 2024 and 2025 suggests that strengthened institutional and industry-wide controls may contribute to fraud reduction. Second, the persistence of billions of naira in losses demonstrates that cybersecurity controls have not eliminated the problem. Fraudsters continue to adapt their methods, exploit human vulnerabilities and target weaknesses across digital financial systems. NIBSS has specifically identified phishing, account compromise, SIM-swap fraud and insider involvement among continuing concerns, while stressing the importance of institutional monitoring, staff activity controls and industry collaboration.
Cybersecurity has therefore become an essential component of modern banking risk management. Cybersecurity can be understood as the protection of information systems, networks, applications, devices and data against unauthorised access, disruption, alteration, destruction or misuse. In banking, effective cybersecurity seeks to protect the confidentiality, integrity and availability of financial information and services. A successful cybersecurity programme should not only prevent unauthorised access but also detect suspicious activities, respond rapidly to incidents and facilitate recovery when security breaches occur.
Cybersecurity controls are the technical, administrative and procedural safeguards established by an organisation to reduce information-security and cyber-related risks. In the banking sector, these controls can include access controls, password policies, multi-factor authentication, biometric verification, encryption, firewalls, intrusion detection and prevention systems, transaction monitoring, fraud analytics, security information and event management, endpoint protection, network segmentation, vulnerability management, penetration testing, staff awareness programmes, incident response procedures and continuous security monitoring. Their effectiveness depends not simply on whether they exist but on whether they are properly implemented, regularly updated, monitored and integrated into the bank’s broader risk-management system.
The Central Bank of Nigeria (CBN) has recognised the importance of cybersecurity to the stability of the financial system. The CBN’s Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Banks provides a regulatory framework for managing cybersecurity risks in Nigerian banking institutions. The framework places responsibilities on boards and senior management and requires compliance with relevant cybersecurity laws and regulatory directives. It also provides for monitoring and enforcement of compliance by the CBN.
The regulatory emphasis on cybersecurity reflects the fact that electronic financial fraud can threaten more than the financial position of individual customers. A successful cyberattack may compromise confidential customer information, disrupt banking services, damage institutional reputation, increase legal and regulatory exposure and undermine public confidence in electronic banking. Tade and Adeniyi (2020) found that experiences of electronic banking fraud affected customers’ trust in and willingness to adopt electronic banking services in Nigeria. Their study identified internal, external and collaborative dimensions of electronic fraud and observed that banks had adopted measures such as scam alerts and internal disciplinary actions to strengthen customer confidence.
The consequences of electronic fraud can also extend to the financial performance and stability of banks. Akinwale, Ikpefan and Areghan (2021), in their study of Nigerian deposit money banks using data from 2006 to 2018, found that electronic fraud cases increased over much of the study period and linked the increase partly to the expansion of electronic banking products. The authors examined electronic fraud as a potential contributor to bank failure and highlighted the need for effective measures to curtail electronic fraud.
This relationship between digital banking and fraud is particularly important because banks are increasingly dependent on interconnected technological infrastructure. A bank’s electronic channels are not isolated systems. They interact with telecommunications networks, payment platforms, customer devices, identity-management systems, third-party service providers and other financial institutions. Consequently, a vulnerability in one component may potentially create risks for other interconnected components.
One of the major challenges confronting cybersecurity controls is the rapidly changing nature of cyber threats. Traditional security mechanisms that were effective against earlier forms of fraud may be less effective against contemporary attacks. Fraudsters increasingly combine technological methods with social engineering. For example, phishing messages may be used to obtain login credentials or one-time passwords, while impersonation may be used to persuade customers or employees to disclose confidential information. Insider threats can also arise when authorised employees misuse their legitimate access privileges.
The importance of insider threats is increasingly recognised in the Nigerian banking environment. NIBSS reported in 2026 that insider involvement remained a significant concern and stressed the importance of monitoring staff activities and ensuring that fraud incidents are properly reported. This demonstrates that cybersecurity cannot be treated purely as a technical issue. Human behaviour, organisational culture, employee awareness, access privileges and management controls are also central to effective fraud prevention.
The increasing use of artificial intelligence and data analytics is another important development in electronic fraud prevention. Banks can use automated systems to analyse large volumes of transactions and identify patterns that may indicate fraudulent activity. Such systems can generate alerts when transactions deviate significantly from expected customer behaviour. Data analytics may therefore enable banks to detect suspicious transactions more rapidly than traditional manual approaches.
Ogunnubi and Ogidiolu (2023) examined the potential of data analytics for mitigating electronic fraud risks in Nigerian banking institutions. Their study highlighted real-time monitoring, predictive modelling, anomaly detection and artificial intelligence as technologies capable of supporting fraud detection and cybersecurity. More recent research on AI-driven fraud detection in Nigerian banking similarly identifies technological infrastructure, staff competency, regulatory compliance and top-management support as important factors affecting the adoption of advanced fraud-detection systems (John et al., 2025).
However, sophisticated technology alone does not guarantee effective fraud prevention. A cybersecurity control can fail because of poor implementation, outdated technology, inadequate monitoring, weak access management, insufficient employee training or poor coordination between departments. This means that assessing the effectiveness of cybersecurity controls is more important than merely establishing whether a bank has cybersecurity technologies.
Effectiveness in this context concerns the extent to which cybersecurity controls actually reduce the likelihood and impact of electronic financial fraud. Effective controls should ideally prevent unauthorised transactions, detect suspicious activities quickly, minimise financial losses, facilitate timely response and strengthen customer confidence. A control may be technically sophisticated but ineffective if it generates excessive false alerts, is poorly configured, is not regularly updated or can easily be circumvented by fraudsters.
Information technology controls have consequently attracted scholarly attention in Nigeria. Onajero, Dada and Ogundajo (2022) examined information technology control and fraud risk detection in Nigerian deposit money banks and argued that technological changes in banking have created a need for appropriate IT-based controls to complement traditional approaches. Similarly, Ohwo (2024) examined information security management in quoted Nigerian deposit money banks and argued that the persistence of fraud despite traditional fraud-management approaches creates a need for stronger information-security-based approaches.
Agboare (2023) also reviewed internal control measures for preventing electronic banking fraud in Nigeria and emphasised that the increasing reliance on electronic banking transactions has changed the nature of risks faced by banks and their customers. The study argues for sound internal controls capable of reducing risks associated with electronic banking.
Another important dimension is authentication. Authentication controls seek to verify that an individual attempting to access an account or initiate a transaction is genuinely authorised to do so. Traditional passwords may be vulnerable to phishing, credential theft and password reuse. Consequently, banks increasingly use multi-factor authentication, biometrics, transaction confirmation mechanisms and behavioural analysis. Recent Nigerian research on two-factor authentication reported reductions in online banking fraud following increased use of stronger authentication mechanisms, although the effectiveness varied according to the authentication method used (Egenti & Ojo, 2026).
Access controls are similarly important. The principle of least privilege requires users to receive only the level of access necessary to perform their duties. In banking environments, excessive employee privileges can create opportunities for insider fraud or accidental compromise. Segregation of duties can also reduce risk by ensuring that one employee cannot independently initiate, approve and execute sensitive transactions. Effective access management must therefore combine technical controls with organisational procedures.
Encryption is another important control because financial institutions process sensitive customer and transaction information. Encryption helps protect data from unauthorised access while information is stored or transmitted. Nevertheless, encryption does not prevent all forms of fraud. A fraudster who obtains valid customer credentials through phishing, for example, may be able to conduct transactions through legitimate channels. This illustrates why banking cybersecurity requires multiple layers of protection rather than dependence on a single technology.
Transaction monitoring and anomaly detection provide another layer of defence. These controls can examine transaction amounts, locations, frequencies, devices, beneficiaries and behavioural patterns to identify unusual activity. When properly designed, they can enable banks to identify suspicious transactions before significant losses occur. However, poorly designed systems can produce false positives, potentially inconveniencing legitimate customers and increasing operational costs.
Employee awareness and training are equally important. Bank employees are often exposed to confidential information and privileged systems. A technically strong cybersecurity architecture can be undermined if employees fail to recognise phishing attempts, mishandle passwords, disclose sensitive information or ignore security procedures. Cybersecurity awareness should therefore be continuous rather than a one-time activity.
Customer awareness also matters because many electronic financial fraud incidents exploit customers directly. Fraudsters may impersonate bank officials, send fake links, request authentication codes or use social media to obtain personal information. Banks therefore need customer education programmes alongside technical controls. The effectiveness of cybersecurity must consequently be evaluated across the entire digital banking ecosystem rather than solely within the bank’s internal IT environment.
The Nigerian banking sector has continued to respond to these challenges through regulatory requirements and technological investment. The CBN’s cybersecurity framework requires banks and payment institutions to establish structured cybersecurity governance and risk-management arrangements. The increasing volume of electronic payments has also encouraged industry stakeholders to improve identity management, transaction monitoring and payment-system security.
The emergence of ISO 20022 is another development relevant to the security of financial transactions. NIBSS has indicated that Nigeria is transitioning toward ISO 20022 messaging standards as part of efforts to improve payment-system interoperability and security. The organisation has also highlighted identity management and industry coordination as mechanisms for reducing digital payment fraud.
Lagos Metropolis represents a particularly significant environment for studying electronic financial fraud and cybersecurity controls. Lagos is Nigeria’s largest commercial centre and one of the country’s most important locations for banking, financial technology, commerce and electronic transactions. NIBSS data indicate that Lagos accounted for 63.43 percent of reported digital payment fraud activity in 2025. This concentration makes Lagos a particularly relevant setting for examining how banking institutions implement cybersecurity controls and how effective those controls are in reducing electronic financial fraud.
The study focuses specifically on branches of United Bank for Africa (UBA) Plc, Guaranty Trust Bank (GTBank/GTCO) and Access Bank Plc in Lagos Metropolis. These institutions are major Nigerian banking organisations with extensive digital banking operations and significant customer bases. Their branches provide a useful setting for examining the implementation of cybersecurity controls from the perspective of bank employees who interact with customers, financial transactions, operational systems and fraud-management procedures.
UBA’s 2024 financial results demonstrate the scale of its operations. The bank reported gross earnings of approximately ₦3.19 trillion and total assets of ₦30.4 trillion at the end of 2024. Such a large financial institution processes significant volumes of financial transactions, making effective cybersecurity and fraud controls strategically important.
The study of these three banks is not intended to suggest that they have identical cybersecurity systems or identical levels of fraud. Rather, selecting UBA, GTBank and Access Bank provides an opportunity to examine cybersecurity controls across three major institutions operating within the same regulatory and geographical environment. The comparative context can help identify common controls, differences in implementation and perceptions of effectiveness among banking personnel.
The contemporary Nigerian banking environment therefore presents a complex relationship between digital innovation and financial security. On the one hand, electronic banking has improved convenience, transaction speed, financial inclusion and operational efficiency. On the other hand, digitalisation has created new opportunities for cybercriminals to exploit technological and human vulnerabilities. The objective of cybersecurity controls is not to prevent technological innovation but to ensure that the benefits of digital banking can be realised without exposing customers and financial institutions to unacceptable levels of fraud risk.
The importance of evaluating cybersecurity controls is further strengthened by recent evidence. A 2025 study of selected Nigerian banks examined cloud security, application security and network security as dimensions of cybersecurity and fraud control, indicating the importance of multiple technological layers in managing fraud risk (David, Offia & Ekwunife, 2025). Another recent study focusing specifically on UBA, GTBank and Access Bank examined cybersecurity’s role in mitigating financial fraud and reported that cybersecurity has become increasingly important for protecting banking institutions against evolving digital threats (Okikiola et al., 2026).
Nevertheless, there remains a need for further empirical investigation because the existence of cybersecurity controls does not necessarily demonstrate their effectiveness. Banks may have firewalls, authentication systems, transaction-monitoring systems, encryption, employee training and incident-response procedures, yet fraud can continue to occur. The important question is therefore whether these controls are sufficiently implemented, monitored and updated to prevent electronic financial fraud.
It is against this background that this study seeks to assess the effectiveness of cybersecurity controls in preventing electronic financial fraud in the Nigerian banking sector, with particular focus on UBA Plc, GTBank and Access Bank branches in Lagos Metropolis. The study is expected to generate evidence on the major cybersecurity controls used by the selected banks, their perceived effectiveness, challenges affecting their implementation and the extent to which they contribute to the prevention of electronic financial fraud.
1.2 Statement of the Problem
The rapid digital transformation of the Nigerian banking sector has significantly increased the speed and convenience of financial transactions. Customers can transfer funds, make payments, check account balances and perform other banking activities without visiting a physical branch. The volume of electronic transactions has grown substantially, reaching approximately ₦1.07 quadrillion in 2024. While this development supports financial inclusion and economic activity, it also exposes banks and customers to increasingly complex cybersecurity risks.
The fundamental problem is that electronic financial fraud continues to occur despite the existence of increasingly sophisticated cybersecurity controls. Nigerian financial institutions have invested in authentication systems, transaction monitoring, firewalls, encryption, biometric verification, fraud alerts, access controls, cybersecurity policies and other protective measures. The CBN has also established regulatory requirements for cybersecurity governance and risk management. Nevertheless, significant financial losses continue to occur.
The magnitude of the problem is demonstrated by the ₦52.26 billion lost to fraud in 2024. Although losses subsequently declined to ₦25.85 billion in 2025, the amount remains substantial. Furthermore, approximately 67,518 fraud incidents were recorded in 2025, indicating that the reduction in financial losses should not be interpreted as elimination of the underlying problem.
The problem is particularly significant in Lagos Metropolis. NIBSS reported that Lagos accounted for 63.43 percent of digital payment fraud activity in 2025. Given Lagos’s position as Nigeria’s major commercial and financial centre, the high concentration of electronic financial transactions makes banking institutions operating in the metropolis especially exposed to cyber-enabled financial crime.
A major concern is that cybercriminals continue to adapt their methods in response to improvements in banking security. Phishing, social engineering, account compromise, SIM-swap fraud and insider-related fraud can exploit weaknesses that are not necessarily located within the technological infrastructure itself. NIBSS has specifically identified insider involvement and social engineering as continuing concerns. Thus, even when banks deploy advanced technical systems, human and organisational vulnerabilities may undermine their effectiveness.
Another dimension of the problem is the possible inadequacy of traditional fraud controls in a highly digital environment. Akinwale et al. (2021) found that electronic fraud cases increased over much of the period they examined as electronic banking products expanded. This suggests that the development of electronic banking must be accompanied by corresponding improvements in security and fraud-control mechanisms.
The problem also concerns the actual effectiveness of individual cybersecurity controls. For instance, multi-factor authentication may reduce unauthorised access, but phishing can sometimes deceive customers into disclosing authentication credentials. Encryption may protect information in transit or storage, but it cannot prevent an authorised user from deliberately misusing legitimate access. Firewalls may block certain external threats, but they may not detect fraud conducted through valid credentials. Transaction-monitoring systems may identify unusual patterns but may also generate false alerts. These examples illustrate that no single cybersecurity control is sufficient to address the full spectrum of electronic financial fraud.
Furthermore, the rapid emergence of artificial intelligence, cloud computing, mobile banking and other technologies creates both opportunities and risks. Advanced analytics and AI can improve fraud detection, but they also introduce new technical, governance and implementation requirements. John et al. (2025) found that top-management support, IT infrastructure, regulatory compliance, staff competency and perceived effectiveness influence adoption of AI-driven fraud detection systems in Nigerian banks, while implementation costs can constrain adoption.
There is also the problem of employee and customer awareness. Banks can establish comprehensive cybersecurity policies, but the effectiveness of those policies may be compromised if employees fail to comply with security procedures or customers disclose sensitive information to fraudsters. Tade and Adeniyi (2020) demonstrated that electronic fraud affects trust in the Nigerian cashless ecosystem, showing that the problem extends beyond direct financial loss to customer confidence and adoption of digital banking.
Regulatory compliance represents another concern. Although the CBN has established a risk-based cybersecurity framework, compliance with a regulatory framework does not necessarily mean that all controls are equally effective in practice. The existence of policies and procedures must be accompanied by continuous implementation, testing, monitoring, incident reporting and improvement. Banks therefore need to determine not simply whether controls exist but whether those controls actually prevent, detect and respond effectively to fraudulent activity.
A further problem is that much of the available Nigerian literature examines electronic fraud at the general banking-sector level, while comparatively fewer studies provide branch-level evidence concerning the implementation and effectiveness of cybersecurity controls in specific major banks operating in Lagos. This creates an empirical gap concerning how bank employees perceive the effectiveness of controls within their operational environments.
The problem is particularly relevant to UBA, GTBank and Access Bank because these institutions operate large digital banking ecosystems and serve substantial numbers of customers. Their branches in Lagos operate within an environment characterised by high transaction volumes and significant exposure to electronic financial crime. Although these banks invest in cybersecurity, the extent to which their controls effectively prevent electronic financial fraud requires empirical assessment.
The persistence of fraud despite cybersecurity investment creates an important management question: Are existing cybersecurity controls sufficiently effective to prevent electronic financial fraud, or do weaknesses in implementation, technology, human behaviour, monitoring and regulatory compliance continue to create opportunities for fraud?
Without empirical evidence addressing this question, bank management may find it difficult to determine which controls require strengthening and where additional investment should be directed. Similarly, regulators may have limited institution-specific evidence concerning the practical effectiveness of cybersecurity measures. Customers may also continue to face risks if security controls are perceived as adequate but fail to address emerging forms of fraud.
Therefore, the central problem of this study is the continued occurrence of electronic financial fraud in the Nigerian banking sector despite the implementation of various cybersecurity controls and regulatory requirements. The study seeks to determine how effective cybersecurity controls are in preventing electronic financial fraud, with specific reference to UBA Plc, GTBank and Access Bank branches in Lagos Metropolis.
1.3 Purpose of the Study
The general purpose of this study is to assess the effectiveness of cybersecurity controls in preventing electronic financial fraud in the Nigerian banking sector, using selected branches of UBA Plc, GTBank and Access Bank in Lagos Metropolis as the study context.
Specifically, the study seeks to:
- examine the major cybersecurity controls implemented by UBA Plc, GTBank and Access Bank branches in Lagos Metropolis;
- assess the perceived effectiveness of access-control and authentication mechanisms in preventing electronic financial fraud;
- determine the effectiveness of transaction-monitoring and fraud-detection systems in identifying and preventing fraudulent electronic transactions;
- examine the effectiveness of network, application and data-security controls in preventing electronic financial fraud;
1.4 Research Questions
The study will be guided by the following research questions:
- What major cybersecurity controls are implemented by UBA Plc, GTBank and Access Bank branches in Lagos Metropolis?
- To what extent are access-control and authentication mechanisms effective in preventing electronic financial fraud?
- To what extent are transaction-monitoring and fraud-detection systems effective in identifying and preventing fraudulent electronic transactions?
- To what extent are network, application and data-security controls effective in preventing electronic financial fraud?
1.5 Research Hypothesis
The following null hypothesis will be tested at the 0.05 level of significance:
H₀: Cybersecurity controls have no statistically significant effect on the prevention of electronic financial fraud in UBA Plc, GTBank and Access Bank branches in Lagos Metropolis.
1.6 Significance of the Study
The study will be significant to bank management, cybersecurity professionals, employees, customers, regulators, policymakers, researchers and the Nigerian banking sector generally.
Bank Management: The findings will provide evidence concerning the effectiveness of existing cybersecurity controls and may help management identify areas requiring additional investment, monitoring or restructuring. The findings may assist management in making informed decisions concerning authentication, transaction monitoring, access management, employee training, incident response and other security measures.
Cybersecurity Professionals: The study may provide useful information concerning practical challenges encountered in implementing cybersecurity controls in banking environments. Cybersecurity professionals may use the findings to strengthen security architectures, monitoring procedures, vulnerability-management programmes and fraud-detection mechanisms.
Bank Employees: The study may increase awareness among employees regarding their role in preventing electronic financial fraud. Since insider threats, phishing and social engineering can exploit human vulnerabilities, the findings may reinforce the importance of compliance with cybersecurity policies and procedures.
Customers: The findings may contribute indirectly to improved customer protection by identifying security weaknesses that may expose customers to unauthorised transactions, identity theft, phishing and account compromise.
Central Bank of Nigeria: The findings may provide additional empirical evidence that can support the CBN’s ongoing supervision and evaluation of cybersecurity practices within deposit money banks. The CBN’s existing framework requires banks to establish appropriate cybersecurity governance and risk-management arrangements.
Nigeria Inter-Bank Settlement System (NIBSS): Since NIBSS operates critical components of Nigeria’s payment infrastructure and monitors payment-related fraud trends, findings from the study may provide useful insights into institution-level controls and the continuing challenges associated with electronic financial fraud.
Policymakers: The study may contribute to policy discussions concerning cybersecurity, digital banking, financial-sector resilience and electronic financial crime. It may help policymakers identify areas where regulatory requirements need to be strengthened or better enforced.
Researchers and Students: The study will contribute to the Nigerian literature on cybersecurity controls, electronic banking fraud and financial-sector risk management. It may provide a basis for future research involving specific security technologies, fraud detection, artificial intelligence, employee behaviour or customer cybersecurity awareness.
The Nigerian Banking Sector: More effective cybersecurity controls can contribute to reduced fraud losses, stronger customer trust, improved digital-banking adoption and greater stability of the financial system. The study may therefore have broader relevance beyond the selected banks.
1.7 Scope of the Study
The study focuses on the effectiveness of cybersecurity controls in preventing electronic financial fraud in the Nigerian banking sector, using selected branches of UBA Plc, GTBank and Access Bank in Lagos Metropolis.
Geographically, the study is limited to selected branches of the three banks within Lagos Metropolis. The study does not seek to examine all branches of the selected banks across Nigeria.
Conceptually, the study focuses on cybersecurity controls as the independent variable and prevention of electronic financial fraud as the dependent variable.
The cybersecurity controls examined include:
- access controls and authentication;
- multi-factor and biometric authentication;
- transaction monitoring and fraud-detection systems;
- network and application security;
- data protection and encryption;
- employee cybersecurity awareness and training;
- incident-response mechanisms;
- continuous security monitoring; and
- cybersecurity policies and compliance procedures.
Electronic financial fraud will be considered in relation to fraudulent activities conducted through or involving electronic banking channels, including internet banking, mobile banking, ATM/card transactions, electronic transfers, POS transactions, account compromise, phishing, social engineering, SIM-swap-related fraud and insider-enabled electronic fraud.
The study will focus primarily on the perspectives of relevant bank personnel involved in banking operations, information technology, cybersecurity, risk management, internal control, audit, customer service and fraud management.
1.8 Operational Definition of Terms
Access Control: The policies, procedures and technologies used to regulate who or what can access banking systems, applications, networks and information resources.
Authentication: The process of verifying the identity of a customer, employee or system attempting to access a banking resource or initiate a transaction.
Banking Cybersecurity: The protection of banking information systems, networks, applications, devices and data against cyber threats, unauthorised access, disruption, alteration, theft or destruction.
Cybersecurity Controls: Technical, administrative and procedural safeguards established by a bank to prevent, detect, respond to and recover from cybersecurity threats and electronic financial fraud.
Cybersecurity Awareness: The knowledge and understanding possessed by bank employees and other users concerning cyber threats, security policies, safe digital practices and their responsibilities for protecting banking systems and information.
Electronic Financial Fraud: The intentional use of electronic, digital or computer-mediated systems to obtain money, financial information or other financial benefits through deception, unauthorised access, manipulation or other unlawful means.
Fraud Detection: The process of identifying transactions, activities, behaviours or events that indicate actual or potential fraudulent activity.
Fraud Prevention: Measures designed to stop or reduce the likelihood of fraudulent activities before they result in financial loss.
Incident Response: The policies, procedures and actions used by a bank to identify, contain, investigate, manage and recover from cybersecurity incidents or suspected fraudulent activities.
Multi-Factor Authentication (MFA): An authentication method requiring two or more independent forms of verification before access or a transaction is authorised.
Phishing: A fraudulent technique in which attackers impersonate legitimate persons or organisations to deceive individuals into revealing confidential information such as passwords, PINs or authentication codes.
Transaction Monitoring: The continuous or periodic examination of financial transactions to identify unusual or suspicious patterns that may indicate fraudulent activity.
Electronic Banking: The delivery of banking products and services through electronic channels such as internet banking, mobile applications, ATMs, POS terminals and USSD platforms.
Effectiveness: The extent to which a cybersecurity control achieves its intended purpose of preventing, detecting or reducing electronic financial fraud and associated losses.
1.9 Organisation of the Study
The study will be organised into five chapters.
Chapter One presents the introduction, background of the study, statement of the problem, purpose of the study, research questions, hypothesis, significance of the study, scope of the study and operational definition of terms.
Chapter Two will review relevant conceptual, theoretical and empirical literature on cybersecurity, cybersecurity controls, electronic financial fraud, banking cybersecurity, fraud detection, access controls, authentication, transaction monitoring, employee awareness and cybersecurity governance. The chapter will also present the theoretical and conceptual frameworks guiding the study.
Chapter Three will present the methodology of the study, including research design, area of the study, population, sample size, sampling technique, instrument for data collection, validity and reliability of the instrument, method of data collection and method of data analysis.
Chapter Four will present and analyse the data collected from respondents. The research questions will be answered and the hypothesis will be tested at the 0.05 level of significance.
Chapter Five will present the summary of findings, conclusion, recommendations and suggestions for further studies.
Project – Effectiveness of Cybersecurity Controls in Preventing Electronic Financial Fraud in the Nigerian Banking Sector
Frequently Asked Questions
Our Customers are Happy
Ademola A.
I was skeptical at first, but after placing my order, my full project arrived in my email in under 15 minutes! The process was smooth, clear, and professional. Truly amazing service!
Kwabena K.
I needed a custom project on a new topic. Https://azresearchconsult.com.ng delivered within 3 days, and the quality was outstanding. They even guided me on how to defend it. Highly recommend!
Michael H.
Fast, reliable, and very professional. My research project was delivered on time, with no hidden charges. The team is trustworthy and supportive.
Fatou B.
I got my full project in minutes and my custom request within 3 days. Their communication is clear, and the material is top-notch. Excellent experience!
James O.
https://azresearchconsult.com.ng is a lifesaver! My project was delivered exactly as requested. The team is friendly, professional, and highly responsive. Very satisfied!
Ngozi E.
I was worried about paying online, but the team reassured me and delivered my complete project instantly. Transparent and professional service!
Ama S.
I requested a custom topic project and received it in just 3 days. The guidance and quality were excellent. I recommend azresearchconsult.com.ng to everyone!
Sarah W.
The service is dependable and efficient. My project arrived on time, and every step was transparent. Truly a professional service I trust.
Emmanuel T.
Fast and reliable. My full project was delivered in minutes, and the custom project in 3 days. Communication was excellent throughout.
Aisha N.
Extremely satisfied with the service. My project was delivered promptly, fully transparent, and of high quality. A trustworthy academic partner!
