NAICOM Cyber Guidelines
NAICOM Cybersecurity Risk Management Guidelines for Insurers 2023
What it is
NAICOM's cybersecurity guidelines impose specific cyber risk management, incident reporting, and board-level governance obligations on Nigerian insurance entities. Aligned with broader CBN sector cybersecurity guidance and the NDPA 2023.
What it requires
All NAICOM-licensed insurers, reinsurers, and intermediaries. Requires board-approved cyber risk strategy, cyber risk officer appointment, third-party risk management, periodic security testing including penetration testing, incident reporting to NAICOM within prescribed timeframes, and integration with broader operational risk frameworks.
Key facts
- Supervisor
- National Insurance Commission (NAICOM)
- Official text
- https://naicom.gov.ng/
DSI services for NAICOM Cyber Guidelines
DSI Advisory Services helps covered entities translate NAICOM Cyber Guidelines obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Related briefings
In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.
Trellix's source code repository was breached on May 2. Three weeks earlier, Medtronic confirmed a ShinyHunters attack on 9 million patient records. They join Microsoft, Okta, and LastPass on a list that should never exist — the security vendors whose entire commercial proposition is preventing the attacks they cannot prevent on themselves. This briefing maps the structural failure and the four predicted outcomes.
Somewhere in Europe, this week, a developer cloned DevDojo Wave to bootstrap a new Laravel project. Twenty seconds later, /tmp/.sshd was running in the background — masquerading as a system daemon, downloaded from a compromised GitHub repository. The developer did not know they had installed malware. Neither did 9,100 other installations. This briefing examines the 700-repo compromise, the structural pattern across eight years of GitHub supply chain attacks, the alternatives operators are starting to consider, and what AI-driven defence can and cannot do about it.
Berlin, January 2022. Hackers took the IT systems of Oiltanking and Mabanaft offline. Tank-loading scheduling went dark for two weeks. The OT held — but the IT system that scheduled the loading did not. That is the incident pattern now migrating into the Nigerian operational reality. This briefing examines what the global oil and gas pattern is telling operators in the post-PIA Nigerian context — and why single-operator defence has reached its structural ceiling.
A Tier 1 Nigerian bank lost billions on a Friday evening. The institution did not report the breach to its peers. Within 48 hours, two other banks were compromised by the same group. This briefing examines what the 2026 incident pattern is telling CISOs in the Nigerian banking sector — and why individual-bank defence has stopped working.
On 16 May 2026, a joint US-Nigerian precision strike in Mitile killed Abu-Bilal al-Minuki, the second-in-command of the Islamic State. The same year, Nigeria recorded the highest Belt and Road Initiative construction volume on earth — $24.6 billion in Chinese contracts, up from $1.8 billion the year before. Tinubu's government is splitting its great-power dependencies by domain: the United States for intelligence and counterterrorism; China for railways, telecoms, and oil. The arrangement is being studied as the multipolar playbook for the Global South. The complication: the ghost the Eagle is hunting in Lake Chad is one the Eagle helped to birth — through CPA Order 2 in 2003, Camp Bucca, and the August 2012 DIA memo that predicted exactly the outcome it became.
Read more on this
Other cybersecurity frameworks in the DSI registry: