Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

A Theoretical Review of Internal Control System on Cyber Risk Management in Nigerian Banks

Atelhe Joy Sekele

Abstract

The purpose of the study was to examine internal control system on cyber risk management in Nigerian banks. The rapid adoption of digital banking technologies has transformed the Nigerian banking sector, making banking services faster, more accessible and increasingly dependent on interconnected information systems. The study recommended that management of Nigerian banks should strengthen the control environment by demonstrating clear commitment to cybersecurity, establishing accountability for cyber risks and developing an organizational culture that promotes ethical behaviour and security consciousness. Banks should conduct regular cyber-risk assessments covering digital banking platforms, information systems, employees, third-party service providers and emerging cyber threats. Nigerian banks should strengthen access controls, authentication procedures, segregation of duties, transaction authorization, encryption and automated monitoring mechanisms to reduce unauthorized access and fraudulent electronic transactions.

Keywords

Internal control systemcyber risk managementdigital banking technologies

References

Abdulkadir, A., & Bello, [initials]. (2026). The impact of internal control systems on cybercrimes prevention of deposit money banks in Nigeria. Journal of Business Development and Management Research, 12(7). Abdullahi, R., & Mansor, N. (2021). Fraud risk management and internal control effectiveness: Evidence from organizations. Journal of Financial Crime, 28(4), 1115–1130. Aldasoro, I., Gambacorta, L., Giudici, P., & Leach, T. (2022). Operational and cyber risks in the financial sector. BIS Quarterly Review, 1–15. Azura, Y. T. Y., Azad, M. A., & Ahmed, Y. (2025). An integrated cyber security risk management framework for online banking systems. Journal of Banking and Financial Technology, 9, 85–104. https://doi.org/10.1007/s42786-025-00056-3 Bada, M., Sasse, M. A., & Nurse, J. R. C. (2022). Cyber security awareness campaigns: Why do they fail to change behaviour? International Journal of Information Security, 21, 1–15. Basel Committee on Banking Supervision. (2023). Principles for operational resilience. Bank for International Settlements. Bouveret, A. (2021). Cyber risk for the financial sector: A framework for quantitative assessment. IMF Working Paper, 2021(143), 1–33. Committee of Sponsoring Organizations of the Treadway Commission. (2013). Internal control— Integrated framework. COSO. Eling, M., & Schnell, W. (2022). What do we know about cyber risk and cyber insurance? The Geneva Papers on Risk and Insurance—Issues and Practice, 47, 1–23. Eulerich, M., Kremin, J., & Wood, D. A. (2022). Factors that influence the perceived usefulness of internal audit in the digital age. Accounting Horizons, 36(1), 1–20. Hadlington, L. (2021). Human factors in cybersecurity: Examining the role of individual differences and organizational factors. Computers & Security, 105, 102239. International Monetary Fund. (2024). Global financial stability report: Steadying the course— Global banking and financial stability. IMF. Kou, G., Olgu Akdeniz, Ö., Dinçer, H., & Yüksel, S. (2021). FinTech investments in cybersecurity: A systematic approach. Technological Forecasting and Social Change, 167, 120702. National Institute of Standards and Technology. (2024). The NIST cybersecurity framework 2.0. U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29 Nweke, I. V., & Ekpeh, U. C. (2026). Internal control weaknesses and cybersecurity breach frequency in listed deposit money banks in Nigeria. IIARD International Journal of Banking and Finance Research, 12(4). https://doi.org/10.56201/ijbfr..pg22.33 Ouchi, W. G. (1979). A conceptual framework for the design of organizational control mechanisms. Management Science, 25(9), 833–848. https://doi.org/10.1287/mnsc.25.9.833 Oyebisi, L. O. (2024). Risk management, internal control systems and performance of selected deposit money banks in Lagos State, Nigeria [Master's thesis, Lead City University]. Lead City University Repository. Ozuomba, C. N., Ibeaja, U. F., & Nosiri, H. U. (2023). Internal control activities and risk assessment effect on the operations of quoted banks in the Nigerian Stock Exchange. IDOSR Journal of Arts and Management, 8(1), 27–39. https://doi.org/10.59298/IDOSR/2023/12.1.5893 Parsons, K., Butavicius, M., Pattinson, M., & McCormac, A. (2021). Determining employee awareness and behaviour toward cybersecurity. Computers & Security, 109, 102397. Tøndel, I. A., Jaatun, M. G., & Cruzes, D. S. (2021). Threat modelling and security controls in digital organizations. International Journal of Information Security, 20, 1–15. Tornatzky, L. G., & Fleischer, M. (1990). The processes of technological innovation. Lexington Books.