Digital Resilience Rises as Banking Turns Fully Tech
By Shuaib S. Agaka

When Kashifu Inuwa Abdullahi spoke to senior directors of the Central Bank of Nigeria in Lagos, his message was not simply about banks adopting more technology. It was about recognising that the financial system has already become a technology system, whether regulators are prepared for that reality or not.

Inuwa, the Director General of the National Information Technology Development Agency, was speaking at the CBN Committee of Departmental Directors’ retreat on digital transformation, supervision, innovation and operational resilience. His warning was straightforward. Nigeria can no longer think about financial stability without thinking about digital stability.

That argument deserves attention because the transformation of Nigerian banking is no longer confined to the distinction between traditional banks and fintechs. The business models may differ, the licences may differ, and the customer experiences may differ, but both increasingly depend on the same underlying reality. Banking now runs on software, networks, data, cloud infrastructure, payment systems, cybersecurity and a growing web of technology providers.

The traditional bank has not disappeared. Its branches, employees and balance sheets still matter. What has changed is the infrastructure through which those institutions operate. A customer may interact with a conventional bank through a mobile application, while a fintech may provide an entirely digital experience, but both depend on technology to authenticate customers, process transactions, move information, detect fraud and keep services available. That creates a different kind of risk.

A bank can have sufficient capital and comply with financial regulations and still be unable to serve customers if a critical technology provider fails. A disruption to connectivity, cloud infrastructure, payment processing, data systems or another essential service can quickly move from being an IT problem to becoming a financial problem.

This is why the emphasis on third-party and fourth-party risks is important. Financial institutions increasingly depend on companies that may sit outside the traditional boundaries of financial supervision. A bank may rely on a technology provider, which may itself depend on another infrastructure provider. The further this chain extends, the harder it becomes to understand where a critical vulnerability actually sits.

The problem is not that banks use external technology. That is a normal feature of modern digital economies. The problem is failing to understand which external dependencies could become systemic if they break.

This becomes even more significant as artificial intelligence changes the threat landscape. AI can strengthen fraud detection, cybersecurity and risk monitoring, but the same technology can also make attacks more sophisticated, automated and difficult to detect. Financial institutions therefore have to protect not only their conventional systems but also the AI systems increasingly being introduced into their operations.

For regulators, this changes the question they need to answer.

It is no longer enough to ask whether a particular bank is financially sound or whether it has complied with a particular requirement. Regulators increasingly need to understand the technological ecosystem surrounding that institution. Where is critical data stored? Which providers handle it? What happens if a major service becomes unavailable? How quickly can an institution recover? Are several financial institutions exposed to the same technology provider? These questions require a different form of supervision.

This is where digital transformation becomes more important than simply digitising regulation.
Putting regulatory processes online is digitalisation. Building the ability to continuously monitor a complex financial ecosystem, identify unusual activity, understand infrastructure dependencies and anticipate emerging threats is something much bigger. It is a question of regulatory intelligence.

The CBN’s move to require banks and payment providers to store and manage payment transaction data generated in Nigeria within the country by January 1, 2027, is one example of how this broader shift is already taking shape. The requirement applies across significant parts of the payments ecosystem and places data location directly within the conversation about financial infrastructure and regulatory oversight.

Data localisation should therefore not be viewed simply as a compliance exercise or a requirement to move databases from foreign servers to Nigerian facilities. It raises a much larger question about whether Nigeria has sufficient control over the infrastructure supporting its financial system.

Keeping data within Nigeria will strengthen regulatory access and reduce dependence on external jurisdictions. But data residency alone does not create resilience. Nigeria also needs reliable data centres, dependable power, strong connectivity, cybersecurity capacity, disaster recovery systems, and skilled professionals capable of operating and securing critical infrastructure.

Otherwise, localisation could simply move the point of vulnerability without eliminating it.
This is where digital sovereignty becomes more than a policy phrase. For a country whose economy increasingly depends on digital payments, sovereignty means having meaningful control over the infrastructure, data, skills and systems that keep essential services running.

It does not necessarily mean building every technology domestically or withdrawing from global technology providers. It means knowing which dependencies are strategically important and ensuring that Nigeria has the capacity, alternatives and expertise required when those dependencies fail.

The financial sector should consequently begin thinking about technology resilience in the same way it thinks about financial resilience.

The next stage of Nigeria’s financial regulation therefore has to move beyond the boundaries of individual institutions. Regulators need visibility across banks, fintechs, payment companies, telecommunications infrastructure, cloud services and other critical technology providers. They need stronger real-time monitoring, better ecosystem mapping and the technical expertise to understand risks before those risks become disruptions.

Nigeria has spent years moving banking away from physical branches and towards digital platforms. The next challenge is harder. It is ensuring that the technology beneath those platforms is resilient enough to carry an economy that increasingly depends on them.

The lesson from Inuwa’s intervention is ultimately not that Nigerian banks need more technology. They already have it.

The real question is whether Nigeria understands the technology its financial system now depends on well enough to protect it.

Because when banking becomes technology, a technology failure is no longer just a technology failure, it becomes a financial crisis.

Shuaib S. Agaka is a tech journalist and digital policy analyst based in Kano.

Bank Recapitalization-abacha-university-ad