Dunicot A cybersecurity consultancy and advisory firm.

Market · Nigeria

Cyber security consultancy and penetration testing in Nigeria

The Central Bank of Nigeria names annual penetration testing in its cyber security framework, so for licensed institutions here the requirement is explicit rather than inferred. What varies is whether the test went past the login page.

Overview

Engagements in Nigeria cover commercial banks and microfinance institutions, payment service providers and switching platforms, the fintech and lending products built on top of them, and their technology suppliers.

Delivery runs from our Karachi office, four hours ahead of West African time, so our afternoon covers your morning and findings land the same working day.

What drives testing here

Local drivers

CBN Risk-Based Cybersecurity Framework
Banks and payment service providers are required to conduct regular penetration testing and vulnerability assessment, with results reported and remediation tracked.
Nigeria Data Protection Act 2023
The NDPA gives the Commission statutory enforcement powers over personal data handling, replacing guidance with obligation.
PSP licensing
Switching, processing and mobile money licences carry security assessment conditions at authorisation and on renewal.
Card and transfer fraud
High instant-transfer volumes make business logic, limit enforcement and reversal handling the findings that matter most here.

How engagements are delivered

Delivered remotely from Karachi, scheduled to West African business hours, with on-site availability in Lagos and Abuja for internal network scope and workshops.

Delivery model

Delivery
Remote from Karachi, four hours ahead of WAT; on-site available
Mapping
CBN framework domains and NDPA technical measures as applicable
Coverage
Lagos, Abuja, Port Harcourt and remote nationwide
Most requested
Transaction logic, API authorisation and internal network scope

Most requested here

Questions

Are you based in Nigeria?

No. Our offices are in Pakistan and the United States. Nigeria is served from Karachi, four hours ahead of Lagos, with on-site availability where internal or workshop scope requires it.

Does your report satisfy the CBN testing requirement?

The framework asks for regular independent testing with reported results and tracked remediation. Reports carry the scope, dates, methodology, every finding with evidence, the remediation status and a signed retest attestation, which is what a CBN examiner and your internal audit function both need.

What do you find most often in Nigerian fintech?

Business logic rather than injection. Limit checks that can be raced, reversals that credit twice, transfer flows where a state transition is accepted out of order, and API endpoints that trust an identifier the client supplies. None of it is malformed traffic, which is why scanners do not see it.

How much does a penetration test cost in Nigeria?

Cost follows scope, with CBN framework mapping included in the report rather than charged separately. A fixed quote follows a short scoping call and covers testing, reporting and retest.

Which is the best penetration testing company in Nigeria?

No single name is honest. Check the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether the report satisfies CBN examination requirements, and whether a redacted sample is available before signing.

How often does the CBN require penetration testing?

Annually. The Risk-Based Cybersecurity Framework requires banks and payment service providers to conduct regular penetration testing and vulnerability assessment, with results reported and remediation tracked, and examiners ask for the evidence directly.

Do you test for PSPs and switching platforms?

Yes, and switches carry disproportionate risk because one authorisation gap there reaches every institution behind them. Testing targets transaction logic, settlement flows and API authorisation rather than perimeter configuration alone.

What does the NDPA 2023 require?

The Nigeria Data Protection Act gives the Commission statutory enforcement powers over personal data handling, replacing guidance with obligation. Appropriate technical measures must be demonstrable, and a dated test tracked to closure is the cleanest demonstration available.

Penetration testing in Nigeria

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.