What is Cybersecurity?
What is Cybersecurity?
Cybersecurity is the practice of protecting computers, networks, applications, and data from digital attacks, unauthorised access, theft, and damage.
If you have ever received an SMS saying "Your Access Bank account has been restricted, click here to verify" (or the same message with Barclays, Chase, or your own bank's name), or a call from someone claiming to be from your bank asking for an OTP, you have already met cybercrime. Cybersecurity is the discipline of stopping those attacks, or limiting the damage when they succeed.
The CIA Triad: The Foundation of Security
Every security concept traces back to three properties, known as the CIA Triad:
Confidentiality
Information should only be visible to people who are authorised to see it. Only you and the bank should see your balance.
Example: A fraudster tricks you into reading out your OTP, whether you bank in Lagos, London, or Toronto. Your account is now visible to someone who should not have access. Confidentiality is broken.
Integrity
Data should be accurate and unmodified by unauthorised parties. A transfer of ₦50,000 (or £50, or $50) should arrive as exactly that.
Example: In a business email compromise (BEC) attack, a scam that hits companies in every country, a criminal edits the bank account number on a supplier's invoice. The company pays the right amount to the wrong account. Integrity is broken.
Availability
Systems and data should be accessible to authorised users when they need them.
Example: A bank app that is down on salary day in Lagos, or a hospital system, like the UK's NHS in the 2017 WannaCry attack, whose records are locked by ransomware. Availability is broken.
Security professionals judge every threat, and every defence, against all three.
The Threat Landscape
Attackers come in different forms, with different goals:
| Threat actor | Motivation | Typical activity |
|---|---|---|
| Opportunistic fraudsters | Quick money | Phishing SMS, fake alert scams, SIM swaps |
| Organised cybercrime groups | Large-scale profit | BEC, ransomware, account takeover |
| Insiders | Money, grievance | Selling customer data, abusing system access |
| Hacktivists | Political or social causes | Defacing websites, leaking data |
| Nation-state groups | Espionage, disruption | Long-term targeted intrusions |
Most of the attacks you will see, in Nigeria and worldwide, are financially motivated and rely on tricking people rather than breaking clever technology.
Why It Matters Everywhere
Digital finance is growing fast worldwide, and Nigeria is one of the fastest-growing digital economies in Africa. Mobile banking, USSD, fintech apps, and online marketplaces have brought millions of people into the formal financial system, just as online banking and contactless payments did in the UK and US. Every one of those people is also a potential target. The threats below are described with Nigerian examples, and each one has a close parallel elsewhere.
Banking and payment fraud
Fraudsters impersonate banks through fake SMS messages, cloned websites, and phone calls. A typical message imitates a bank such as Access Bank in Nigeria, asking you to "verify your BVN" or "reactivate your account" through a link that leads to a look-alike login page. Barclays customers in the UK and Chase customers in the US receive almost identical messages. Anything you type goes straight to the criminal.
SIM swap fraud
Many accounts still rely on SMS one-time passwords. In a SIM swap, a criminal convinces a telco agent (or bribes an insider) to move your phone number to a new SIM card. Your phone suddenly loses service, and the attacker receives your calls and OTPs. With those, and personal details gathered earlier, they can reset banking and social media passwords. Lines from networks such as MTN, Airtel, Glo, and 9mobile have all been targeted this way, which is why the SIM-NIN linkage exercise and telco verification controls became such a big deal in Nigeria. SIM swaps are just as common against AT&T, T-Mobile, and Vodafone customers, and US regulators have pushed carriers to tighten identity checks for the same reason.
Business email compromise (BEC)
In BEC, attackers compromise or imitate a business email account, often a CEO, finance manager, or supplier, and send a convincing instruction: "Please update our account details and pay the invoice today." Companies, NGOs, and universities that pay suppliers by bank transfer are common targets everywhere, from Nigeria to Europe to North America. The FBI has ranked BEC among the costliest forms of cybercrime for years. There is no malware involved, only a believable email and a rushed finance officer.
Fake alert scams
Fraudsters send SMS or screenshot "credit alerts" to vendors and traders, then collect goods before the seller checks the real account balance. Overpayment and fake payment-confirmation scams on marketplaces such as eBay and Facebook Marketplace work the same way. It is simple, low-tech, and very effective.
Insider and data risks
Customer databases held by banks, telcos, and fintechs are valuable. Weak access controls or a bribed employee can expose them.
Key idea: Most attacks succeed because of a human decision (clicking, trusting, rushing), not because a hacker broke encryption. Good security combines technology, process, and people.
The Legal and Regulatory Picture
Every country has laws against hacking and rules on protecting data. In Nigeria, the main ones are the Cybercrimes Act 2015 (amended 2024), the Nigeria Data Protection Act 2023, and Central Bank of Nigeria (CBN) requirements for banks. Nigeria's national CERT, ngCERT, takes incident reports.
Here are the same ideas globally:
| Area | Nigeria | Global equivalents |
|---|---|---|
| Computer crime | Cybercrimes Act | Computer Fraud and Abuse Act (US), Computer Misuse Act (UK), Budapest Convention (international) |
| Personal data | Nigeria Data Protection Act 2023 | GDPR (EU/UK), CCPA (California) |
| Payment card security | CBN rules for banks and payment providers | PCI-DSS (worldwide) |
| Company security assurance | CBN risk-management expectations | SOC 2 and ISO 27001 (worldwide) |
| Incident reporting | ngCERT | CISA (US), NCSC (UK), national CERTs |
This is why banks, telcos, and fintechs hire security teams, and why demand for skilled people is growing.
Key Cybersecurity Domains
| Domain | What it covers |
|---|---|
| Network Security | Protecting the infrastructure that carries data |
| Application Security | Building software that resists attack |
| Cloud Security | Protecting systems hosted on AWS, Azure, GCP |
| Endpoint Security | Protecting laptops, phones, and servers |
| Identity and Access Management | Controlling who can access what |
| Security Operations (SOC) | Monitoring, detecting, and responding to attacks |
| Penetration Testing | Ethically attacking systems to find weaknesses |
| Governance, Risk and Compliance (GRC) | Policies, audits, and regulation |
Offensive vs Defensive Security
- Red Team (offensive): Simulates attackers to find weaknesses, e.g. penetration testers.
- Blue Team (defensive): Detects, prevents, and responds to attacks, e.g. SOC analysts.
- Purple Team: Red and blue working together to improve defences.
Ethics and the Law
The line between an ethical hacker and a criminal is authorisation. Testing a system without written permission is a crime under Nigerian law and the laws of almost every country, even if your intentions are good. Practise only on your own systems or on legal platforms such as TryHackMe and HackTheBox.
Try It Yourself
The editor on this page contains a CIA Triad analyser. Choose an incident and see which of the three properties it breaks. Then try to think of an incident that breaks all three.
Try it yourself
Key Takeaways
- Cybersecurity protects systems, networks, and data from attacks, theft, and damage.
- The CIA triad (Confidentiality, Integrity, Availability) is the framework for judging every threat and defence.
- Banking fraud, SIM swaps, fake payment scams, and BEC are among the most common real-world threats in Nigeria and worldwide.
- Most attacks exploit people and process, not just technology.
- Authorisation is the legal line: only test systems you own or have written permission to test.
Quick Quiz
1.What does the 'A' in the CIA triad stand for?
2.A criminal edits the bank account number on a supplier invoice before it reaches the finance team. Which CIA property is primarily violated?
3.Why is a SIM swap dangerous for a bank customer?
4.What legally separates an ethical hacker from a cybercriminal?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx