Connect with us

Banking

EXPLAINER: Understanding CBN’s 0.5% Cybersecurity Levy

Published

on

CBN Ways and Means

By Adedapo Adesanya

On Monday, May 6, 2024, the Central Bank of Nigeria (CBN) directed all financial institutions, including commercial banks and others to deduct a 0.5 per cent cybersecurity levy on electronic transfers as stipulated in the Cybercrime (Prohibition, Prevention, etc) (Amendment) Act 2024.

The directive has since created an uproar among Nigerians as they interpreted it to be that the 0.5 per cent fee would be charged on the value of the funds transferred electronically. For instance, a sum of N1,000 will attract N5, N2,000 to attract N10, N5,000 to attract N50, and so on.

But from the explanation given by the CBN in 2018 when this policy was first implemented, the cybersecurity fee is levied on the service charge by the financial institutions from the originator of the transaction.

For example, if the service charge on the transfer of N10,000 is N50, the 0.5 per cent cybersecurity levy will be charged on the N50, not N10,000, which means apart from paying N50 for Electronic Money Transfer Levy (EMTL), 7.5 per cent Value-Added Tax (VAT), and other fees, the customer will likely pay 25 Kobo as an additional fee for the transaction.

This development is not new. The Cybersecurity Act was first passed in 2015 and introduced a 0.005 per cent levy on electronic transfers. In June 2018, the CBN implemented the policy and directed banks to collect the levy on “electronic transactions occurring in a bank or on a mobile money scheme or any other payment platform that have an accompanying service charge.”

It was explained in 2018 through Mr Dipo Fatokun, who was then the Director Banking and Payments System Department, that “Electronic transactions shall be all financial transactions occurring in the bank or on a Mobile Money Scheme or any other payment platform that have an accompanying service charge; the levy shall be 0.005 per cent of the service charge (exclusive of all tax effects) from all electronic financial transactions occurring in a bank, a Mobile Money Scheme and other Payment Platforms.

“All electronic transactions (both inter and intra) that have an accompanying service charge shall qualify as eligible transactions; the effective date of collection shall be with effect from July 1, 2018.”

Now, the levy has been increased by 900 per cent and covers fintechs, payment service providers, and other financial institutions. These institutions have been mandated to remit the monies to the National Cybersecurity Fund (NCF), which would be administered by the Office of the National Security Adviser (ONSA).

In the latest circular signed by the Director of the Payments System Management Department of the CBN, Mr Chibuzo Efobi; and the Director of the Financial Policy and Regulation Department, Mr Haruna Mustafa, the apex bank emphasised that failure to remit the fees is an offence as stated in Section 44 (8) of the Act and will attract a conviction of not less than 2 per cent of the annual turnover of the defaulting business, amongst others.

“Following the enactment of the Cybercrime (Prohibition, Prevention, etc) (Amendment) Act 2024 and pursuant to the provision of Section 44 (2)(a) of the Act, ‘a levy of 0.5% (0.005) equivalent to a half per cent of all electronic transactions value by the business specified in the Second Schedule of the Act,’ is to be remitted to the National Cybersecurity Fund, which shall be administered by the Office of the National Security Adviser,” a part of the notice said.

While the outbursts have continued, many have also justified the need for the charge, especially with fraud prevalent in the Nigerian financial ecosystem.

Available data released by the Financial Institutions Training Centre (FITC) showed that Nigerian banks lost N2.09 billion to frauds in the fourth quarter of 2023, with mobile emerging as the top channel through which the largest amount was lost. 

According to the report, the N2.09 billion loss recorded in Q4 was a 77.58 per cent increase from the N1.18 billion recorded by the banks in Q3 2024.  

There are also indicators that the number might be higher this year, with the CBN forcing the hands of neobanks like Opay, MoniePoint, PalmPay, and Kuda not to open new accounts.

Despite this new fund, it is not all gloomy as 16 banking transactions are exempted from the CBN’s new cybersecurity levy.

These are Loan disbursements and repayments; Salary payments; Intra-account transfers within the same bank or between different banks for the same customer; Intra-bank transfers between customers of the same bank, Other Financial Institutions’ instructions to their correspondent banks; Interbank placements; Banks’ transfers to CBN and vice-versa; Inter-branch transfers within a bank; and Cheque clearing and settlements.

Others are Letters of Credit; Banks’ recapitalisation-related funding – only bulk funds movement from collection accounts; Savings and deposits, including transactions involving long-term investments such as Treasury Bills, Bonds, and Commercial Papers; Government Social Welfare Programmes transactions e.g. Pension payments; Non-profit and charitable transactions, including donations to registered non-profit organisations or charities; Educational institutions’ transactions, including tuition payments and other transactions involving schools, universities, or other educational institutions; as well as transactions involving the bank’s internal accounts such as suspense accounts, clearing accounts, profit and loss accounts, inter-branch accounts, reserve accounts, nostro and vostro accounts, and escrow accounts.

Adedapo Adesanya is a journalist, polymath, and connoisseur of everything art. When he is not writing, he has his nose buried in one of the many books or articles he has bookmarked or simply listening to good music with a bottle of beer or wine. He supports the greatest club in the world, Manchester United F.C.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Banking

Access Holdings Records Zero Cybersecurity Breaches, Cuts Operational Emissions by 28.47%

Published

on

Access Holdings

By Aduragbemi Omiyale

In 2025, Access Holdings Plc lowered its operational emissions by 28.47 per cent by growing its green asset portfolio to N92.15 billion, though still far from its N475 billion target.

Details of its 2025 Sustainability Report showed that operational emissions fell to 49,352 tonnes of carbon dioxide equivalent from 57,176 tonnes in 2024, supported primarily by branch solarisation across 263 locations and the deployment of 323 solar-powered ATMs, largely across Access Bank in Nigeria.

The organisation applies the operational-control approach under the Greenhouse Gas Protocol, accounting for emissions across its African footprint, with Access Bank representing the largest share.

The report reinforces its strategic shift from scale to value by showing how sustainability is being embedded in capital allocation, risk management, product development and operations.

During the year, Access Holdings deployed N72.3 billion under its Sustainable Finance Framework to eligible environmentally beneficial projects and grew its cumulative sustainability-focused loan book to $1.269 billion.

Beyond environmental outcomes, the report highlights the group’s contribution to inclusive economic participation.

In 2025, Access Holdings extended access to finance to 2,528,117 low-income individuals and onboarded 78,438 new MSMEs onto its financing platform.

Across the institution, 2.8 billion transactions were processed during the year, underscoring its role as core financial infrastructure for Africa’s real

economy. Gender-lens lending also progressed, with 354,156 loans extended to women and women-owned businesses, totalling N67.4 billion, equivalent to 24 per cent of the relevant loan portfolio.

Its Corporate Social Investment programmes reached 2,439,480 beneficiaries across education, health, entrepreneurship and the environment, delivered with partners, including UNICEF, HACEY Health Initiative and the Kenya Forest Service.

Employees recorded 359,500 volunteer hours with 100 per cent participation, while more than 50,000 trees were planted. The group notes that 2025 community figures follow a board-mandated tightening of its impact-measurement methodology and are not directly comparable with prior years. Women represent 49 per cent of the workforce, and the Access Holdings board comprised nine directors with 44.4 per cent female representation. Employee satisfaction rose to 87 per cent against an 80 per cent target, while attrition eased from about 13 per cent to about 11 per cent.

For the second straight year, Access Holdings reported zero material regulatory penalties relating to sustainability and zero cybersecurity breaches.

It mobilised $185.38 million, equivalent to N266.83 billion, in concessional funding from development finance institutions during the year and allocated a sustainability budget of N4.8 billion from profit before tax.

Sales-facing staff in the banking subsidiary carry green-portfolio targets within their individual performance measures, linking strategic sustainability goals to day-to-day execution across governance, strategy, risk management, capital allocation, products and operations.

To strengthen credibility and comparability, the report was prepared using the IFRS Sustainability Disclosure Standards, specifically IFRS S1 and IFRS S2, as the primary framework, with the GRI Standards (2021) and the SASB Standards applied as complementary references.

“Our 2025 Sustainability Report reflects the discipline with which we are converting scale into value. We reduced operational emissions by 28.47 per cent,

grew our green asset portfolio to N92.14 billion and extended financial access to about 2.5 million low-income individuals.

“These outcomes show that sustainability is not separate from our business; it is central to how we create value, manage risk and support inclusive growth across Africa,” the chief executive of Access Holdings, Mr Innocent Ike, stated.

Looking ahead, the company promised to deepen the measurable impact of its sustainability agenda, accelerate the transition of its portfolio towards low-carbon and climate-resilient assets, and grow the green asset portfolio towards the N475 billion target.

Continue Reading

Banking

NDIC Reimburses 700,000 Heritage Bank Depositors, Moves to Pay Customers of 46 Failed MFBs

Published

on

Heritage Bank headquarters

By Adedapo Adesanya

The Nigeria Deposit Insurance Corporation (NDIC) says it has paid the insured deposits of about 700,000 customers of the defunct Heritage Bank and has commenced the reimbursement of depositors of 46 microfinance banks (MFBs) whose operating licences were recently revoked by the Central Bank of Nigeria (CBN).

The chief executive of NDIC, Mr Oludare Sunday, made this known on Wednesday during a retreat for members of the House of Representatives Committee on Insurance and Actuarial Matters in Lagos.

He said the corporation immediately began settling the insured deposits of customers after the CBN revoked the licences of the 46 microfinance banks and appointed the NDIC as their provisional liquidator.

“We are working on those. The CBN revoked the licences, and we were appointed as the provisional liquidator. We have started paying depositors of those banks, and gradually we intend to cover all the insured depositors,” he said.

Mr Sunday explained that the NDIC’s responsibility extends beyond paying insured deposits to recovering outstanding loans owed to the failed institutions and disposing of their assets to generate funds for the settlement of uninsured depositors.

“Our function as liquidator involves the payment of guaranteed sums. Thereafter, we go after those who owe the institutions and have not paid. We also ensure that we sell the available assets and realise their investments towards paying the uninsured portion of the deposits. So, we have started paying the guaranteed deposits. What we are doing now is also realising the assets of those institutions,” he stated.

Although he declined to disclose the exact number of depositors of the failed microfinance banks who had been reimbursed, Sunday said the Corporation was working with the Nigerian Interbank Settlement System (NIBSS) to identify depositors through their Bank Verification Numbers (BVN) to ensure seamless payments.

“So, the more accounts we discover, the more payments we make,” he added.

Providing an update on the liquidation of Heritage Bank, the NDIC chief said about 700,000 depositors had already received their insured deposits, while efforts were ongoing to trace other customers whose identities could not be verified from available records.

He attributed the challenge to legacy accounts created before the introduction of the BVN system, as well as incomplete customer records inherited from banks that were later merged into Heritage Bank.

“If you know Heritage Bank, you know it is an amalgamation of several banks, including the acquisition of Enterprise Bank in 2014. So, if you think of banks like Guardian Express and Spring Bank, they are all part of Heritage Bank.

“There are depositors we have not been able to trace, and this is an opportunity for them to come forward. I am sure many of us did the National Youth Service Corps (NYSC) and may have left some money in an account, but there was no BVN then.

“Even the addresses we had were sometimes things like ‘opposite filling station.’ How do you trace such a person? Once they come forward, and for those we have been able to identify from the institution’s database, we have been paying them,” he explained.

Mr Sunday added that the Corporation would continue to recover outstanding loans and dispose of Heritage Bank’s assets to generate funds for the payment of liquidation dividends to depositors whose balances exceeded the insured limit.

Earlier in his remarks, he described the NDIC as a critical pillar of Nigeria’s financial safety net, stressing the need for stronger collaboration between regulators and the National Assembly as the banking sector responds to recapitalisation efforts and rapid financial technology developments.

According to him, while the ongoing banking recapitalisation programme has strengthened the resilience of financial institutions, it must be complemented by sound corporate governance, effective risk management, strict regulatory compliance and robust supervision to safeguard long-term financial system stability.

He also disclosed that more than 98 per cent of depositors, representing over 281 million accounts across insured financial institutions, are fully protected under the NDIC’s deposit insurance scheme.

Continue Reading

Banking

Zenith Bank Probes Customer Data Breach, Says Funds Remain Safe

Published

on

zenith bank logo

By Adedapo Adesanya

Zenith Bank Plc is investigating an incident involving unauthorised access to customers’ data, noting that the breach does not involve financial information and has not compromised its banking services or digital channels.

In an email sent to customers on Wednesday, the bank stated that the incident was part of a broader global cyberattack affecting multiple international organisations across various sectors.

The lender stated that it immediately activated its incident response protocols and intensified its cybersecurity and remediation efforts upon discovering the incident.

“This incident is part of a broader, global cyber-attack targeting multiple international organisations across various sectors. Upon discovery, we promptly activated our incident response protocols, cybersecurity actions and remediation efforts,” the bank said.

The bank reassured customers that its banking services and digital channels remain secure and fully operational.

As a precautionary measure, Zenith Bank advised customers to remain alert to potential phishing attempts and other forms of social engineering.

“As a precaution, we encourage our customers to remain vigilant against phishing emails, text messages, or phone calls, and never to disclose their password, PIN, One-Time Password (OTP), or other security credentials to anyone,” the bank said.

The incident is the latest in a series of cybersecurity challenges facing Nigerian financial institutions, with banks in recent months suspending their social media operations over impersonation and other fraudulent activities.

Earlier in April, the Nigeria Data Protection Commission (NDPC) said it was investigating alleged data breaches involving Sterling Bank, Remita and the Corporate Affairs Commission (CAC).

Nigerian banks have long been prime targets for cybercriminals because of the vast amounts of customer data and financial transactions they handle every day.

While many attacks have traditionally sought to steal funds, cybercriminals are increasingly targeting personal information, which can be used for identity theft, phishing schemes, account takeovers and other forms of financial fraud.

Cybersecurity threats have increasingly targeted Nigerian banks in recent years. In 2025, Union Bank of Nigeria warned customers about fraudulent websites and phishing campaigns designed to steal login credentials and personal information by impersonating the bank.

In August 2024, Guaranty Trust Bank experienced a domain-related security incident that temporarily disrupted access to its official website, although the lender assured customers that their deposits and banking services remained secure while it resolved the issue.

Continue Reading