‘Nigerian firms vulnerable to cyberattacks despite audit success’



Nigerian organisations may be meeting cybersecurity compliance requirements while remaining exposed to real-world cyber threats, an Information Technology Governance, Risk and Compliance Consultant, Akinwumi Opeoluwa Ayodele, has warned.Ayodele said many companies were placing too much confidence in internationally recognised cybersecurity certifications and audit approvals, despite the fact that passing compliance assessments does not necessarily mean an organisation can withstand an actual cyberattack.According to him, several businesses spend millions of naira obtaining security certifications, displaying audit approvals and assuring customers and regulators of their security posture, but fail to address operational weaknesses that attackers often exploit.He likened the situation to securing a house with a strong padlock while leaving a window open, noting that the effectiveness of the lock becomes irrelevant if criminals find another way inside.“Compliance and security ask fundamentally different questions. Compliance asks: Have you followed the rules? Security asks: Can you stop a real attack?” Ayodele told The PUNCH.He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. Ayodele said many companies were placing too much confidence in internationally recognised cybersecurity certifications and audit approvals, despite the fact that passing compliance assessments does not necessarily mean an organisation can withstand an actual cyberattack.According to him, several businesses spend millions of naira obtaining security certifications, displaying audit approvals and assuring customers and regulators of their security posture, but fail to address operational weaknesses that attackers often exploit.He likened the situation to securing a house with a strong padlock while leaving a window open, noting that the effectiveness of the lock becomes irrelevant if criminals find another way inside.“Compliance and security ask fundamentally different questions. Compliance asks: Have you followed the rules? Security asks: Can you stop a real attack?” Ayodele told The PUNCH.He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. According to him, several businesses spend millions of naira obtaining security certifications, displaying audit approvals and assuring customers and regulators of their security posture, but fail to address operational weaknesses that attackers often exploit.He likened the situation to securing a house with a strong padlock while leaving a window open, noting that the effectiveness of the lock becomes irrelevant if criminals find another way inside.“Compliance and security ask fundamentally different questions. Compliance asks: Have you followed the rules? Security asks: Can you stop a real attack?” Ayodele told The PUNCH.He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. He likened the situation to securing a house with a strong padlock while leaving a window open, noting that the effectiveness of the lock becomes irrelevant if criminals find another way inside.“Compliance and security ask fundamentally different questions. Compliance asks: Have you followed the rules? Security asks: Can you stop a real attack?” Ayodele told The PUNCH.He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. “Compliance and security ask fundamentally different questions. Compliance asks: Have you followed the rules? Security asks: Can you stop a real attack?” Ayodele told The PUNCH.He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. He argued that organisations often mistake documentation, policies and successful audits for genuine cybersecurity readiness, adding that attackers do not target companies based on their compliance status but exploit vulnerabilities that exist at the time of attack.“A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. “A company may have a beautifully written password policy, but if employees are writing passwords on sticky notes and leaving them visible, the policy offers little protection,” he said.The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. The consultant said businesses could also have detailed incident response plans that satisfy auditors but remain ineffective if they have never been tested under real attack conditions.“Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. “Cybersecurity certification tells you where an organisation stood when auditors visited. It says very little about where it stands when the threat arrives,” he added.Related NewsBuhari’s legacy of integrity, service will inspire Nigeria — TinubuUN, FG seek innovative financing to fast-track SDGs before 2030VIDEO: Nigerians deserve full transparency, Makinde seeks UN probe into Oyo abductionAyodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. Ayodele noted that compliance frameworks remain important because they provide minimum standards for organisations, regulators and customers, but warned that certification should be treated as a foundation rather than the final destination.He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. He compared cybersecurity certification to a driving licence, saying that while it confirms that an individual has met a minimum requirement at a particular point in time, it does not guarantee safe driving behaviour.“Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. “Real security is not an annual event. It is a continuous discipline that depends on leadership decisions, employee awareness, vulnerability management and regular testing of recovery plans,” he said.The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. The consultant stressed that cybersecurity has increasingly become a boardroom responsibility rather than only an information technology function.He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. He said organisations where executives bypass security procedures or treat cybersecurity as a regulatory obligation often create a culture where employees also ignore security practices.According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. According to him, companies that recover fastest from cyber incidents are not necessarily those with the highest number of certifications but those where security is integrated into everyday business decisions.He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. He urged boards and senior executives to move beyond asking whether their organisations are compliant and instead consider whether they would remain resilient if attacked immediately after an audit.“Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said. “Certificates matter. But governance matters more. Compliance helps satisfy regulators, while good security protects the business, its people and customers who have entrusted it with their data,” Ayodele said.