Compliance · · 10 min read · By Hackrowd Team
CBN Risk-Based Cybersecurity Framework: Penetration Testing Guide
A practical guide to CBN cybersecurity framework penetration testing, governance evidence, remediation records and examination readiness for Nigerian financial institutions.
## Which CBN Cybersecurity Framework Applies in 2026?
The current instrument for deposit money banks and payment service banks is the **Central Bank of Nigeria Risk-Based Cybersecurity Framework and Guidelines issued in 2024**, effective 1 July 2024. It replaced the 2018 framework for the institutions within its scope.
Start by confirming your licence category. A payment service bank is not the same thing as every payment service provider, and related CBN instruments may apply to other licensed payment businesses. Your compliance team should map the exact entity and services to the current CBN publications rather than relying on an old framework downloaded from a third-party website.
The framework expects supervised financial institutions to manage cyber risk through governance, risk assessment, technical controls, assurance and reporting. Vulnerability assessment and penetration testing support that system, but a pentest report alone is not a complete compliance programme.
## What Penetration Testing Should Cover
A defensible scope follows the institution's risk assessment and critical asset inventory. It commonly includes:
- Internet-facing infrastructure and remote-access services
- Internal networks and identity infrastructure
- Web and mobile banking applications
- Customer, partner and payment APIs
- Cloud services that process regulated workloads
- Connections to material third parties
- Segmentation boundaries protecting critical environments
Automated vulnerability scanning and manual penetration testing are different forms of assurance. Scanning identifies known weaknesses at scale. A manual-led penetration test validates exploitable attack paths, authorization weaknesses and business-logic risks under signed rules of engagement.
Do not invent a universal testing frequency from an outdated summary. The programme should document a risk-based schedule, test after significant changes, and confirm the applicable minimum directly from the current CBN framework and any licence-specific direction.
## The Governance Evidence Examiners Need
Technical work becomes auditable when management can show what was approved, what was found, what changed and who accepted any remaining risk. Prepare:
- A board-approved cybersecurity policy and risk appetite
- A current asset inventory and risk assessment
- An approved VAPT plan defining scope, cadence and independence
- Signed rules of engagement and tester qualification evidence
- Internal, external, application and API test reports as applicable
- A finding register with owners, severity, deadlines and exceptions
- Remediation evidence and independent retest results
- Third-party assurance for outsourced critical services
- Cybersecurity self-assessment records and supporting evidence
- Board or Risk/IT Committee papers showing oversight of material findings
- Incident-response and business-continuity exercise records
This evidence chain matters. A report marked complete is weak evidence if critical findings remain open without an owner, deadline or documented risk decision.
## A Practical Examination-Readiness Workflow
### 1. Confirm applicability and ownership
Record the regulated entity, licence category, accountable executive and board committee. Keep the 2024 framework in the compliance library and label the 2018 version as superseded where appropriate.
### 2. Tie scope to risk
Map crown-jewel systems, customer channels, payment flows, privileged access and third-party dependencies. Explain exclusions in writing rather than silently leaving systems out.
### 3. Commission independent testing
Use testers who are operationally independent of the systems they assess. The methodology should cover discovery, manual validation, controlled exploitation, impact analysis and safe cleanup.
### 4. Remediate and retest
Prioritize exploitable business risk, not only scanner severity. Preserve tickets, configuration changes, code fixes and retest evidence.
### 5. Report to governance bodies
Translate technical findings into customer, operational, fraud and regulatory impact. Board reporting should show trends, overdue items, accepted risks and funding decisions.
## Common Gaps
- Reusing the 2018 framework without checking the 2024 instrument
- Treating a vulnerability scan as a penetration test
- Testing only public IP addresses while excluding applications and APIs
- Missing third-party connections from scope
- Closing findings without retest evidence
- Presenting a technical report without board-level risk reporting
- Setting an annual date but failing to test after major changes
## CBN Penetration Testing Evidence Checklist
- Confirm the institution and applicable current CBN instrument
- Maintain a board-approved cybersecurity and VAPT policy
- Keep a risk-based test schedule and approved scope
- Retain signed engagement documents and tester credentials
- Test critical networks, applications, APIs and relevant third parties
- Track every finding to remediation, exception or risk acceptance
- Retest corrected exploitable findings
- Include material outcomes in governance reporting
- Retain self-assessment, incident exercise and continuity evidence
## Frequently Asked Questions
### Does the CBN framework require only automated scanning?
No. Vulnerability assessment and penetration testing serve different purposes. A mature programme uses repeatable scanning and manual-led testing appropriate to risk.
### Is one annual penetration test always enough?
Do not assume that. Your documented schedule should follow the current framework, risk profile and significant system changes. Some systems may need more frequent assurance.
### Can a penetration test guarantee CBN compliance?
No. It supports technical assurance. Compliance also depends on governance, risk management, remediation, reporting and other controls.
### What should go to the board?
Material findings, business impact, remediation status, overdue risk, accepted exceptions and trend information—not an unfiltered technical dump.
## Prepare an Auditor-Ready Assessment
Hackrowd provides manual-led [penetration testing](/penetration-testing), remediation verification and executive reporting for Nigerian financial institutions. We can align scope and evidence to your risk register while your legal and compliance advisers confirm regulatory applicability.