
Incident Response Plan: How Nigerian Financial Institutions Should Respond to Data Breaches
Key Takeaways
- A data breach incident response plan helps Nigerian financial institutions detect, contain, investigate, and recover from security incidents involving customer records, financial information, compromised accounts, malware, accidental disclosures, or third-party providers.
- The seven steps of incident response are preparation, identification, containment, eradication, recovery, communication and reporting, and lessons learned. Financial institutions should document responsibilities, preserve evidence, and coordinate security, compliance, legal, and operations teams throughout the process.
- Under Section 40 of Nigeria’s Data Protection Act 2023, a personal data breach likely to create a risk to individuals’ rights and freedoms must be reported to the NDPC within 72 hours of the data controller becoming aware of it. Breaches likely to create a high risk may also require communication to affected individuals without undue delay.
- Effective solutions to data breaches combine access controls, multi-factor authentication, encryption, security monitoring, vendor risk management, employee training, and tested incident response procedures. Financial institutions should investigate the root cause, restore systems securely, and update controls to reduce the risk of recurrence.
A data breach can expose customer information, disrupt financial services, enable fraud and damage trust. For Nigerian banks, fintechs and payment service providers, responding effectively requires more than fixing the technical problem. They must also investigate what happened, protect affected customers, preserve evidence and determine whether regulatory notifications are required.
A documented incident response plan gives financial institutions a clear process for managing these situations. It defines who takes action, how the breach is contained, how the impact is assessed and what happens before normal operations resume.
Under Nigeria’s data protection framework, institutions must also understand their obligations when a breach involves personal data. The right incident response strategies help security, compliance, legal and operations teams work together instead of reacting independently.
This guide explains what counts as a data breach under the Nigeria Data Protection Act (NDPA), the seven steps of incident response, and the practical actions financial institutions should take before, during and after a breach.
What Is an Incident Response Plan?
An incident response plan is a documented set of procedures an organisation follows to identify, contain, investigate and recover from a security incident. It helps teams respond quickly, limit damage and restore affected systems safely.
For financial institutions, a data breach incident response plan should cover incidents such as:
Unauthorised access to customer records or financial information.
Compromised employee accounts or stolen login credentials.
Malware or ransomware affecting systems that store customer data.
Accidental disclosure of personal information to the wrong recipient.
Unauthorised changes to customer records or transaction data.
Data theft involving a third-party service provider.
The plan should identify the people responsible for responding, the systems and information that need protection, the steps for escalating an incident, and the process for deciding whether regulators or affected customers must be notified.
A good plan also establishes how the institution will document decisions, preserve evidence and learn from the incident. These details matter because a response must be both effective and defensible.
Why Do Financial Institutions Need an Incident Response Plan?
Financial institutions handle sensitive information, including identity documents, account details, transaction records and customer contact information. If this information is exposed, the consequences may extend beyond the initial security incident.
READ ON: NDPA 2023 for Financial Institutions in Nigeria
An effective incident response plan helps an institution:
Limit damage: Contain unauthorised access before the incident spreads.
Protect customers: Reduce the risk of identity theft, account takeover and fraud.
Meet regulatory obligations: Assess reporting and notification requirements promptly.
Maintain evidence: Keep records that support investigations and regulatory reviews.
Restore operations: Return affected systems to service safely.
Prevent recurrence: Identify weaknesses and strengthen security controls.
The objective is not simply to close an incident. It is to understand what happened, control the damage, meet applicable obligations and reduce the likelihood of another breach.
What Counts as a Data Breach Under the NDPA?
Under Section 65 of the Nigeria Data Protection Act 2023, a personal data breach is a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
In simple terms, a personal data breach occurs when personal information is lost, exposed, changed or accessed without authorisation. It does not have to involve a hacker or a deliberate attack.
Examples include:
Scenario | Could it be a personal data breach? |
A cybercriminal accesses customer identity documents. | Yes. Personal data has been accessed without authorisation. |
An employee emails a customer database to the wrong recipient. | Yes. Personal data may have been disclosed without authorisation. |
A compromised account allows someone to download customer records. | Yes. Unauthorised access or disclosure may have occurred. |
A system failure permanently destroys stored customer records. | Yes. Accidental destruction or loss of personal data may qualify. |
An employee accesses records they are not authorised to view. | Potentially. The institution should investigate the access and its circumstances. |
A cybersecurity incident does not automatically qualify as a personal data breach. For example, an attempted attack that is blocked before any personal data is compromised may be a security incident without being a personal data breach. The institution must investigate the facts before making that determination.
What Does the NDPA Require After a Personal Data Breach?
Section 40 of the NDPA sets out breach notification obligations for data controllers.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach. If notification is delayed, the controller must provide reasons for the delay.
Where a breach is likely to result in a high risk to individuals’ rights and freedoms, the controller must also communicate the breach to affected data subjects without undue delay, subject to the Act’s applicable provisions.
The notification assessment should consider the type of personal data involved, the potential harm to individuals, the extent of exposure and the likelihood that the information could be misused.
Financial institutions should also check any additional obligations that apply under their sector-specific regulatory framework. A single incident may trigger data protection, cybersecurity and other reporting requirements, depending on the institution and the circumstances.
Important: The 72-hour period is not a general deadline for every cybersecurity incident. It relates to the applicable NDPA notification obligation for a personal data breach that meets the statutory risk threshold. Institutions should escalate suspected breaches immediately so the assessment does not delay required action.
For broader Nigerian data protection obligations, see our guide to NDPA 2023 and data protection requirements in Nigeria.
A Practical Data Breach Scenario in a Nigerian Fintech
Imagine a Nigerian fintech discovers that an employee’s login credentials have been compromised. Someone has used the account to access customer records, including names, phone numbers, identity information and transaction histories.
The security team detects unusual activity, but it does not yet know how many records were accessed or whether the information was copied.
The fintech now has several priorities:
Disable the compromised account and stop further unauthorised access.
Investigate the account’s activity to establish which systems and records were affected.
Preserve logs and other evidence that could help determine what happened.
Involve compliance and legal teams to assess the breach and applicable reporting obligations.
Determine whether the incident meets the NDPA’s notification threshold and whether other regulators must be notified.
Fix the vulnerability, secure affected accounts and monitor for further suspicious activity.
Review the incident and strengthen access controls to reduce the risk of recurrence.
The fintech should not wait until every detail is confirmed before beginning its response. Containment, evidence preservation, investigation and notification assessment can happen in parallel.
This is why an incident response plan should be prepared before a breach occurs. Without clear responsibilities and escalation procedures, teams may waste valuable time deciding who should act, what to investigate and who should communicate with regulators.
What Are the 7 Steps of Incident Response?
An effective data breach incident response plan follows seven steps, from preparing for potential incidents to reviewing what happened. Each step helps financial institutions respond quickly, limit damage and strengthen their security.
1. Preparation
Prepare before a breach occurs. Assign response roles, identify critical systems and sensitive data, establish escalation procedures, and test the incident response plan.
2. Identification
Detect and confirm the incident. Review security alerts, access logs and affected accounts to understand what happened and whether personal data may be involved.
3. Containment
Stop the incident from spreading. Disable compromised accounts, restrict unauthorised access or isolate affected systems while preserving evidence for investigation.
4. Eradication
Remove the cause of the breach. Fix security vulnerabilities, remove malicious access and reset compromised credentials to prevent further unauthorised activity.
5. Recovery
Restore affected systems safely. Test them to confirm they are secure, then monitor for suspicious activity before returning to normal operations.
6. Communication and Reporting
Inform the relevant internal teams and assess regulatory notification requirements. Notify the appropriate regulators and affected individuals where required by law.
7. Lessons Learned
Review how the breach happened and how the response was handled. Document the findings and use them to improve security controls, staff training and the incident response plan.

These steps should not always be treated as a strict sequence. For example, a financial institution may need to begin regulatory notification assessment while containment and investigation are still underway.
The institution should also document key decisions throughout the process. A clear record helps teams understand the response later and demonstrate how they assessed risks and met their obligations.
Frequently Asked Questions

6 Ways to Protect Your Business From Hackers this December

How Machine Learning is Used In Fraud Prevention For E-commerce
