---
title: "Insider Threats in Nigeria: Prevent Data Leaks with Access Control and Offboarding"
url: https://planetweb.ng/insider-threats-in-nigeria/
date: 2025-04-15T15:31:50+00:00
modified: 2026-08-29T22:09:07+00:00
lang: en_US
---

# Insider Threats in Nigeria: Prevent Data Leaks with Access Control and Offboarding

## Insider Threats in Nigeria: What Every Business Must Know

Most Nigerian businesses are so focused on external attacks that they forget the threat might already be inside the building. The firewall is up, the antivirus is running, and the IT team is watching for suspicious traffic from outside. Meanwhile, someone in accounts is downloading the entire customer database. Insider threats are not a new concept, but in Nigeria, they carry a particular weight. The country's rapid digital adoption has outpaced the maturity of most organisations' internal controls. Data governance, offboarding procedures, and access management policies- the basics that make insider threat programmes work- are often missing, inconsistently applied, or treated as paperwork rather than everyday practice. Add to that the economic pressures facing many Nigerian employees, the prevalence of informal work culture in mid-sized businesses, and the fact that most incidents are resolved internally rather than reported, and the conditions for a persistent, largely invisible risk are already in place. This article unpacks who insider threats are in the Nigerian context, what drives their behaviour, and the warning signs organisations routinely miss. It also covers what a realistic prevention strategy looks like and the legal exposure businesses carry under the Nigeria Data Protection Act (NDPA) 2023, since an insider-caused breach doesn't reduce that exposure. It simply moves the question from "who did this" to "why weren't the controls in place?"

## The Scale of the Problem: Nigeria vs the World

Insider threats are often overlooked, yet they represent one of the most dangerous cybersecurity risks organisations face. The challenge is particularly acute in Nigeria, where informal work cultures, underfunded IT departments, and inconsistent governance amplify the risk. Insider threats account for nearly 30% of all data breaches worldwide. In Nigeria specifically, the [Nigeria Inter-Bank Settlement System (NIBSS)](https://nibss-plc.com.ng/) now identifies insider abuse as the single greatest threat within the broader category of social engineering fraud, the dominant fraud technique across the country's banking and fintech sector. The Financial Institutions Training Centre recorded a 23.4% quarter-on-quarter rise in staff-involved fraud in Q2 2024, with cases climbing from 47 to 58 and 49 employees terminated as a result. By Q1 2025, staff-linked fraud losses reached ₦3.3 billion, a 137% increase from the previous quarter, despite fewer reported cases overall, a pattern that echoes the broader shift toward fewer but more damaging incidents seen across Nigerian fraud data generally. The First Bank case remains the most documented example. A manager on the bank's electronic products team at its Iganmu head office allegedly diverted ₦40 billion by processing customer reversal requests into merchant accounts he controlled. He was the final approval point on his team, so no second approver was required, and the fraud only surfaced when a customer complaint triggered an internal review. A single missing control point, not a sophisticated attack, is what let it run for as long as it did. Separately, research into Nigerian financial institutions between 2020 and 2024 found that insider-caused security breaches grew by 92% over that period, alongside sharp increases in ransomware and phishing. Most incidents never make it to the public record at all. According to **Confidence Staveley**, Executive Director of Cybersafe Foundation, "*We see that generally, a lot of organisations absolutely deny the occurrence of cyberattacks and data breach incidents, even in the face of overwhelming evidence.*" This culture of silence allows insider threats in Nigeria to persist unchecked. While firewalls and antivirus software receive the most attention, the most serious cybersecurity risk in Nigerian workplaces is often the one facilitated by a trusted insider, whether knowingly or not.

## Who Are the Insiders? Real Threats, Real People

These threats are technical in nature but also rooted in human behaviour and organisational culture. They do not come in a single mould. In Nigerian workplaces, they often stem from complex interpersonal dynamics, poor governance, and economic stressors. Here are the core insider personas:

### \1. The Disengaged Employee

Some employees feel invisible. Perhaps they have been overlooked for promotions or are exhausted by toxic leadership. These individuals do not need to be malicious; their apathy alone makes them careless with sensitive data. When disengaged staff do not see the value in protecting company assets, security breaks down.

### \2. The Opportunist

For some employees, company data becomes a career asset rather than a business asset. Whether it is a database to impress a new employer or client information to help launch a startup, these actors treat company assets as personal tools for career or business gain. This is especially prevalent in sectors such as technology and consulting.

### \3. The Over-Helper

Often well-meaning, this individual overrides rules to "get things done." They might send documents to personal emails to work from home or share login credentials to meet a deadline. They do not think they are causing harm, but they open backdoors unintentionally.

### \4. The Exit Risk

Departing employees are particularly high-risk. Whether they are resentful about how they were treated or feel entitled to "take what they built," exits are a major blind spot in Nigerian offboarding practices.

### \5. The Trusted Vendor or Contractor

With little internal oversight, outsourced developers, consultants, or IT support providers may have elevated access. Their work is rarely audited, and when relationships end poorly, organisations are often left exposed. As **Zainab O. Sanni**, an Information Security Specialist, explains: "*Insider threats in Nigeria refer to risks posed by employees, former employees, contractors, or business associates who have inside information concerning the organisation's security practices, data, and computer systems.*" Understanding these personas helps Nigerian business leaders move from vague suspicion to targeted prevention. For a broader overview, see [Fortinet's guide to insider threats](https://www.fortinet.com/resources/cyberglossary/insider-threats).

## Why Do Insiders Leak Data? The Human Triggers

These incidents are almost never random. They are triggered by real human experiences and organisational dysfunctions, and several local realities make Nigerian workplaces particularly exposed. Financial pressure is a key driver. Employees facing unpaid salaries or inflationary pressures are more susceptible to bribes or unethical behaviour. Toxic work environments compound this, where disrespect, overwork, and micro-management create resentment that sometimes surfaces as sabotage or negligence. Peer normalisation is another quiet risk. If data sharing or unauthorised device use is seen as standard practice, it becomes a collective blind spot that no single person feels responsible for fixing. Poor offboarding is the final gap: failing to de-provision users promptly or ignoring staff grievances before departure are among the most avoidable vulnerabilities in Nigerian workplaces. Addressing insider threats in Nigeria means dealing with the emotional, procedural, and cultural factors that make data leakage seem justified or invisible, not only the technical gaps.

## Warning Signs Worth Watching For

Prevention starts with knowing what to look for. Most insider incidents are not spontaneous; they leave a trail. The problem is that Nigerian organisations rarely have the processes in place to spot it in time. On the behavioural side, watch for staff who begin expressing unusual frustration about perceived unfair treatment or management decisions. A sudden interest in data or systems outside their normal responsibilities is worth noting, as is an employee who starts asking questions about offboarding processes or data retention policies before any official notice has been given. The technical signals are often more concrete. Bulk file downloads or mass email exports, particularly in the days before a resignation or termination, are a consistent pattern in post-breach investigations. Off-hour logins, unfamiliar devices, repeated attempts to access restricted folders, and bulk downloads should all trigger a closer look. Sensitive documents forwarded to personal email accounts or uploaded to personal cloud storage are among the clearest warning signs. Contractor-specific red flags include continued system access after a project has formally ended, the use of credentials outside agreed working hours, and resistance to standard code review or audit processes. None of these signs, on their own, is proof of malicious intent. But they are the kind of patterns that a structured monitoring programme, applied transparently and consistently, can surface before a breach occurs rather than after.

## What's at Stake? The Consequences Go Beyond Fines

Too often, Nigerian companies treat cybersecurity as a checkbox task until it is too late. The consequences of insider threats go far beyond regulatory penalties. Reputational damage is often the most lasting. In tightly networked sectors such as banking, law, or real estate, word spreads quickly, and one incident can permanently shut doors. Sterling Bank's public denial after its January 2025 breach, and the scrutiny that followed, are a reminder of how much attention these incidents draw, regardless of how they're eventually resolved. Client attrition often follows: breaches create fear, and clients quietly take their business elsewhere, almost never returning. Financially, fraud, stolen customer databases, and the leaking of trade secrets to competitors all hit the bottom line directly. In the aftermath of a breach, internal trust breaks down too: innocent employees are scrutinised, collaboration suffers, and the best talent quietly exits. Further reading on the scale of this problem is available in [this report on insider threat trends](https://vpnalert.com/resources/insider-threat-statistics/).

## NDPA Liability Doesn't Shrink Because an Insider Caused the Breach

This is the part many Nigerian business owners miss. The [Nigeria Data Protection Act 2023](https://planetweb.ng/nigeria-data-protection-act-for-businesses/) does not create a carve-out for insider-caused breaches. If personal data is compromised, the organisation is still the data controller, and the regulatory obligations still apply, regardless of who caused the incident. That means if an employee leaks a customer database, the business is required to notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach. The clock does not pause for internal investigation, and it includes weekends and public holidays. If the breach poses a high risk to affected individuals, direct notification to them may also be required. Penalties for inadequate data protection practices under the NDPA can reach ₦10 million or 2% of annual gross revenue, whichever is higher, and the NDPC has shown a willingness to investigate. "It was an insider" is not a defence against a finding of inadequate technical and organisational measures. Failing to have access controls, monitoring, or offboarding procedures in place is itself a compliance failure, whether or not a breach ever occurs. The General Application and Implementation Directive (GAID), which replaced the older Nigeria Data Protection Regulation (NDPR) as the operative compliance standard in September 2025, makes this expectation explicit: documented access controls and monitoring aren't optional extras; they're part of what an audit checks for. The practical implication is that insider threat prevention and NDPA compliance are not two separate projects. A data protection programme that doesn't include access control, employee training, and exit procedures from day one is incomplete. For a full breakdown of the law's requirements, see the *[NDPA Compliance Guide for Nigerian Businesses](https://planetweb.ng/nigeria-data-protection-act-for-businesses/)*.

## Case Studies: When Insider Threats Hit Home

One of the clearest recent examples comes from Sterling Bank. In January 2025, police filings alleged that external actors, working in collusion with some staff, compromised the bank's systems and diverted roughly ₦1.2 to ₦1.3 billion. Sterling denied wrongdoing, but the case is a reminder that insider risk doesn't always mean an employee acting alone; sometimes it means an employee acting as the entry point for someone outside. The *[Nigerian Data Breach Case Studies](https://planetweb.ng/nigerian-data-breach-case-studies/)* collection covers this and five other real Nigerian incidents in full. The following three cases are composites drawn from common patterns seen across Nigerian workplaces, not individual named incidents.

### Case 1: An HR Executive's Revenge

**What Happened:** A mid-level HR manager at a Lagos consultancy was dismissed for misconduct. Before exiting, they downloaded the full employee records database, including bank details and salary history, and anonymously leaked it. **Impact:** Two major clients suspended their contracts, pending investigation. Internal morale declined, particularly among staff whose salaries and benefits had become public knowledge. **Lessons Learned:** Exit interviews must be paired with IT de-provisioning. Organisations should implement data access logs and flag high-risk exits before they escalate.

### Case 2: The Ghost Developer

**What Happened:** An e-commerce startup hired a freelance developer to build a payment module. The contractor embedded a backdoor script and re-entered months later to siphon customer card data. **Impact:** Dozens of customers reported fraud. The company faced a PR backlash and was temporarily blacklisted by its payment processor. **Lessons Learned:** All third-party code should undergo thorough auditing. Contracts must mandate the removal of post-engagement access and the vetting of external contributors.

### Case 3: The 'Helpful' Sales Lead

**What Happened:** A senior sales lead at a broadband firm shared internal bid documents with a friend at a rival company. His intention was to help, not sabotage. **Impact:** The rival undercut the bid. The broadband firm lost a multimillion-naira government contract, triggering an internal investigation and public scrutiny. **Lessons Learned:** Intent does not matter in cybersecurity. Formal data classification and internal access training could have prevented this lapse.

## Solutions That Work (Without Breaking the Bank)

Preventing insider threats in Nigeria is not about expensive software. It is about mindset, structure, and discipline. Here is a dual-layered framework that balances strategic and operational responses, aligned with global best practices, including those highlighted in [Security Magazine](https://www.securitymagazine.com/articles/94156-combating-insider-threats-in-the-age-of-remote-work).

### Strategic-Level Actions

These are decisions leadership has to own, not delegate entirely to IT.

1. **Establish Clear Data Governance**: Define what counts as sensitive data, who owns it, and how it is handled across the business.
2. **Board-Level Ownership**: Cyber risk needs a seat at the board table. Governance, rather than IT alone, must drive insider threat strategies.
3. **Invest in Leadership Training**: Equip department heads with awareness of how cultural lapses and informal practices become security risks.

### Operational-Level Defences

These are the day-to-day controls that make the strategic decisions above actually stick.

1. **Least Privilege Access Control**: Grant employees access to data only as necessary for their role, and automate revocation during offboarding.
2. **Security Awareness Campaigns**: Go beyond onboarding. Make cyber hygiene part of team routines, with real-world examples and local case studies. The *[guide to cybersecurity for Nigerian SMEs](https://planetweb.ng/cybersecurity-for-nigerian-smes/)* covers how to build this on a limited budget.
3. **Endpoint Monitoring (Ethical and Transparent)**: Use tools that flag anomalies, such as off-hour logins or bulk downloads, with clear internal communication about their purpose.
4. **Exit Risk Scoring**: Evaluate departing employees based on access level, past behaviour, and recent grievances. High-risk exits should trigger additional checks.
5. **Vendor Security Audits**: Third parties must comply with the organisation's cybersecurity policies. Service Level Agreements should include security clauses that are actually enforced.

## If It Has Already Happened: What to Do Next

Not every organisation will catch the threat in time, even with prevention as the goal. If an insider breach is suspected or already underway, the steps taken in the first few hours matter enormously, both for limiting the damage and for meeting NDPA obligations. The short version: isolate compromised systems, preserve evidence, and start the 72-hour NDPC notification clock the moment a high-risk breach is confirmed. Systems should not be wiped or reimaged before forensic investigators arrive, and every decision and action taken from the point of discovery should be documented. For a full step-by-step guide on managing a breach response in Nigeria, including NDPA notification requirements and what regulators expect to see, the *[guide to responding to data breaches in Nigeria](https://planetweb.ng/responding-to-data-breaches-in-nigeria/)* covers the complete process.

## Insider Threats Thrive in the Shadows of Assumption

"It's just James from Admin." "We've worked with that consultant for years." "She'd never do that." But cybersecurity risks in Nigerian workplaces do not always come from the outside. They happen quietly, often by people who did not intend to cause harm, and sometimes by those who did. **Dr. Obadare Peter Adewale**, Co-founder of Digital Encode, puts it plainly: "*Many Nigerian organisations only pay lip service to security, and the absence of an active and communicative authority figure allows many excesses.*" Future-proofing a Nigerian business in a fast-digitising economy takes more than antivirus software. It takes a people strategy rooted in accountability, transparency, and structure, access control, training, and offboarding that actually gets followed rather than only written down.

## How PlanetWeb Can Help

Most insider incidents don't happen because a business ignored security. They happen because one ordinary gap- an ex-employee whose access was never revoked, a contractor nobody re-checked, a warning sign nobody was watching for- went unaddressed until someone used it. PlanetWeb works with Nigerian organisations to close those gaps: access control, offboarding procedures, staff training, and the documented compliance posture the NDPA now actively enforces. Professional services firms carry a particular version of this risk, since client folders and correspondence often sit in one consultant's inbox rather than a structure the firm actually controls; the *[guide to IT for professional services firms](https://planetweb.ng/it-for-professional-services-firms/)* covers that gap in more depth. If you'd like a clearer picture of where your organisation stands, [get in touch](https://planetweb.ng/free-it-consultation/).
