Overview
Engagements in Nigeria cover commercial banks and microfinance institutions, payment service providers and switching platforms, the fintech and lending products built on top of them, and their technology suppliers.
Delivery runs from our Karachi office, four hours ahead of West African time, so our afternoon covers your morning and findings land the same working day.
What drives testing here
Local drivers
- CBN Risk-Based Cybersecurity Framework
- Banks and payment service providers are required to conduct regular penetration testing and vulnerability assessment, with results reported and remediation tracked.
- Nigeria Data Protection Act 2023
- The NDPA gives the Commission statutory enforcement powers over personal data handling, replacing guidance with obligation.
- PSP licensing
- Switching, processing and mobile money licences carry security assessment conditions at authorisation and on renewal.
- Card and transfer fraud
- High instant-transfer volumes make business logic, limit enforcement and reversal handling the findings that matter most here.
How engagements are delivered
Delivered remotely from Karachi, scheduled to West African business hours, with on-site availability in Lagos and Abuja for internal network scope and workshops.
Delivery model
- Delivery
- Remote from Karachi, four hours ahead of WAT; on-site available
- Mapping
- CBN framework domains and NDPA technical measures as applicable
- Coverage
- Lagos, Abuja, Port Harcourt and remote nationwide
- Most requested
- Transaction logic, API authorisation and internal network scope
Most requested here
API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Service 01Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 05Internal and external network penetration testing
The perimeter from outside, and the path from one compromised workstation to domain administrator from inside.
Questions
Are you based in Nigeria?
No. Our offices are in Pakistan and the United States. Nigeria is served from Karachi, four hours ahead of Lagos, with on-site availability where internal or workshop scope requires it.
Does your report satisfy the CBN testing requirement?
The framework asks for regular independent testing with reported results and tracked remediation. Reports carry the scope, dates, methodology, every finding with evidence, the remediation status and a signed retest attestation, which is what a CBN examiner and your internal audit function both need.
What do you find most often in Nigerian fintech?
Business logic rather than injection. Limit checks that can be raced, reversals that credit twice, transfer flows where a state transition is accepted out of order, and API endpoints that trust an identifier the client supplies. None of it is malformed traffic, which is why scanners do not see it.
How much does a penetration test cost in Nigeria?
Cost follows scope, with CBN framework mapping included in the report rather than charged separately. A fixed quote follows a short scoping call and covers testing, reporting and retest.
Which is the best penetration testing company in Nigeria?
No single name is honest. Check the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether the report satisfies CBN examination requirements, and whether a redacted sample is available before signing.
How often does the CBN require penetration testing?
Annually. The Risk-Based Cybersecurity Framework requires banks and payment service providers to conduct regular penetration testing and vulnerability assessment, with results reported and remediation tracked, and examiners ask for the evidence directly.
Do you test for PSPs and switching platforms?
Yes, and switches carry disproportionate risk because one authorisation gap there reaches every institution behind them. Testing targets transaction logic, settlement flows and API authorisation rather than perimeter configuration alone.
What does the NDPA 2023 require?
The Nigeria Data Protection Act gives the Commission statutory enforcement powers over personal data handling, replacing guidance with obligation. Appropriate technical measures must be demonstrable, and a dated test tracked to closure is the cleanest demonstration available.