Resources
Read before you build the business case
Whitepapers on how we think, illustrative examples of how engagements typically run, and plain-language breakdowns of the regulations you're actually being audited against.
03
Whitepapers
How we think about identity governance, Zero Trust and PAM.
03
Case Studies
Illustrative engagement patterns — not specific named clients.
03
Regulatory Insights
Plain-language breakdowns of CBN and NDPA requirements.
Whitepaper
IDAM for Nigerian Banks: Compliance & Efficiency
Why identity governance is now a board-level risk topic for Nigerian banks, and a practical model for balancing audit-readiness with employee speed.
What it covers
- The tension between compliance teams that need evidence and business teams that need people productive fast.
- Why blanket quarterly recertification of every user creates review fatigue without improving security.
- A model where routine access changes are automated and manual review is reserved for genuine exceptions.
Key takeaways
- Treat JML automation as a compliance control, not only an IT efficiency project.
- Recertification should surface what changed, not re-approve the entire user base every cycle.
- Evidence trails matter as much as the access decision itself during CBN and NDPA audits.
Whitepaper
Zero Trust Identity: A Practical Roadmap for Financial Institutions
A phased approach to Zero Trust that starts with identity, not a full network re-architecture — because identity is usually the control you can change fastest.
What it covers
- Why "never trust, always verify" starts with strong, adaptive authentication rather than a network overhaul.
- A workable sequence: MFA everywhere, then privileged session controls, then continuous risk-based verification.
- How Zero Trust principles apply differently to staff access versus customer-facing channels.
Key takeaways
- Zero Trust is a direction to move in, not a single product to buy.
- Identity-first sequencing produces visible wins faster than network segmentation projects.
- Continuous verification matters most for privileged and remote access, not every routine login.
Whitepaper
Privileged Access Management: Closing the Insider Threat Gap
Most breaches involving financial institutions trace back to over-privileged or shared accounts — where PAM programs typically start, and in what order.
What it covers
- Why shared admin credentials are usually the first and highest-value target for a PAM program.
- The difference between vaulting credentials and actually monitoring privileged sessions.
- How to sequence a PAM rollout without disrupting day-to-day operations teams.
Key takeaways
- Start with the accounts that have the broadest reach — domain admins, DBAs, core banking operators.
- Session recording matters as much as credential rotation for audit and incident response.
- A phased rollout by system criticality reduces operational risk versus a big-bang deployment.
Case Study
Cutting access recertification from weeks to days
A mid-sized bank ran quarterly access recertification manually across spreadsheets, taking compliance and IT staff several weeks per cycle and creating reviewer fatigue.
Approach
- Connected HR and core systems to a central IGA platform to establish one authoritative source of truth for roles.
- Automated baseline access provisioning tied to job role, with manual review reserved for exceptions.
- Replaced blanket quarterly sign-off with an exception-based review showing only what had changed.
Outcome
- Recertification moved from a multi-week manual exercise to a matter of days.
- Reviewers spent their time on genuine exceptions instead of re-approving unchanged access.
- Audit evidence became a live export rather than a manually assembled spreadsheet.
Illustrative engagement pattern — a composite example based on common project shapes, not a specific named client.
Case Study
Eliminating shared admin credentials in core banking operations
A financial institution's database and core banking admin accounts were shared across a small operations team, with no way to attribute privileged actions to individuals.
Approach
- Vaulted all shared credentials and issued individual, time-bound elevation instead of standing admin rights.
- Enabled session recording for privileged access to core banking and database systems.
- Rotated credentials automatically instead of relying on manual, infrequent password changes.
Outcome
- Every privileged action became attributable to a named individual and a specific session.
- Standing admin access was replaced with just-in-time elevation for defined tasks.
- Incident investigation time improved because session recordings replaced guesswork.
Illustrative engagement pattern — a composite example based on common project shapes, not a specific named client.
Case Study
Federating SSO across internet banking and partner APIs
A bank onboarding several fintech partners needed a consistent, secure login experience across internet banking, admin consoles, and partner-facing APIs.
Approach
- Introduced a federated identity layer using standards-based SSO (SAML/OAuth/OIDC) across channels.
- Applied adaptive MFA that stepped up verification based on device, location and transaction risk.
- Gave partner fintechs a defined onboarding path instead of one-off, custom integrations each time.
Outcome
- New fintech partners onboarded against a repeatable integration pattern rather than bespoke work each time.
- Users experienced one consistent login across channels instead of separate credentials per system.
- Step-up authentication reduced friction for low-risk logins while still protecting sensitive transactions.
Illustrative engagement pattern — a composite example based on common project shapes, not a specific named client.
Regulatory Insight
From NDPR to NDPA: What Changed
Nigeria's data protection framework moved on in 2023, with new operational guidance issued in 2025 — here's what that means if your compliance documents still only mention "NDPR."
What changed
- The Nigeria Data Protection Act (NDPA) 2023 replaced the NDPR 2019 as the country's primary data protection law, enforced by the independent Nigeria Data Protection Commission (NDPC).
- The General Application and Implementation Directive (GAID), issued by the NDPC, sets out registration, audit and compliance procedures under the NDPA.
- Organizations designated as Data Controllers/Processors of Major Importance must file annual Compliance Audit Returns with the NDPC.
What this means for you
- If your compliance materials still only reference "NDPR," they may be describing a framework that has been substantially superseded.
- Demonstrating who accessed personal data, when, and under what authorization is a direct NDPC audit expectation — an identity governance problem as much as a legal one.
- Confirm current registration and audit-return deadlines directly with the NDPC, as dates have shifted before.
General information, not legal advice — confirm current obligations with your compliance/legal counsel or the NDPC directly.
Regulatory Insight
CBN's Risk-Based Cybersecurity Framework, Plain-Language
What the CBN actually expects from Deposit Money Banks and Payment Service Banks under its cybersecurity framework.
What it requires
- Issued for Deposit Money Banks and Payment Service Banks, with a related framework covering Other Financial Institutions.
- Covers governance, risk identification, third-party risk, vulnerability management and cybersecurity maturity assessment.
- Requires cyber incidents to be reported to the CBN within 24 hours of occurring.
What this means for you
- Third-party and vendor risk assessment is an explicit expectation, not an optional add-on.
- Annual compliance audits and risk-based examinations mean access-control evidence needs to be ready year-round, not assembled just before an audit.
- Tight incident-reporting timelines mean identity and access logs need to be queryable quickly, not buried in disconnected systems.
General information, not legal advice — confirm current obligations with your compliance/legal counsel or the CBN directly.
Regulatory Insight
PCI DSS, ISO 27001 & SWIFT CSP: One Common Thread
Three different frameworks — all of them ultimately asking the same question about access control.
What each one asks
- PCI DSS expects access to cardholder data restricted on a need-to-know basis, with strong authentication for anyone who can reach it.
- ISO 27001's access control clause expects documented processes for granting, reviewing and revoking access — the same JML lifecycle described on our Services page.
- The SWIFT Customer Security Programme places specific emphasis on restricting and monitoring privileged access to SWIFT-connected infrastructure.
What this means for you
- A single, well-run IGA/PAM program can produce evidence that satisfies several frameworks at once, instead of running parallel compliance efforts.
- Auditors across all three frameworks tend to ask the same underlying question: can you prove who had access, and why?
General information, not a substitute for formal certification or audit guidance from each framework's governing body.