FITC was established in 1981 as a Limited by Guarantee not for profit professional services organisation, based on the Company’s Act of 1968. It was created in response to the recommendations of the Pius Okigbo Committee, which was set-up by the Federal Government of Nigeria in 1976, to review the Nigerian financial system. FITC’s Institutional Members are members of the Nigerian Banker’s Committee, comprises of the Central Bank of Nigeria, the Nigeria Deposit Insurance Corporation and all licensed banks in Nigeria.
Read More
Enhancing Board Oversight of Cybersecurity, Digital Risk Management and AI Governance for Competitive Advantage

Background
Cybersecurity has become a matter for direct board judgement because technology failure can impair revenue, liquidity, customer access, confidential information, contractual performance and the legal standing of an organisation. The board is therefore required to examine more than reports of attempted attacks, malware events or security expenditure. Its responsibility extends to determining which business services must remain available, the systems and data on which those services depend, the degree of interruption the organisation can absorb and the conditions under which management must escalate a technology incident. This requires a firm connection between business strategy, technology architecture, risk appetite, capital allocation, insurance, outsourcing and executive accountability.
Digital risk also arises from decisions that may not initially appear to be cybersecurity matters. Cloud concentration, third-party platforms, application programming interfaces, automated decision systems, identity infrastructure, payment channels, data repositories, software dependencies and technology acquisitions can each introduce exposures that remain hidden within operating units. Board oversight must therefore distinguish between technical control activity and actual risk reduction. This distinction depends on reliable information concerning privileged access, vulnerability exposure, system criticality, control exceptions, recovery capability, supplier dependencies, loss estimates and the effectiveness of management remediation. Without such evidence, cyber reporting may describe activity while leaving the board unable to determine the organisation’s true exposure.
Artificial intelligence introduces a further class of governance questions concerning authority, data ownership, model validity, explainability, intellectual property, privacy, security, human intervention and accountability for automated outcomes. Boards must decide where artificial intelligence may be used, which applications require prior approval, what level of independent validation is necessary and when automated decisions must be subject to human review. Properly governed cybersecurity, digital systems and artificial intelligence can improve service reliability, operational efficiency, customer confidence, decision quality and product performance. Poorly governed use can create financial loss, regulatory action, litigation, reputational damage and strategic dependence on systems that directors do not sufficiently understand.
Target Audience
- Board Chairpersons and Deputy Chairpersons
- Executive and Non-Executive Directors
- Independent Directors
- Members of Board Risk, Audit, Technology, Digital, Compliance and Strategy Committees
- Company Secretaries and Board Governance Advisers
- Chief Executive Officers and Managing Directors
- Deputy Managing Directors and Executive Directors
- Chief Operating Officers
- Chief Financial Officers
- Chief Strategy Officers
- Business and Subsidiary Chief Executives
- Chief Risk Officers
- Chief Information Security Officers
- Chief Compliance Officers
- Chief Audit Executives
- Chief Information Officers
- Chief Technology Officers
- Chief Digital Officers
- Chief Data Officers
- Leaders responsible for critical business services and technology-dependent operations
Learning Outcomes
At the end of the programme, participants will be able to:
- Exercise informed board oversight of cybersecurity, digital risk and artificial intelligence through defined governance structures, decision rights, risk limits and management accountability.
- Evaluate cyber and technology exposures using business-service criticality, financial impact analysis, attack-path assessment, control effectiveness testing and recovery capability evidence.
- Govern artificial intelligence systems throughout their life cycle, including approval, data use, model validation, deployment, human intervention, performance monitoring and retirement.
- Direct technology investment and risk treatment decisions in a manner that protects enterprise value while supporting reliable operations, customer confidence, innovation and competitive performance.
Learning Objectives
The programme will enable participants to:
- Examine the legal, fiduciary and governance responsibilities of boards for cybersecurity incidents, technology failure, data misuse and automated decision-making.
- Establish board-approved cyber, digital and artificial intelligence risk appetite statements supported by thresholds, key risk indicators and escalation procedures.
- Assess management’s cybersecurity and digital risk reports using financial exposure, system dependency, control performance and recovery-readiness measures.
- Design governance arrangements for artificial intelligence covering model classification, validation, explainability, privacy, security, ethical use and human accountability.
- Apply board-level scenario analysis, incident simulation, independent assurance and post-incident review to strengthen oversight and strategic decision-making.
Programme Focused Areas
Board Duties, Decision Rights and Accountability for Cybersecurity
- Fiduciary responsibilities arising from cyber and technology risk
- Allocation of responsibilities among the full board, board committees and executive management
- Board approval authorities for cyber risk acceptance and control exceptions
- Personal accountability of directors and senior officers following material technology failures
- Governance boundaries between oversight, management and technical execution
- Board competence requirements and the use of independent technical advisers
- Documentation of challenge, deliberation, dissent and decisions in board records
- Integration of cybersecurity into strategy, audit, risk, investment and performance discussions
Cyber Risk Appetite, Tolerance and Financial Exposure Measurement
- Translation of cyber risk into financial, operational, legal and strategic consequences
- Development of cyber risk appetite statements linked to critical business services
- Establishment of loss limits, downtime limits, data-loss thresholds and recovery tolerances
- Cyber value-at-risk, annualised loss expectancy and scenario-based loss estimation
- Quantification of direct costs, secondary losses and long-duration consequences
- Assessment of capital, liquidity, revenue and insurance implications
- Determination of risk acceptance authority by exposure level
- Connection between cyber risk appetite, investment priorities and executive remuneration
Enterprise Technology Dependency and Critical Service Mapping
- Identification of important business services and maximum tolerable disruption periods
- Mapping of applications, databases, networks, identities, suppliers and personnel dependencies
- Detection of single points of failure and hidden technology concentration
- Assessment of legacy systems, unsupported software and accumulated technology debt
- Evaluation of data flows across business units, jurisdictions and service providers
- Identification of privileged-access pathways and high-impact compromise points
- Classification of systems by confidentiality, integrity, availability and business importance
- Board use of dependency maps in investment, outsourcing and recovery decisions
- Case Study: Board Investigation of a Material Cyber Exposure Hidden within a Strategic Expansion
Board Evaluation of Cybersecurity Control Architecture
- Governance assessment of identity and access management
- Privileged-access management and segregation of administrative authority
- Multi-factor authentication coverage and exception governance
- Network segmentation and containment of lateral movement
- Endpoint detection, security monitoring and threat intelligence
- Encryption, key management and protection of sensitive information
- Secure configuration, patch management and vulnerability remediation
- Board interpretation of penetration tests, control assessments and security ratings
Third-Party, Cloud, Software Supply-Chain and Concentration Risk
- Risk classification of technology vendors and outsourced service providers
- Board approval criteria for critical outsourcing and cloud adoption
- Due diligence covering ownership, security capability, subcontractors and financial condition
- Contractual requirements for audit rights, incident notification and data return
- Software supply-chain exposure and dependency on open-source components
- Cloud shared-responsibility arrangements and control ownership
- Concentration risk across providers, regions, platforms and network connections
- Exit planning, service portability, data migration and supplier failure scenarios
Cyber Incident Governance, Crisis Command and Recovery Assurance
- Board and executive roles during major cyber incidents
- Criteria for declaring a crisis and activating command structures
- Incident severity classification and escalation to directors
- Decision-making under incomplete, conflicting or unreliable information
- Regulatory notification, customer communication and legal privilege
- Ransomware governance, restoration priorities and payment decision protocols
- Recovery Time Objectives, Recovery Point Objectives and restoration sequencing
- Independent testing of backups, crisis plans and technology recovery arrangements
- Case Study: Ransomware, Cloud Failure and Conflicting Executive Advice
Board Governance Framework for Artificial Intelligence (AI)
- Definition of artificial intelligence governance within the organisation
- Classification of AI systems by use, consequence and decision authority
- Board approval requirements for high-impact and externally facing applications
- Governance of generative, predictive, autonomous and embedded AI systems
- Establishment of prohibited, restricted and permitted AI use cases
- Management accountability for AI ownership, validation and monitoring
- Human oversight and intervention requirements
- Integration of AI governance with risk, compliance, audit, technology and strategy structures
Artificial Intelligence Model Risk, Validation and Performance Assurance
- Model inventory, ownership and system-of-record requirements
- Assessment of training data, data lineage and data suitability
- Independent model validation and challenge procedures
- Accuracy, stability, robustness and sensitivity testing
- Bias, discrimination and fairness assessment
- Explainability requirements for material automated decisions
- Model drift, performance deterioration and threshold breaches
- Override controls, fallback arrangements, suspension and model retirement
AI Security, Privacy, Intellectual Property and Regulatory Exposure
- Adversarial attacks, prompt manipulation and data poisoning
- Leakage of confidential information through AI tools
- Unauthorised use of corporate data in external AI platforms
- Protection of models, training data, source code and system instructions
- Privacy implications of automated profiling and decision-making
- Copyright, licensing and intellectual property ownership
- Deepfakes, impersonation and AI-assisted fraud
- Governance of AI vendors, foundation models and external data sources
- Case Study: Failure of an AI-Driven Credit and Customer Decision System
Cybersecurity and Artificial Intelligence Assurance for Boards
- Design of the board’s technology assurance framework
- Coordination of first-line controls, risk oversight and internal audit
- Independence and competence of cybersecurity and AI assurance providers
- Scoping of internal audit reviews for cyber, cloud, data and AI
- Use of penetration testing, red teaming and control effectiveness assessments
- Validation of management’s closure of audit and regulatory findings
- Assurance over board-reported metrics and risk classifications
- Board commissioning of special reviews following major control failures
Board Reporting, Metrics, Indicators and Escalation Thresholds
- Distinction between activity measures, control measures and risk measures
- Construction of board-level cyber and digital risk dashboards
- Key Risk Indicators and Key Control Indicators
- Measurement of privileged-access exposure and critical vulnerability ageing
- Tracking of incident frequency, severity, containment and recovery performance
- Measurement of third-party exposure and concentration
- AI model performance, bias, override, drift and exception reporting
- Use of thresholds, trend analysis and mandatory escalation triggers
Technology Investment, Strategic Advantage and Board Action Planning
- Evaluation of cyber and AI investment proposals
- Comparison of risk-reduction benefits against cost and implementation exposure
- Prioritisation of expenditure using critical service and loss analysis
- Governance of technology modernisation and legacy-system replacement
- Assessment of acquisition, partnership and outsourcing opportunities
- Use of secure technology and governed AI to improve customer confidence
- Linking technology capability to product quality, operating efficiency and market position
- Development of a board-approved cybersecurity, digital risk and AI governance action plan
- Case Study: Board Allocation of Capital across Cybersecurity, AI and Business Expansion
Executive Experiential Tour