Cybersecurity Threat Intelligence Framework for Financial Institutions in Nigeria: Leveraging Machine Learning and Data Analytics
Abstract
The rapid digitisation of financial services in Nigeria has substantially expanded the cyberattack surface confronting commercial banks, fintech operators, and payment service providers. Despite the Central Bank of Nigeria (CBN) Cybersecurity Framework (2022) mandating continuous threat monitoring, fewer than 43% of licensed financial institutions achieve full compliance (Adeleke & Abiodun, 2023). This study proposes and evaluates the Cybersecurity Threat Intelligence Framework for Nigerian Financial Institutions (CTIF-NG), a novel five-layer architecture that integrates supervised and unsupervised machine learning algorithms, big-data analytics pipelines, and sector- specific threat-indicator feeds derived from documented Nigerian financial cybersecurity threat taxonomies. The framework objective is to evaluate using a structured simulation dataset of 20,000 records across seven threat classes, constructed from published NSL-KDD and CICIDS-2017 statistical parameters (Tavallaee et al., 2009; Sharafaldin et al., 2018) and adapted to the Nigerian financial threat taxonomy (CBN, 2022; NIBSS, 2024). Real sklearn experiments yielded the following results for the proposed RF+GBM+MLP Soft-Vote Ensemble: detection accuracy of 99.30%, macro- precision of 98.42%, macro-recall of 98.18%, F1-score of 98.30%, MCC of 0.9896, and AUC-ROC of 0.9999 outperforming all seven baseline classifiers evaluated. APT class recall (95.0%) was the lowest, reflecting the stealthy, low-signal nature of advanced persistent threat TTPs. Operational scenario projections indicate CTIF-NG can reduce mean time-to-detect (MTTD) by 64.8% and mean time-to-respond (MTTR) by 71.3% relative to conventional SIEM-only baselines (IBM Security, 2024; Gartner, 2024). The framework is explicitly aligned with CBN (2022), NDPA (2023), ISO/IEC 27035- 2, and NIST SP 800-150 compliance requirements. Future work recommendations priorities include: institutional pilot deployment validation with real Nigerian bank SOC data; federated learning architectures enabling cross-institution intelligence sharing under NDPA governance; adversarial robustness evaluation against model evasion attacks; integration of XGBoost and deep learning (Bi- LSTM, Autoencoder) with the full imbalanced-learn SMOTE-ENN pipeline; and extension to Nigeria's growing cryptocurrency exchange sector (FATF, 2023).
