BoG Unveils Major Cybersecurity Overhaul for Banks and Fintechs

The Bank of Ghana (BoG) is preparing to introduce a tougher cybersecurity framework for banks and fintech companies as digital payments continue to expand and attract more sophisticated cyber threats.
The central bank plans to issue a revised Cyber and Information Security Directive early next year. The updated rules will tighten governance, strengthen reporting obligations and expand the Bank’s sector-wide monitoring systems.
Rising threats as digital payments surge
Speaking at the Payments Industry Cybersecurity Summit on behalf of Governor Dr Johnson Pandit Asiama, Mr Daniel S. Klu, Acting Head of Information Security, warned that cyber risks are growing as fast as Africa’s digital finance revolution.
“The very innovations powering this revolution also introduce heightened security risks,” he said, referencing instant payment systems, cloud infrastructure and emerging AI tools.
Mr Klu noted that digital transactions have become central to Ghana’s economy, but the increased dependence on technology has also amplified the risk of broad, system-wide disruptions.
He added that the Bank intends to “champion data protection and consumer safety” while ensuring that regulation does not suffocate innovation in financial services.
CISOs to get more power
A major shift in the upcoming directive is the elevated role of Chief Information Security Officers (CISOs).
The draft proposes giving CISOs more authority in strategic decision-making to strengthen cybersecurity oversight within institutions.
The BoG already requires all regulated institutions to appoint dedicated cybersecurity officers and report incidents within strict timelines, but the new rules are expected to tighten compliance even further.
FICSOC expansion to deepen real-time monitoring
The reforms will also scale up the Financial Industry Command Security Operations Centre (FICSOC) — a 24-hour monitoring hub created in 2019. Initially built to monitor universal banks, FICSOC now covers all regulated financial institutions and fintechs.
Mr Klu described the centre as the “nerve-centre” of industry-wide cybersecurity, noting that commercial banks, savings and loans companies and some regulators are already connected.
The BoG plans to extend connectivity to more supervisory bodies, enabling faster detection of anomalies and better coordination during cyber incidents.
Banks urged to adopt global security standards
The central bank is also encouraging institutions to adopt internationally recognised frameworks such as ISO 27001 and NIST standards to strengthen their cyber maturity.
Mr Klu said the ultimate goal is to build “collective resilience,” stressing that the financial sector is only as secure as its weakest player. He urged institutions to invest in strong governance systems, customer verification tools and fraud prevention technologies.
Cyber risks, he said, are now a daily reality:
“We must try to be visionary, stay 10 or even 100 steps ahead of malicious actors.”
Visa backs BoG with call for deeper collaboration
Visa, which co-hosted the summit, echoed the need for enhanced cooperation across the sector.
Fabrice Konan, Visa’s Country Manager for Ghana, said cybersecurity underpins the growth and trust in digital payments across Africa.
“Cybersecurity is not a technical issue. It’s a matter of national interest,” he said.
Mr Konan urged banks and fintechs to share intelligence more freely, adopt coordinated defences and strengthen Ghana’s preparedness for evolving cyber threats.
He added: “Together we can make Ghana’s payment ecosystem secure, resilient and ready for the future.”



