Abstract
The rapid expansion of financial technology (Fintech) in Nigeria has intensified the need for advanced cybersecurity risk management. Traditional risk assessment methods in the sector rely on qualitative labels such as High or Low, which are subjective and fail to show explicit monetary exposure. To address this gap, this study developed a localized Quantitative Cyber Risk Assessment Framework to measure and prioritize cyber threats in financial terms for Nigerian fintech organizations. Adopting a design science and quantitative research approach, a web based Decision Support System (DSS) was engineered using Next.js and TypeScript. The risk engine operationalized Single Loss Expectancy (SLE), Annualized Loss Expectancy (ALE), and Return on Security Investment (ROSI), calibrated with NIBSS and FITC fraud data, applying a verified 2.1% fraud to transaction ratio as the Exposure Factor. A controlled simulation of a hypothetical fintech organization showed an unmitigated Annualized Loss Expectancy of ₦390,600,000, reduced to ₦58,590,000 after applying anti-phishing controls costing ₦50,000,000, yielding a Return on Security Investment of 564.02%. The study concluded that localized quantitative frameworks replace subjective judgment with actionable financial intelligence, optimizing cybersecurity planning, budgeting, and regulatory compliance in the Nigerian fintech sector.
Keywords: Cyber Risk Quantification, Annualized Loss Expectancy, Fintech Cybersecurity, Decision Support System, Nigeria.
Authors:
Adejumo Modupe Anthonia
Corresponding Author Email: annieade01@gmail.com
Fatimah Adamu-Fika
fateemahfika@gmail.com
Abdulrahman Tunde Alabelewe
abdulrahman.alabelewe@gmail.com
Samson Adeyinka
Samson.adeyinka@afit.edu.ng
Dauda Sule
daudas@gmail.com
Renshaw Onah Benjamin
renshawbenjamin4@gmail.com