Connect with us

E-Business

Delegate Responsibility not Accountability- Keele

Published

on

Kindly share this post

Allen Keele is a certified fraud examiner, information security manager, information systems auditor and information systems security professional, among 20 other professional and technical accreditations. He shares over 17 years of experience in information security and risk management, including nine years of conducting professional advanced business lectures and seminars across the globe. Keele spoke to hilary okeke on a range of issues.

Training on Fraud Detection and Management
In information security, one of the most important things we have is not always having information security itself but having the internal control to be sure that we have information security. I wrote the text that most people use to prepare for Certified Information Systems Auditors (CISA) exams around the world. In that context, a lot of the controls that the internal auditors monitor have to do with controlling internal breaches and abuse. So, it would make logical sense to extend my auditors knowledge and expertise and interest into internal fraud detection and management. I was shocked to find in my younger days that 90 percent of frauds can be detected through the books. So many organizations tell you that they have no fraud problem but when you take a careful look, you find that there actually is a problem. People device all kinds of means to get money out their organizations without doing anything on the book. That was very concerning to me as an auditor. Fraud in itself is a disaster for an organization. It could lead to loss of market share if made public. Organizations need to be prepared for that kind of disaster just the same way they prepare for fire. So that is why we extended our training to business continuity, disaster recovery, as well as a new perspective on fraud. There are lots of folks out there who offer training on business continuity and disaster recovery, but what we are doing that is unique in the market is that we are not trying to project our best practices; we are teaching according to the new British standard – BS 25999. It is a new international standard designed to keep your business going during the most challenging and unexpected circumstances. It provides a basis for understanding, developing, implementing and managing business continuity within your organization and gives you confidence when dealing with stakeholders both within and outside your organization. BS 25999 has been developed by a group of experts representing a cross-section of industry sectors and governmental organizations which is reflected in its applicability. The standard is suitable for any organization, large or small, from any sector. It is particularly relevant for those that operate in a high risk environment such as the finance, telecommunications, transport, utilities and public sectors, where there is need for continuity. I have had a lot of organizations tell me they went for training a couple of years ago – the British standard may have existed a couple of years ago for training, but it just got ratified recently. There was no standard prior to BS 25999. So, this is a whole new world in terms of getting the certification to prove that your organization has the ability to manage fraud and disaster. Often times, organizations do things because regulators make them. Now more than ever, you have financial regulators requiring you to prove that you have strong control against fraud but you do not even have a fraud policy.
Best Security Strategy for an Organization
The best security strategy is first, to have one. Whether it is fraud, business continuity or information security; organizations have this odd tendency to casually appoint people within the organization to handle those areas. They point to the IT or compliance person – somebody who does not understand that area, and that person has to go and figure out what controls to put in place to get things working. So the problem is that currently, there is no strategy. Nobody has stopped to think “we need to be at 95 percent for fraud capacity at all times, no matter what.” They leave it up to the discretion of people who are not actually accountable for the business. That is wrong! Maybe you have an inexpensive web server that manages your brand new e-commerce that supports 90 percent of your business but because it was not expensive, your IT manager complains that it goes down all the time and that he is going to have it replaced in two weeks. Two weeks for e-commerce? That is why we said that the most important strategy is to have one. It is not just my idea, it is ISO 27001 standard for information security, which instructs that you get a strategy in place. I have always recommended that organizations should first have the right people that are actually accountable for that decision and have them make the decisions for a change. You can delegate responsibility but you cannot delegate accountability.
Networking and Telecommunication in Auditing, Internal Control
ICT has a very important role to play in internal control because auditors control access to information which IT does too. Auditors also control how information is used and how transactions are processed. Over the years, automated control organizes business functions and that has reduced loss of money. So, IT is able to put controls in place but then again, depending on how well it is managed, there might also be some vulnerability. In detecting and managing fraud, you need asset combination. I have often asked people in my classes if their organizations are committed to preventing, detecting and minimizing fraud. And they say yes, absolutely! I ask them to show me a policy that says: “Our organization does not want fraud, and this is what we are going to do to stop it.” They have no fraud policy! Shockingly, a policy is nothing more than a statement of management that states the way things are done within an organization. If you say that controlling fraud is a good objective, where is the policy that not only says it is wrong but also says here is who should be looking for it; here is who should be investigating it and here is what we do if we find it. A fraud policy is where senior managers say “not only am I going to accept responsibility, but I will accept accountability for something going wrong.”
Legal and Ethical Issues Facing IT Auditors
The legal and ethical issues are similar for IT auditors as they are for financial auditors. As an IT auditor, it is possible that you would be dealing with irregular or illegal acts. Towards that end, you have to be careful whom you release information to – there is always tendency for you to be exposed to sensitive information about an organization that you have to protect. As you are investigating issues, you have to be sure that you do not breach privacy laws. For instance, there are laws now that protect account information for people who have bank accounts. Imagine if during the course of an IT audit, the auditor compromised your account, and your account number and access code was made public. That auditor could be in for a lot of legal hassle.

 

 


Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

E-Business

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

Published

on

Kindly share this post

National Information Technology Development Agency (NITDA) has introduced so-called Nigeria’s Certified Cloud Register, regulatory framework developed under the agency’s National Sovereign Cloud Initiative to determine which cloud providers are authorized to handle sensitive data, such as banking records.

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

In effect, from October, NITDA requires banks, fintech companies and other regulated organisations to source cloud infrastructure providers from a national register of certified firms approved to host sensitive financial and government data.

The Certified Cloud Register, is expected to strengthen data sovereignty, improve regulatory oversight and support the implementation of the Central Bank of Nigeria’s (CBN) data localisation policy, which takes effect on January 1, 2027.

Under the framework, banks, fintechs, government institutions and other regulated entities will be able to verify whether cloud service providers, data centre operators, managed service providers and Artificial Intelligence (AI) infrastructure companies have met NITDA’s certification requirements before entrusting them with critical digital workloads.

The initiative is expected to provide regulated institutions with a standardised process for selecting cloud infrastructure providers that satisfy Nigeria’s technical, security and regulatory requirements.

Advertisement

According to NITDA, the framework establishes “a common national standard, an independent assessment process and a public register of approved providers that banks, fintechs and government institutions can rely on when selecting cloud infrastructure partners.”

The register is expected to become a key compliance tool ahead of the CBN’s directive, which requires all payment transaction data generated within Nigeria to be stored and processed locally, effective from January 1, 2027.

The policy applies to deposit money banks, microfinance banks, mobile money operators, payment service providers, switching companies and other financial institutions.

The certification regime is also expected to reshape Nigeria’s cloud computing ecosystem, making regulatory approval a major requirement for cloud providers seeking to handle sensitive data for regulated industries.

Figures cited by NITDA showed that Nigeria’s 10 largest banks spent about N177.91 billion on information technology in the first quarter of 2026, representing a 31 per cent increase over the corresponding period last year.

Advertisement

A sizeable portion of the investment currently supports cloud infrastructure hosted outside Nigeria, a trend the new certification framework is expected to address by encouraging greater utilisation of compliant local infrastructure.

NITDA said the certification programme will apply the same technical and regulatory standards to indigenous cloud providers and international hyperscale operators, creating a level playing field for all companies seeking to provide cloud services to regulated sectors.

The agency also disclosed that more than 85 per cent of Nigerian businesses currently rely on cloud services, with the majority using infrastructure hosted outside the country.

It said the new framework is aimed at improving confidence in Nigeria’s digital infrastructure while promoting local capacity and enhancing oversight of critical national data.

Speaking on the objective of the initiative, Kashifu Inuwa Abdullahi, director-general of NITDA, said the programme is designed to strengthen Nigeria’s position in the global digital economy rather than exclude foreign technology companies.

Advertisement

According to him, the initiative is intended “to redefine the terms under which Nigeria participates in the global digital economy rather than isolate the country from international technology providers.”

The Certified Cloud Register forms part of broader efforts by the Federal Government to deepen digital trust, strengthen cybersecurity and ensure that critical financial and public sector data are managed in line with Nigeria’s evolving data governance and sovereignty objectives.

Kindly share this post
Continue Reading

E-Business

Firm Advocates Healthy IT Habits to Strengthen Cyber Resilience

Published

on

Kindly share this post

At the recent Cyber Security Weekend 2026 conference, Kaspersky shared the findings from its survey titled “Cybersecurity in the workplace: Employee knowledge and behaviour” which was conducted among employees from the Middle East, Turkiye and Africa (META) region.

The study highlights that everyday IT habits, including decluttering computers and reducing digital fatigue, can have a direct and often underestimated impact on an organisation’s cyber resilience.

The Kaspersky survey points to a growing challenge of digital fatigue in the workplace. 13.5% of employees surveyed in the META region confirmed that they made IT-related mistakes due to a lack of cybersecurity knowledge – a figure that shows the critical importance of continuous cybersecurity training and awareness programmes.

Among other reasons behind IT mistakes, respondents cited being in a hurry (30%), oversight (14%), being tired or stressed (12.9%) and having too many notifications (10%). The constant barrage of alerts, messages, and on-screen clutter is becoming an acute problem that can lead to costly IT errors, overlooked social engineering attacks, and even to cyber breaches.

The survey also examined employees’ digital workspace habits. An overwhelming 44.5% of respondents in the META region reported having between 10 and 20 icons on their desktop, while 30% admitted to having even more – with half to a full screen covered in them.

Advertisement

Meanwhile, 33% of respondents also keep more than 10 tabs open in their browser at any given time. Excessive icons and open tabs do more than distract attention and fuel procrastination – they can slow device performance and, in the case of unused applications, quietly collect data.

Interestingly, most employees regularly disinfect their keyboards and phone surfaces (21.5% have adopted this habit since the COVID pandemic). However, digital cleanliness has not kept pace: 55% of respondents remove needless files once a month or more often; the rest perform digital clean-ups far less frequently – once a quarter, or even once a year.

Managing digital noise is key to staying alert: only essential notifications should remain active, especially during periods of deep focus on critical project deliverables. Regular breaks are just as vital for maintaining both well-being and cyber vigilance.

According to the survey, 78% of respondents spend their work breaks eating or drinking, while 58% chat with friends and colleagues. However, stretching and physical exercise is a more effective way to relieve stress and recharge focus – a habit adopted by only 14% of employees.

“It is important to recognise that digital fatigue is a real and growing stress factor: the constant stream of notifications, cluttered screens, and information overload gradually erode focus and make employees far more susceptible to mistakes and social engineering attacks. Simplifying your digital environment is not just a productivity tip, it is a cybersecurity measure”, says Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

Trending