Three-time Chief Information Security Officer and Data Protection Officer with 16+ years across Nigerian banking, capital markets, payments, and fintech. Founder of AegisIntel Advisory. Publisher of Sovereign Signal.
Across banking, capital markets, payments, and fintech in Nigeria.
Three separate institutions. Three different regulatory stacks.
GTBank, NSE, Interswitch, Smartcash, FSDH, AltBank and beyond.
CISSP, CCSP, C|CISO, CISA, CDPO, ISO 27001 LA, ISO 31000 LRM.
CISO and DPO at a CBN-licensed non-interest digital bank, reporting to the MD/CEO with board-level reporting to the BRMC and MRC. Responsible for the full cybersecurity and data protection governance stack — security strategy, NDPA compliance, CBS security, vendor risk, and regulatory examinations.
Founded and built AegisIntel Advisory, a vCISO and data protection firm serving Nigerian financial institutions and Canadian regulated entities. Developed BaitCheck (phishing simulation SaaS) and the Aegis Exposure Engine (FAIR-based cyber loss quantification) as practitioner-built products.
CISO at one of Nigeria's CBN-licensed Payment Service Banks within the Airtel Africa group structure, building the security function from the ground up and establishing security governance for a mobile money operation at scale.
Led information security governance at a CBN-licensed merchant bank, covering risk management, regulatory compliance, and the bank's information security strategy and posture across treasury, corporate banking, and capital markets operations.
Managed information security at the Nigerian capital markets infrastructure operator, covering market data systems, trading platforms, and SEC/NSE regulatory requirements for the exchange's technology estate.
Security operations and risk management at Nigeria's leading payment infrastructure company, covering the Verve card scheme, Quickteller, and the interbank switching network serving the Nigerian financial system.
Early career at one of Nigeria's Tier-1 banks, building foundational experience in IT audit, access management, and information security operations across retail and corporate banking platforms.
Board-level security and data protection governance, reporting to the MD/CEO with BRMC and MRC reporting lines. Full CISO and DPO mandate across cybersecurity, NDPA compliance, and CBS security.
Fractional vCISO, NDPA/NDPC compliance, and cyber risk quantification for Nigerian FIs and fintechs. Canadian practice serves OSFI-regulated institutions under the Sovereign Bridge methodology.
Regular speaker at cybersecurity, data protection, and financial services conferences. Topics span NDPA compliance, cyber risk quantification, CISO leadership, and the intersection of regulation and digital finance across Africa and Canada.
Publishes Sovereign Signal, a practitioner newsletter on cybersecurity governance, data protection law, and digital finance across Nigeria, Africa, and Canada. Written for practitioners, regulators, and executives navigating the intersection of risk and regulation.
A vCISO and data protection advisory firm serving Nigerian financial institutions and CBN-regulated entities. Services span fractional CISO leadership, NDPA/NDPC compliance, and cyber risk governance. A separate Canadian practice serves OSFI-regulated institutions under the Sovereign Bridge methodology.
aegisintel.com.ng →A GoPhish-based phishing simulation and security awareness platform purpose-built for Nigerian financial institutions. Delivers campaign management, staff awareness tracking, and CBN-aligned reporting — without the international pricing of generic tools. AI-generated awareness content included.
baitcheck.ng →A FAIR-based Monte Carlo cyber loss quantification framework translating security posture into board-ready loss scenarios — denominated in Naira or CAD, mapped to business lines, and structured for BRMC or OSFI examination consumption. Built from practitioner engagements, not theoretical frameworks.
exposure.aegisintel.com.ng →A Substack newsletter covering cybersecurity governance, data protection law, and digital finance across Nigeria, Africa, and Canada. Written for practitioners, regulators, and executives navigating the intersection of risk and regulation. Not vendor content — practitioner analysis.
olulekeolatunji.substack.com →Published on Substack. Covers cyber risk governance, data protection regulation, and digital finance — with a practitioner's eye on what actually matters for regulated institutions in Nigeria and Canada. Not vendor content. Not recycled frameworks. Honest analysis from someone doing the work.
Read on Substack →Cyber risk quantification — why heat maps fail boards and what FAIR-based modelling gives you instead.
NDPA in practice — what the Nigeria Data Protection Act means for fintechs, banks, and operators going through NDPC registration.
OSFI's evolving cyber expectations — how B-13 is reshaping what boards need to know and how CISOs need to report.
Phishing economics — the real cost of a compromised credential in a Nigerian financial institution, and what simulation data actually shows.
For advisory engagements, speaking invitations, research collaboration, or media enquiries — reach out directly. I read and respond to every message personally.