Lagos, Nigeria · CISO · DPO · Founder

Oluleke Olatunji.
Cyber risk practitioner.

Three-time Chief Information Security Officer and Data Protection Officer with 16+ years across Nigerian banking, capital markets, payments, and fintech. Founder of AegisIntel Advisory. Publisher of Sovereign Signal.

CISSP CCSP C|CISO CISA CDPO ISO 27001 LA ISO 31000 LRM
16+
Years

Across banking, capital markets, payments, and fintech in Nigeria.

CISO Appointments

Three separate institutions. Three different regulatory stacks.

8
Institutions

GTBank, NSE, Interswitch, Smartcash, FSDH, AltBank and beyond.

7
Certifications

CISSP, CCSP, C|CISO, CISA, CDPO, ISO 27001 LA, ISO 31000 LRM.

16+ years across
Nigerian financial services.

2024 — Present
Current
Chief Information Security Officer & Data Protection Officer
Alternative Bank Limited (AltBank) · Lagos

CISO and DPO at a CBN-licensed non-interest digital bank, reporting to the MD/CEO with board-level reporting to the BRMC and MRC. Responsible for the full cybersecurity and data protection governance stack — security strategy, NDPA compliance, CBS security, vendor risk, and regulatory examinations.

2023 — Present
Current
Founder & Principal Advisor
AegisIntel Advisory · Lagos & Alberta

Founded and built AegisIntel Advisory, a vCISO and data protection firm serving Nigerian financial institutions and Canadian regulated entities. Developed BaitCheck (phishing simulation SaaS) and the Aegis Exposure Engine (FAIR-based cyber loss quantification) as practitioner-built products.

2022 — 2024
Chief Information Security Officer
Smartcash PSB (Airtel Africa) · Lagos

CISO at one of Nigeria's CBN-licensed Payment Service Banks within the Airtel Africa group structure, building the security function from the ground up and establishing security governance for a mobile money operation at scale.

2019 — 2022
Head, Information Security
FSDH Merchant Bank · Lagos

Led information security governance at a CBN-licensed merchant bank, covering risk management, regulatory compliance, and the bank's information security strategy and posture across treasury, corporate banking, and capital markets operations.

2016 — 2019
Information Security Manager
Nigerian Stock Exchange · Lagos

Managed information security at the Nigerian capital markets infrastructure operator, covering market data systems, trading platforms, and SEC/NSE regulatory requirements for the exchange's technology estate.

2012 — 2016
Information Security Analyst
Interswitch Group · Lagos

Security operations and risk management at Nigeria's leading payment infrastructure company, covering the Verve card scheme, Quickteller, and the interbank switching network serving the Nigerian financial system.

2008 — 2012
IT Security & Audit
Guaranty Trust Bank (GTBank) · Lagos

Early career at one of Nigeria's Tier-1 banks, building foundational experience in IT audit, access management, and information security operations across retail and corporate banking platforms.

Four active mandates,
simultaneously.

CISO & DPO
Alternative Bank Limited (AltBank)
CBN-licensed non-interest digital bank · Lagos

Board-level security and data protection governance, reporting to the MD/CEO with BRMC and MRC reporting lines. Full CISO and DPO mandate across cybersecurity, NDPA compliance, and CBS security.

Founder & Principal
AegisIntel Advisory
vCISO & Data Protection · Lagos & Alberta

Fractional vCISO, NDPA/NDPC compliance, and cyber risk quantification for Nigerian FIs and fintechs. Canadian practice serves OSFI-regulated institutions under the Sovereign Bridge methodology.

Conference Speaker
Cybersecurity & Data Protection
Nigeria & International · Ongoing

Regular speaker at cybersecurity, data protection, and financial services conferences. Topics span NDPA compliance, cyber risk quantification, CISO leadership, and the intersection of regulation and digital finance across Africa and Canada.

Publisher
Sovereign Signal
Substack · 4,300+ LinkedIn followers

Publishes Sovereign Signal, a practitioner newsletter on cybersecurity governance, data protection law, and digital finance across Nigeria, Africa, and Canada. Written for practitioners, regulators, and executives navigating the intersection of risk and regulation.

Built alongside
advisory practice.

// Advisory Firm
AegisIntel Advisory

A vCISO and data protection advisory firm serving Nigerian financial institutions and CBN-regulated entities. Services span fractional CISO leadership, NDPA/NDPC compliance, and cyber risk governance. A separate Canadian practice serves OSFI-regulated institutions under the Sovereign Bridge methodology.

aegisintel.com.ng →
// SaaS · Active MVP
BaitCheck

A GoPhish-based phishing simulation and security awareness platform purpose-built for Nigerian financial institutions. Delivers campaign management, staff awareness tracking, and CBN-aligned reporting — without the international pricing of generic tools. AI-generated awareness content included.

baitcheck.ng →
// Quantification Platform
Aegis Exposure Engine

A FAIR-based Monte Carlo cyber loss quantification framework translating security posture into board-ready loss scenarios — denominated in Naira or CAD, mapped to business lines, and structured for BRMC or OSFI examination consumption. Built from practitioner engagements, not theoretical frameworks.

exposure.aegisintel.com.ng →
// Newsletter
Sovereign Signal

A Substack newsletter covering cybersecurity governance, data protection law, and digital finance across Nigeria, Africa, and Canada. Written for practitioners, regulators, and executives navigating the intersection of risk and regulation. Not vendor content — practitioner analysis.

olulekeolatunji.substack.com →
Sovereign Signal —
the newsletter.

Published on Substack. Covers cyber risk governance, data protection regulation, and digital finance — with a practitioner's eye on what actually matters for regulated institutions in Nigeria and Canada. Not vendor content. Not recycled frameworks. Honest analysis from someone doing the work.

Read on Substack →
// Topic 01

Cyber risk quantification — why heat maps fail boards and what FAIR-based modelling gives you instead.

// Topic 02

NDPA in practice — what the Nigeria Data Protection Act means for fintechs, banks, and operators going through NDPC registration.

// Topic 03

OSFI's evolving cyber expectations — how B-13 is reshaping what boards need to know and how CISOs need to report.

// Topic 04

Phishing economics — the real cost of a compromised credential in a Nigerian financial institution, and what simulation data actually shows.

Let's talk.

For advisory engagements, speaking invitations, research collaboration, or media enquiries — reach out directly. I read and respond to every message personally.

For fractional CISO, NDPA compliance, or Exposure Engine engagements, visit aegisintel.com.ng for the full practice overview.