AegisIntel Advisory · Nigeria Practice · vCISO & Data Protection

Three CISO appointments.
One fractional engagement.

Oluleke Olatunji brings board-level security leadership, NDPA/NDPC compliance expertise, and quantitative risk judgment to Nigerian financial institutions, fintechs, and pre-launch platforms — on a fractional basis.

Practice
Statement

AegisIntel Advisory's Nigeria practice is led by a practitioner with 16+ years across banking, capital markets, payments, and fintech — including three separate CISO and DPO appointments. The work is regulated-sector-grade: built to hold up to CBN scrutiny, board review, and external audit. Enquiries are reviewed personally; there is no team intake process.

I.

Practice Areas

Four disciplines, one accountable advisor
Art. 01 — Leadership
Virtual CISO Services

Fractional security leadership for organisations that need board-level judgment without a full-time hire — informed by three separate CISO appointments across banking and fintech.

  • Security strategy & board/BRMC reporting
  • Risk register & vulnerability management design
  • Vendor and third-party risk oversight
  • Incident readiness & DFIR advisory
Art. 02 — Privacy
Data Protection & DPO Services

End-to-end privacy compliance for regulated and pre-launch platforms, from NDPC registration through operating policy.

  • NDPC DCPMI registration & filings
  • Consultant DPO appointment
  • Data protection policy & consent management design
  • Data protection impact assessments
Art. 03 — Compliance
Compliance Programme Build-Out

Structured, document-driven compliance suites mapped to the frameworks that actually govern the client's sector.

  • NDPA-aligned compliance documentation suites
  • ISO 27001 readiness & phased certification roadmaps
  • Gap analyses against CBN and sector guidelines
  • Tiered engagement from ₦300,000 — scope-matched
Art. 04 — Quantification
Cyber Risk & Loss Quantification

Turning security posture into figures a finance committee can act on, using recognised quantitative methods.

  • FAIR-based loss exposure modelling
  • Monte Carlo simulation of loss scenarios
  • Application & infrastructure security assessments
  • Board-ready risk narratives, not just heat maps
II.

Products

Built for Nigerian financial institutions
Security Awareness Platform
BaitCheck
Phishing simulation built for Nigerian banks.
Active MVP — Available for Pilots

BaitCheck is a GoPhish-based phishing simulation and security awareness platform purpose-built for Nigerian financial institutions. Generic tools price in USD and ignore the Nigerian threat landscape. BaitCheck doesn't — it delivers CBN-aligned campaign reporting, Naira-denominated engagement, and awareness content calibrated to the social engineering patterns actually used against Nigerian banks and fintechs.

  • Phishing simulation campaigns with Nigerian-context lures
  • Staff click-rate tracking and awareness scoring
  • CBN-ready security awareness reporting
  • AI-generated awareness videos and training content
  • Multi-institution dashboard for managed service delivery
Request a Pilot ↗
Cyber Risk Quantification Framework
Aegis Exposure Engine
Cyber risk, priced in Naira.
Available — Engagements Open

The Aegis Exposure Engine converts your institution's threat and control environment into quantified loss scenarios — denominated in Naira, mapped to business lines, and structured for BRMC and audit committee consumption. Built on FAIR methodology with Monte Carlo simulation, it gives risk officers and CFOs a common language for decisions that currently rely on gut feel and heat maps.

  • FAIR-based threat and control environment modelling
  • 10,000-trial Monte Carlo loss simulation per scenario
  • Naira-denominated loss exceedance curves
  • Board-ready narrative brief + audit committee methodology pack
  • Transferable Python model — you own it after engagement
Full Details ↗
III.

Selected Engagements

Client names withheld where confidentiality applies
File 001
Data protection compliance suite — pre-launch proptech platform

Led NDPC DCPMI registration and built a twelve-document data protection compliance suite as Lead Compliance Advisor and Consultant DPO, ahead of platform launch.

PrivacyDPO
File 002
DFIR counter-proposal — incident response engagement

Authored an incident response counter-proposal following a compromised-contributor-account incident, evaluating and refining an incumbent vendor's approach.

Incident Response
File 003
ISO 27001 certification roadmap — software development firm

Advised a Nigerian devshop through a phased programme toward ISO 27001 certification, sequencing controls implementation against business constraints.

ISO 27001
File 004
Quantitative cyber loss framework — reusable methodology

Built a FAIR-methodology loss quantification framework with a Python Monte Carlo simulation engine and FX-adjusted Naira exposure modelling, packaged as a reusable methodology.

Risk Quantification
IV.

Credentials

Certifications
CISSP CCSP C|CISO CISA CDPO ISO 27001 LA ISO 31000 LRM
Practice Record
16+
Years in practice
CISO appointments
8
Institutions served
Oluleke Olatunji

A three-time CISO and Data Protection Officer whose career spans banking, capital markets, payments, and fintech — including GTBank, the Nigerian Stock Exchange, Interswitch Group, and Smartcash PSB.

He serves as Research Committee Lead at CCISONFI, the Committee of CISOs of Nigerian Financial Institutions, and publishes Sovereign Signal, a newsletter on cybersecurity, data protection, and digital finance across Africa and Canada.

V.

Get in Touch

Start a conversation.

Whether it's a fractional CISO mandate, an NDPC registration, a BaitCheck pilot, or a compliance gap that needs an honest read — reach out directly. Responses within 24 hours.

For time-sensitive incident response requests, call directly rather than email.
Base
Lagos, Nigeria