Cyber Path Insight
Operational governance · Nigeria

Enterprise-grade governance, built for organisations of 20 to 250

Understand your NDPA duties, meet the requirements that apply to your sector, certify where customers require it — and run the operating cycle yourself. The programme, platform and delivery method are adapted to the Nigerian context.

Where it starts

Most people arrive here because a regulator or a customer set a date

“Our audit return is due.”

You have been classified a controller or processor of major importance, and the annual filing window is open.

NDPA & NDPC filing →

“Our sector regulator set a deadline.”

Your organisation has sector-specific requirements and needs accountable owners, evidence and a workable delivery plan.

Discuss the requirement →

“They want to know how we govern AI.”

A customer, an investor or a regulator has started asking, and the rules are still being written.

AI governance →

“Our customer requires ISO 27001.”

A contract renewal or a new enterprise account — often a foreign one — with a date attached.

ISO 27001 →

Regulatory position

What actually applies to you, and what doesn’t yet

Nigerian governance advice is full of instruments quoted as law before they are law. Here is the position as we hold it, with each item’s status stated plainly. We update this when it changes, including when a date moves backwards.

Nigeria Data Protection Act 2023 and GAID 2025

The Act is the primary statute. GAID provides the current implementation rules, including registration, audit-return and DPO requirements.

In force

Major-importance classification

Classification determines registration, annual renewal and Compliance Audit Return duties. GAID requires UHL and EHL returns to be filed through a licensed DPCO unless the Commission approves otherwise.

Annual cycle

Data Protection Compliance Organisation licensing

Section 33 provides for organisations licensed by the NDPC to train, audit, consult and render compliance services. A .ng website is one of the NDPC’s published licensing requirements.

Licence required

ISO/IEC 27001 · ISO/IEC 42001

Voluntary. Driven by customers, investors and foreign counterparties rather than by a Nigerian regulator — which is exactly why the deadline is usually someone else’s.

Customer-driven

Source check · 12 August 2026 · Nigeria Data Protection Commission

Read the NDP Act and GAID →

How we work

Three things most firms here won’t tell you

You’ll know the scope and the gates.

The programme is staged against evidence and decision gates. Third-party fees, including certification-body and regulator charges where applicable, are identified separately in the written proposal.

Request a written scope →

Everyone can be in the system.

In an organisation where the risk owner sits in Lagos, the auditor in Abuja and the board somewhere else entirely, per-seat licensing quietly decides who is allowed to be accountable. Every risk owner, control owner and action owner gets an account. Unlimited internal users on every plan, priced by organisation size.

See platform pricing →

You’ll run it. Not us.

The engagement completes when you have run a full governed cycle with nobody from Cyber Path Insight in an accountable role. A certificate you can’t maintain is a liability with a logo on it — and a retainer that never ends is a business model, not an outcome.

How we work →

The governance system of record

AccordaGRC

Risk, controls, compliance, evidence, audit and resilience in one operating environment — the same platform, not a regional edition of it.

  • Risk
  • Controls
  • Compliance
  • Policy register & attestation
  • Evidence
  • Incidents
  • Internal audit
  • Operational resilience
  • Data privacy
  • Supplier register & risk
  • Executive reporting

Nigeria obligations library

NDPA and GAID obligations mapped to the control set so filing evidence becomes part of the operating record. This locale-specific library is being prepared and has no published release date.

Regulatory standing

Where we stand, in writing

You are about to be told by several firms that they are accredited, licensed and approved. Ask each of them for the register entry. Here is ours, including the parts that aren’t finished.

  • Licence to audit under section 33 — not yet held Cyber Path Insight Limited does not appear on the NDPC’s licensed-DPCO register. We do not represent the company as licensed or file UHL/EHL returns as a DPCO. Status checked 12 August 2026.
  • We do not yet claim to run ourselves on AccordaGRC in Nigeria It is our intention, but it is not true today, so it is not presented here as a proof point.
  • No NDPC accreditation is claimed for Academy credentials The AssuranceLoop Foundation pathway is available now. Any Nigerian regulatory alignment will be stated only after the relevant approval or accreditation exists.

Check the NDPC register →

Trust and evidence

Why you should believe any of this

Method, not headcount

The same standard, delivered locally

The instruments, the maturity method and the gate criteria are the firm’s, developed in the United Kingdom and applied without dilution here. What changes is the obligation set and the price, not the bar.

How we work →

Platform ecosystem

Seven platforms, described plainly

Every platform in the ecosystem is described by what it does today. A roadmap is never presented as delivered software.

See the platform ecosystem →

Evidence policy

No imported client credibility

UK client marks are not used to imply Nigerian delivery. Nigerian names and marks appear only with written publication permission.

Company evidence

Cyber Path Insight Limited is incorporated in Nigeria

The incorporation record supports the local legal name and registration number shown in the footer. The certificate and tax identifier are not published here.

Founder

Who you’ll actually be working with

Roy Biakpara, founder of Cyber Path Insight

Most governance work I saw arrived as a set of documents. Policies written, registers populated, a certificate on the wall — and eighteen months later, nobody running any of it. The consultants had gone, and what they left behind had decayed the day they walked out.

That isn’t governance. It’s evidence of a project. Governance is an operating capability: the repeatable, evidenced ability to make and execute good decisions about risk, security, data and AI. Compliance is what falls out of doing that well — never the objective.

Nigeria is at the point where that distinction starts to cost money. The instruments are real, the enforcement is arriving, and the market’s instinct is to buy the artefact and file it. We opened here to sell the capability instead — on the same terms, against the same gate, with the same commitment that the engagement completes when you can run it without us.

Roy BiakparaFounder, Cyber Path Insight

Commercial terms

How we propose work here

Nigeria-specific prices and tax treatment are not yet published. Until they are, the written proposal is the commercial source of truth.

Currency stated before commitment

Domestic proposals state the applicable currency. Foreign certification-body or parent-company charges are separated rather than hidden in an exchange-rate assumption.

Milestones defined in writing

Each proposal identifies the evidence or decision that completes a stage, along with the payment terms that apply.

Platform licensing stays separate

AccordaGRC licensing follows its published commercial model. Consultancy and regulatory third-party fees remain distinct.

Contracted through the Nigerian entity

Cyber Path Insight Limited is the incorporated Nigerian company. The signed proposal identifies the contracting and invoicing entity.

Request a written proposal →

Governance technology

Seven platforms, one governance model

AccordaGRC is where most organisations start. As governance widens, these connect to it rather than sitting beside it.

AccordaGRC

Governance system of record

AssuranceLoop

Operational AI governance

TrustBeam

Third-party assurance

Trust Resource Centre

Inbound assurance

PoliGuard

Policy lifecycle

PassPoint CE+

Cyber Essentials

ThreatScope

Regulatory intelligence

Further services

As the ecosystem grows

Academy and partners

Cyber Path Insight Academy

Certification transfers a system. The Academy transfers the competence to run it.

The AssuranceLoop Foundation pathway is available now. Advanced pathways are introduced as their content and assessment routes become ready. No NDPC accreditation is claimed.

Explore the Academy →

Partners

Your clients keep asking about compliance

For law firms, audit practices and managed service providers whose clients have filing dates and no one to run the work. If you’d rather refer it than turn it down, there’s a programme for that — and the arithmetic is published, not gated behind a form.

See the partner programme →

Next step

Start where you are

Don’t know where you stand?

Eighteen questions across nine governance domains, with a scored position and the areas that need attention first. This is a general readiness check, not legal advice.

Know what you need?

Book a 30-minute scoping call. We’ll tell you whether your date is realistic before you commit to anything.

Book a scoping call →

Above 250 people, or multi-entity?

Scope varies enough that a price on a page would be misleading. Here’s how we scope it.

Talk to the practice →