Olatunde Success shares lessons from leading a digital transformation proposal and technical audit for a Nigerian mortgage bank: the vulnerabilities that hide in plain sight and why transformation fails when it starts with apps instead of foundations.
When SAW Technologies prepared a digital transformation proposal for Cooperative Mortgage Bank, the first deliverable was not a roadmap or a mockup. It was a technical audit of what already existed. What we found reshaped how I think about digital transformation across the entire Nigerian banking sector.
The findings hiding in plain sight
The audit surfaced problems that no glossy transformation deck would ever mention: customer forms collecting sensitive data over insecure channels, an Android app distributed as an unsigned APK, and authentication flows that broke in ways an attacker could love. None of these required sophisticated tooling to find. They required someone technical actually looking, with permission to report what they saw.
Why transformation projects skip this step
Audits produce bad news, and bad news is hard to sell internally. A new app announcement is easier than a security remediation budget.
Vendors are incentivized to build new things, not to fix old ones. The audit is where honest vendors prove themselves.
Leadership often lacks a technical translator: someone who can turn an unsigned APK into a board-level risk statement.
Foundations before features
The sequence we proposed put remediation first: secure the data collection paths, sign and harden distribution, fix authentication, and only then build the new digital experience on top. In a bank, a beautiful app on a broken foundation is not progress. It is a bigger attack surface with better marketing. NDPA 2023 sharpens this further, because every vulnerability in a data collection path is now a regulatory exposure, not just a technical one.
Digital transformation that starts with an audit is transformation. Digital transformation that starts with an app is decoration.

