Abuja: TECHz – News Desk
The Nigerian Communications Commission (NCC) has issued a firm directive requiring all telecommunications operators to make dedicated budgetary provisions for cybersecurity.
As cyber risks to critical national digital infrastructure intensify, the regulator is making threat mitigation a mandatory, board-level financial responsibility. The new rules are outlined in the newly released Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which updates the foundational cybersecurity framework introduced in February 2026.
Under the updated framework, licensed service providers – including major operators like MTN Nigeria, Airtel Nigeria, Globacom, and T2mobile, as well as internet service providers – must allocate an appropriate percentage of their total company budget exclusively to cybersecurity. The NCC mandates that these funds must be designated under a separate, standalone budgetary category. This restructuring ensures that cybersecurity investments are no longer treated as optional operational expenses, but rather as strategic business priorities, facilitating direct monitoring by company Boards of Directors. Adherence to these financial directives will be strictly monitored through periodic regulatory audits.
Beyond funding, the NCC has overhauled the governance and incident-response expectations for the sector. Telecom operators must officially appoint a designated Chief Information Security Officer (CISO) who will be responsible for assessing and mitigating enterprise-wide cybersecurity risks. In the event of a cyberattack, service providers must notify the NCC’s Computer Security Incident Response Team (CSIRT) and the Nigeria Data Protection Commission (NDPC) within four hours of detecting the breach, followed by a final comprehensive report within 24 hours. Operators are required to submit quarterly reports detailing cyberattacks, threats, and mitigation measures within 15 days after the end of each quarter.
To further safeguard the ecosystem, the NCC has implemented strict data retention and consumer protection protocols. Telecom companies must retain local call logs, user identifiers, and traffic data within Nigeria for a minimum of two years, ensuring availability for lawful access by security agencies. Operators must also actively educate their subscribers about the risks of sharing login credentials and provide channels for Nigerians to report phishing sites. To foster a risk-aware culture internally, companies must conduct mandatory cybersecurity awareness sessions for their staff and board members at least twice a year.
These stringent requirements arrive amid explosive growth in Nigeria’s digital footprint. According to NCC data, internet users consumed 1.41 million terabytes of data in April 2026 alone, up from approximately 983,000 terabytes in April 2025. Meanwhile, the National Information Technology Development Agency (NITDA) estimates that Nigeria loses more than $500 million annually to cybercrime. By forcing operators to align their financial resources with corporate risk strategies, the NCC aims to fortify the telecommunications sector. Operators have been allotted a 12-month period to achieve full compliance, though the NCC retains the authority to initiate evaluations before that deadline expires.


