Telecommunication operators in Nigeria have been directed by the Nigerian Communications Commission (NCC) to allocate a dedicated portion of their annual budgets to cybersecurity as part of new measures aimed at strengthening the resilience of Nigeria’s communications sector against cyber threats.
The directive is contained in the regulator’s updated Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which provides implementation guidelines for the cybersecurity framework introduced earlier this year.
Under the new requirements, telecom operators, including mobile network providers and internet service providers, must create a separate cybersecurity budget to fund activities such as detecting threats, preventing cyberattacks, monitoring networks, and protecting subscribers’ data.
Cybersecurity spending moves into the boardroom
Although the NCC did not specify the minimum threshold of the annual budget that should go to cybersecurity, the regulator said that spending must be clearly identified as a separate budget category, allowing company boards and senior management to monitor how resources are being invested in protecting digital infrastructure.
“Service Providers shall allocate an appropriate percentage of the total company budget to cybersecurity. This allocation shall be designated under a separate budgetary category to facilitate monitoring and oversight by the Board of Directors and top-level management,” the document reviewed by TechMedia Africa, reads in part.
The NCC added that operators must ensure cybersecurity investments align with their overall risk management strategies, while compliance will be assessed through periodic regulatory audits. During these audits, companies will be expected to demonstrate that their cybersecurity plans are supported by adequate financial resources.
“These resources should be specified in terms of budget, personnel, and materials, NCC said, adding that “resourcing needs shall be reviewed regularly, based on the progress or gaps in implementing cybersecurity standards, and any updates shall be reflected in the budgetary allocations.”
Operators face stricter security and reporting obligations
Beyond funding cybersecurity initiatives, the framework introduces stricter reporting requirements designed to improve the industry’s response to cyber incidents.
Telecom operators are now required to notify both the NCC and the Nigeria Data Protection Commission (NDPC) within four hours of detecting a cyberattack. They must continue providing updates every four hours until the incident is resolved before submitting a final report within 24 hours.
The regulator also directed operators to submit quarterly reports detailing cybersecurity incidents, attempted attacks, identified threats, data breaches, and the steps taken to mitigate them.
To strengthen internal oversight, every operator must appoint a Chief Information Security Officer (CISO) responsible for identifying cybersecurity risks, coordinating incident response, implementing security controls, and ensuring compliance with cybersecurity policies approved by company leadership.
Protecting the foundation of Nigeria’s digital economy
The NCC’s directive comes as cyber threats continue to increase globally, with telecommunications companies becoming frequent targets because they manage large volumes of customer data and critical communications infrastructure.
In a recent Special Coverage, TechMedia Africa reported how China-backed cyber actor UNC2814 used Google Sheets to carry out a large-scale espionage campaign against telecom networks in Africa, allowing them access to some of customers’ critical data, including phone numbers and how they spoke to.
The consequence of a cyber attack in Nigeria’s telecom infrastructure is particularly concerning as the sector has become the backbone of the country’s digital economy. According to the NCC, the country had over 172 million active telephone subscriptions and more than 142 million internet subscriptions in 2025. Mobile networks now support banking, digital payments, e-commerce, healthcare, education, government services, and thousands of digital businesses that rely on uninterrupted connectivity.
According to data from National Bureau of Statistics (NBS), Information and Communication Technology (ICT) accounted for 10.07 percent of Nigeria’s Gross Domestic Product (GDP) in 2025.
Of the four sectors that make up the ICT, including Publishing; Motion Picture, Sound Recording, and Music Production, and Broadcasting, Telecommunications and Information Services accounted for 7.29 percent. demostrating how crucial telecom is to Nigeria’s economy.
Globally, the financial impact of cybercrime is also rising. Cybersecurity Ventures estimates that cybercrime could cost the global economy $10.5 trillion annually, making it one of the fastest-growing economic threats facing businesses and governments.
A successful cyberattack on telecom infrastructure could expose customer information, disrupt essential services, interrupt financial transactions, and affect millions of subscribers and businesses. By requiring operators to dedicate specific budgets to cybersecurity, appoint Chief Information Security Officers, strengthen incident reporting, and improve public awareness, the NCC is encouraging a shift from reacting to cyberattacks after they happen to preventing them before they can cause widespread disruption.
