
Nigeria’s telecommunications operators will now be required to set aside dedicated funding for cybersecurity under new directives issued by the Nigerian Communications Commission (NCC), as the regulator strengthens efforts to protect critical communications infrastructure and subscriber data.
Under the updated Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), telecom operators must allocate a specific portion of their annual budgets exclusively to cybersecurity. The NCC says the allocation should appear as a separate budget item, making it easier for company boards and senior management to monitor cybersecurity investments and ensure adequate oversight.
The updated guidance builds on the cyber resilience framework introduced earlier this year and reflects the regulator’s growing focus on improving the sector’s preparedness against increasingly sophisticated cyber threats.
Handling millions of customer records and massive volumes of digital traffic each day makes telecom operators a prime target for cyberattacks. As threats such as ransomware, malware and data breaches become more frequent, strengthening cybersecurity has become an operational priority across the industry.
Beyond dedicated funding, the NCC is requiring operators to align cybersecurity spending with their overall risk management strategies. Compliance will be assessed through regular audits, with companies expected to demonstrate that appropriate financial resources back their cybersecurity plans.
Prompt reporting is another key requirement under the updated guidance. Telecom operators are expected to notify the NCC and the Nigerian Data Protection Commission (NDPC) within four hours of detecting a cyberattack, issue periodic progress reports while responding to the incident, and deliver a final report within 24 hours.
In addition, telecom companies must file quarterly cybersecurity reports detailing incidents, emerging threats, breaches and the measures taken to address them.
As part of the new governance requirements, operators are expected to appoint a Chief Information Security Officer (CISO) to oversee cybersecurity strategy, incident response and the implementation of security policies approved by company leadership.
The NCC is also placing greater responsibility on telecom operators to help customers stay safe online. Providers must educate subscribers about common cyber threats, discourage the sharing of passwords, OTPs and other sensitive credentials, and encourage users to report phishing scams as soon as they are identified.
Internally, cybersecurity awareness is no longer limited to technical teams. The NCC wants operators to conduct staff and board-level awareness training at least twice a year to strengthen security culture across their organisations.
To improve resilience, operators must also establish regulator-approved recovery plans capable of restoring services quickly following a cyber incident. They are further required to retain call records, user identification data and traffic information within Nigeria for a minimum of two years to support legitimate law enforcement investigations when required.












