NewsMacroNCC Mandates Dedicated Cybersecurity Budgets for Nigerian Telecom Operators

NCC Mandates Dedicated Cybersecurity Budgets for Nigerian Telecom Operators

Author: TechNext24·

Key Takeaways

  • The NCC requires all Nigerian telecom operators to allocate a separate, dedicated budget category specifically for cybersecurity spending subject to board oversight and periodic audits.
  • Operators must notify both the NCC and the Nigerian Data Protection Commission within four hours of detecting any cyberattack, followed by updates every four hours and a confirmation report within 24 hours.
  • Every telecom operator must appoint a Chief Information Security Officer responsible for assessing, identifying, and mitigating cybersecurity risks in accordance with board-approved policies.
  • Telecom companies are obligated to retain call logs, user IDs, and traffic data within Nigeria for a minimum of two years to facilitate law enforcement background checks conducted with a valid warrant.
  • Operators must submit quarterly reports detailing cyberattacks, threats, incidents, breaches, and mitigation measures to the NCC-CSIRT within 15 days after each quarter closes.
NCC Mandates Dedicated Cybersecurity Budgets for Nigerian Telecom Operators

The Nigerian Communications Commission (NCC) has directed all telecommunications operators in the country to set aside a dedicated portion of their budgets for cybersecurity, part of a broader regulatory push to strengthen the sector's defenses against escalating cyber threats.

The directive is contained in the newly released Guidance Note on the Implementation of Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which updates a comprehensive document the regulator originally issued in February 2026.

"Service Providers shall allocate an appropriate percentage of the total company budget to cybersecurity," the implementation document states, adding that "this allocation shall be designated under a separate budgetary category to facilitate monitoring and oversight by the Board of Directors and top-level management."

The framework applies to major Nigerian telecom operators including MTN, Airtel, Globacom, T2mobile, and internet service providers (ISPs). Nigeria is Africa's largest telecom market by subscribers, with over 220 million active mobile connections, making the sector's resilience a nationally significant concern. These companies are expected to effectively respond to and learn from cybersecurity attacks, with an emphasis on strengthening sector-wide situational awareness and protecting subscriber data.

As data- and volume-driven businesses, telecom operators are particularly vulnerable to cyberattacks that target customer information, call logs, and airtime recharge records. Other threats include system outages, targeted intrusions, and malware infections. The framework arrives as telecom networks increasingly underpin Nigeria's digital financial services ecosystem, including USSD-based banking transactions used by tens of millions of Nigerians.

The NCC stressed that operators must ensure sufficient funds and resources are allocated and aligned with their cybersecurity risk strategies. Compliance will be verified through periodic audits, during which all implemented plans must be reflected in budgetary allocations.

Under requirements first announced in February 2026, operators must notify both the NCC and the Nigerian Data Protection Commission (NDPC) within four hours of detecting any cyberattack. They are further required to provide the NCC with updates every four hours following detection and submit a confirmation report within 24 hours. The NDPC's involvement reflects the coordination between telecom and data protection authorities following the Nigeria Data Protection Act of 2023, which established the commission as the country's statutory data protection regulator.

The implementation document also introduces quarterly reporting obligations. Operators must file detailed reports covering cyberattacks, threats, cybersecurity incidents, breaches, and mitigation measures for each quarter ending in June, September, December, and March. These reports are to be submitted to the NCC-CSIRT within 15 days after the close of each quarter.

Additionally, the framework requires every operator to appoint a senior designated officer responsible for assessing, identifying, and mitigating cybersecurity risks. This official will hold the title of Chief Information Security Officer (CISO).

"The officials shall be responding to incidents, establishing appropriate standards and controls, and overseeing the development and execution of processes and procedures in accordance with the cybersecurity and cyber resilience policy or framework approved by the Board, Partners, or Proprietor," the document states.

The NCC has also directed operators to educate subscribers about the risks of sharing login credentials, passwords, one-time passwords (OTPs), and similar sensitive information with third parties, as well as the potential consequences of such actions. Nigerians are encouraged to report phishing emails and fraudulent websites to their respective service providers, who are expected to act swiftly on such reports.

Cybersecurity awareness extends beyond customers. The NCC requires companies to conduct awareness sessions for staff and board members at least twice annually to cultivate a risk-aware culture committed to continuous improvement.

For post-incident recovery, operators must develop strategies for the rapid restoration of systems affected by cybersecurity incidents, attacks, or breaches, including the provision of alternative services or systems to customers. These recovery strategies must be approved by the regulator.

Telecom companies are also required to retain call logs, user IDs, and traffic data within Nigeria for a minimum of two years to facilitate background checks by relevant security agencies armed with a valid law enforcement warrant.