The Nigerian Communications Commission (NCC) has mandated all telecommunications operators to establish a separate budget line for cybersecurity. This directive is part of the updated Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), released in February 2026. Operators including MTN, Airtel, Globacom, T2mobile and internet service providers must allocate an appropriate percentage of their total budget specifically for detecting, preventing and monitoring cyber threats. The budget must be clearly designated to allow oversight by company boards and top management.

The NCC requires that these cybersecurity allocations be reflected in periodic audits, ensuring compliance with the new framework. Telecom operators are also expected to report any cyberattack to the NCC and the Nigerian Data Protection Commission within four hours of detection, followed by updates every four hours and a full confirmation report within 24 hours. Quarterly reports on cyber incidents, breaches and mitigation steps must be submitted to the NCC-CSIRT within 15 days after the end of each reporting period—March, June, September and December.

Operators must appoint a Chief Information Security Officer (CISO) or designated officer responsible for managing cybersecurity risks, incident response and policy implementation. The framework also emphasizes the need for cybersecurity awareness among staff, board members and subscribers. As telecom networks handle vast volumes of sensitive data such as call logs, customer information and airtime records, they remain high-value targets for malware, system outages and targeted attacks. The new measures aim to strengthen sector-wide resilience and real-time threat monitoring.

💡 NaijaBuzz Take

The NCC's requirement for a dedicated cybersecurity budget implies that previous spending may have been insufficient or buried within broader IT allocations. If operators treat this as a compliance checkbox rather than a shift in operational priority, the impact on subscriber data protection could remain limited. The effectiveness will depend on whether appointed CISOs have real authority and whether audits lead to enforceable consequences.

Editorial note: AI-assisted opinion, not established fact. Full disclaimer →