Nigeria’s telecom regulator has ordered mobile operators to carve out dedicated funding for cybersecurity in Abuja, making threat mitigation a mandatory board-level financial responsibility as cyber risks to critical national digital infrastructure intensify.
The Nigerian Communications Commission (NCC), in an updated Guidance Note for implementing its Cyber Resilience Framework, said service providers—including MTN Nigeria, Airtel Nigeria, Globacom and T2mobile—must allocate an appropriate percentage of their operational budgets under a standalone cybersecurity line item.
The directive comes as the National Information Technology Development Agency (NITDA) estimates Nigeria loses more than $500 million annually to cybercrime, with the regulator warning that compliance will be subject to periodic audits to align security resources with corporate risk strategies.
Under the updated framework, operators must appoint dedicated Chief Information Security Officers to oversee risk assessment, incident response, security controls and resilience programmes.
The tougher requirements coincide with rapid growth in Nigeria’s digital footprint, with NCC data showing internet users consumed 1.41 million terabytes of data in April 2026, up from approximately 983,000 terabytes in April 2025.
Under the regulations, operators must report cybersecurity incidents and breaches quarterly, while continuing to adhere to existing rules requiring notification to the NCC and the Nigeria Data Protection Commission within four hours of detecting an attack.
Furthermore, operators must educate customers on phishing, password and one-time-password theft, conduct biannual cybersecurity awareness sessions for staff and board members, and retain local call logs, user identifiers and traffic data within Nigeria for at least two years subject to lawful access.
Share


