Nigeria’s telecommunications regulator has instructed all telecom operators to dedicate specific funds to cybersecurity as cyber threats continue to target the country’s digital infrastructure.
The Nigerian Communications Commission (NCC) announced that every licensed telecommunications company must now include cybersecurity as a key part of its annual budget. The directive is part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), designed to improve the security of Nigeria’s communication networks.
The new framework requires telecom operators to move beyond treating cybersecurity as an optional expense. Instead, the NCC wants companies to see it as a strategic investment that protects their networks, customers, and the country’s growing digital economy.
According to the Commission, operators must provide enough funding for regular cyber risk assessments, advanced security systems, employee training, incident response teams, continuous monitoring, and compliance with cybersecurity regulations.
The framework also introduces stronger leadership responsibilities. Telecom companies are expected to appoint senior executives to oversee cybersecurity programmes, while their boards of directors must ensure adequate funding and provide strategic guidance on cyber risk management.
Speaking during the unveiling of the framework, the Executive Commissioner for Technical Services at the NCC, Abraham Oshadami, said the increasing use of digital services has made stronger cybersecurity more important than ever.
He explained that as businesses, government agencies, and individuals rely more heavily on digital platforms, cybercriminals are becoming more sophisticated in their attacks. According to him, both state-sponsored and criminal groups are now targeting essential infrastructure, including telecommunications systems, through coordinated cyber and physical attacks.
Oshadami noted that these attacks often aim at disrupting network operations and compromising sensitive data, creating risks that extend beyond technology. He warned that successful attacks on telecommunications infrastructure could affect public safety, financial services, and other critical sectors that depend on reliable communication networks.
Under the new rules, telecom operators must also prepare detailed cybersecurity implementation plans. These plans should include regular security risk assessments, business continuity strategies, disaster recovery procedures, and routine testing of their cyber defence systems to ensure they remain effective against evolving threats.
Another major requirement is the mandatory reporting of cyber incidents. If a telecom operator experiences a significant cybersecurity breach, it must notify the NCC’s Computer Security Incident Response Team (CSIRT) within four hours of discovering the incident. After resolving the issue, the company must also submit a comprehensive report explaining the cause of the attack, its impact, and the steps taken to prevent similar incidents in the future.
Industry experts believe the new measures will strengthen the security of Nigeria’s telecommunications sector, which serves as the backbone for banking services, digital payments, e-commerce, government platforms, cloud computing, and other essential economic activities.
Nigeria’s telecom industry has become an increasingly attractive target for cybercriminals due to the rapid growth of mobile banking, online transactions, cloud services, and digital communication. To address these challenges, the NCC introduced the Cyber Resilience Framework, which became effective in February 2026.
The framework applies to all telecom licensees, including mobile network operators, internet service providers, data centre operators, and infrastructure companies. Although operators have been given 12 months to fully comply with the requirements, the NCC has stated that it may begin compliance assessments before the deadline to ensure companies are making meaningful progress.




