The Nigerian Communications Commission (NCC) has directed all telecom operators to allocate an appropriate percentage of their budgets to cybersecurity. The funds, which must be allocated und
The Nigerian Communications Commission (NCC) has directed all telecom operators to allocate an appropriate percentage of their budgets to cybersecurity. The funds, which must be allocated under a separate budgetary category, will be used to detect, prevent, and monitor threats to operators’ systems and subscribers’ data.
The directive, contained in the newly released Guidance Note on the Implementation of Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), is an update to the comprehensive document released by the regulator in February 2026.
“Service Providers shall allocate an appropriate percentage of the total company budget to cybersecurity,” part of the implementation document reads, adding that “this allocation shall be designated under a separate budgetary category to facilitate monitoring and oversight by the Board of Directors and top-level management.”

Backed by the policy framework is the notion that Nigerian telecom operators, such as MTN, Airtel, Globacom, T2mobile and internet service providers (ISPs), must effectively respond to and learn from cybersecurity attacks. The plan sits on strengthening sector-wide situational awareness of cyberattacks and protection of subscribers’ data.
Like other data- and volume-driven businesses, telecom operators are vulnerable to cyberattacks targeting customer information, call logs, and airtime recharge records. Other forms of attacks include system outages, targeted attacks and malware infections.
In a proactive move, NCC noted that telecom operators must ensure that sufficient funds and resources are allocated and aligned with cybersecurity risk strategies. The regulator added that adherence to these directives shall be monitored through periodic audits, during which all implemented plans must be reflected in budgetary allocations.
Earlier in February, the NCC had informed operators to notify both the regulator and the Nigerian Data Protection Commission (NDPC) within four hours of detecting any cyberattack. They are also expected to provide the NCC with a periodic update every four hours after detection and provide a confirmation report after 24 hours (1 day).

In addition, the implementation document has introduced additional responsibilities. Telecom operators must now make quarterly reports (June, September, December, and March) detailing cyberattacks, threats, cybersecurity incidents, breaches, and the measures taken to mitigate the threats.
The document is expected to be submitted to NCC-CSIRT within 15 days after the end of each quarter.
Also Read: FG to set up new national cybersecurity council after rising cyber attacks.
Telecom: designated officer and customers’ awareness
As contained in the framework, operators are directed to appoint a senior official and designated officer who will be responsible for assessing, identifying, and mitigating cybersecurity risks. The designated officer will be accorded the title of Chief Information Security Officer (CISO).
“The officials shall be responding to incidents, establishing appropriate standards and controls, and overseeing the development and execution of processes and procedures in accordance with the cybersecurity and cyber resilience policy or framework approved by the Board, Partners, or Proprietor,” part of the document reads.
As much as telecom operators and the NCC want to mitigate cybersecurity attacks, it becomes necessary to educate Nigerians on basic threat protections.
The NCC has now directed service operators to educate subscribers concerning the risks of sharing their login credentials, passwords, OTPs, or similar information with third parties, and the potential consequences of such actions. Also, Nigerians are to report phishing emails and phishing sites to their respective service providers, where operators are expected to take swift action upon such reports.

Not only customers but also staff and board members of each operator must be cybersecurity-aware. NCC said that companies must conduct awareness sessions at least twice a year for their personnel to foster a culture that is risk-aware and dedicated to continuous improvement.
In terms of the recovery phase following a cyber attack incident, operators are informed to have strategies for the swift restoration of systems affected by cybersecurity incidents, attacks, or breaches, such as providing alternative services or systems to customers. And such strategy must have been approved by the regulator.
It also becomes necessary for telecom companies to retain call logs, user IDs, and traffic data in-country for at least 2 years. This is significant for any background checks by relevant security agencies with a valid law enforcement warrant.