The Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.
The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.
Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.
The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.
According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.
The framework also requires operators to designate senior executives responsible for cybersecurity oversight. At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.
Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, the Executive Commissioner, Technical Services, NCC, Abraham Oshadami, said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”
He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”
“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”
The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.
In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.
Stakeholders believe the new measures will improve the security posture of Nigeria’s telecommunications sector, which serves as the backbone for banking, e-commerce, government services, digital payments and other critical sectors of the economy.
Nigeria’s telecommunications sector has become an increasingly attractive target for cybercriminals due to the rapid expansion of digital services, mobile financial transactions and cloud-based infrastructure. To address the evolving threat landscape, the NCC developed the Cyber Resilience Framework for the Nigerian Communications Sector, which became effective in February 2026.
However, the framework sets baseline cybersecurity requirements applicable to all telecom licensees spanning mobile network operators, internet service providers, data centre operators, and infrastructure firms. While operators are allotted a 12-month period to achieve full compliance, the Commission retains the authority to initiate compliance evaluations before that period expires.

