The Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of new measures to strengthen the resilience of Nigeria’s communications infrastructure against growing and increasingly sophisticated cyber threats.
The directive is contained in the Commission’s updated Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which sets out the requirements telecom operators must meet in implementing the sector’s cybersecurity framework.
Under the new requirements, licensed telecom operators are expected to treat cybersecurity as a strategic business priority, with adequate funding provided for cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and regulatory compliance.
The framework also requires operators to establish formal cybersecurity governance structures and integrate cyber risk into their broader enterprise risk management systems.
The NCC said operators must ensure that cybersecurity investments are adequately funded and supported at the highest levels of their organisations, reflecting the growing importance of communications infrastructure to Nigeria’s economy.
Boards of directors are expected to provide strategic oversight of cyber resilience programmes and ensure that adequate resources are made available, while senior executives must be designated to take responsibility for cybersecurity oversight.
The Commission’s requirements come amid increasing dependence on telecommunications networks for financial services, digital commerce, government services and other economic activities, making disruptions to critical communications infrastructure potentially more damaging.
Speaking on the framework, Abraham Oshadami, executive commissioner, technical services, NCC, said the increasing digitalisation of services and rapid growth in data exchange had made a stronger cybersecurity regime necessary.
“Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent,” Oshadami said.
He noted that essential sectors, including telecommunications, were increasingly being targeted by coordinated cyber and physical attacks, with threats extending to control systems and data integrity.
According to him, the growing exposure of operational technology to cyberattacks presents risks beyond service disruptions, particularly where attacks could affect the physical safety of people.
“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure,” he said.
Beyond funding and governance, the framework requires operators to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments and establish business continuity and disaster recovery procedures.
Operators must also regularly test their cyber defence capabilities to assess their ability to prevent, detect and respond to attacks.
The NCC has further made the reporting of major cyber incidents compulsory under the framework. Telecom licensees are required to notify the NCC’s Computer Security Incident Response Team (CSIRT) within four hours of discovering a major cybersecurity breach.
Following the containment and mitigation of an incident, operators are also required to submit a detailed post-incident analysis to the Commission.
The measures place greater responsibility on telecom operators and their boards to demonstrate that cybersecurity is being adequately funded, governed and integrated into the management of risks to Nigeria’s critical communications infrastructure.





