NCC orders telecom operators to create dedicated cybersecurity budgets.

The Nigerian Communications Commission (NCC) has directed telecom operators to establish dedicated cybersecurity budgets as part of efforts to strengthen the security of Nigeria’s telecommunications sector and protect millions of subscribers from growing cyber threats.

The directive is contained in the regulator’s updated Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), requiring operators to allocate a specific portion of their annual budgets exclusively to cybersecurity initiatives.

Cybersecurity becomes a boardroom priority

Under the new framework, telecom operators must separate cybersecurity spending from their general operational budgets to improve transparency and ensure adequate oversight by company boards and executive management.

The NCC says the dedicated funding will support cyber threat detection, prevention, incident monitoring, and faster recovery from cyberattacks targeting telecom infrastructure and customer data.

The regulator will also assess compliance through periodic audits to ensure operators are making the required investments.

New reporting and governance requirements

Beyond funding, the NCC has introduced stricter governance measures for telecom operators.

Companies must appoint a Chief Information Security Officer (CISO) responsible for identifying cybersecurity risks, responding to incidents, implementing security controls, and overseeing compliance with the regulator’s cybersecurity framework.

Operators are also required to submit quarterly cybersecurity reports detailing attacks, breaches, vulnerabilities, and mitigation measures, while continuing to notify both the NCC and the Nigeria Data Protection Commission (NDPC) within four hours of detecting significant cyber incidents.

Strengthening customer awareness

The framework also places greater emphasis on consumer education.

Telecom operators must educate subscribers about common cybersecurity risks, including phishing attacks, fraudulent websites, password theft, and the dangers of sharing One-Time Passwords (OTPs) or login credentials with third parties.

Customers will also be encouraged to report suspicious emails, websites, and other cyber threats for immediate investigation.

As Nigeria’s digital economy continues to expand, telecom operators have become critical custodians of sensitive customer information, including personal data, call records, and financial transaction details.

The NCC’s latest directive reflects the growing need for stronger cyber resilience as cyberattacks become more sophisticated and frequent.

By requiring dedicated cybersecurity investment, stronger governance, and greater customer awareness, the regulator aims to improve the security, reliability, and resilience of Nigeria’s telecommunications ecosystem.