NCC Orders Telecom Operators to Create Dedicated Cybersecurity Budgets
Nigeria's telecom regulator is tightening the rules on network security. Under a new directive, telecom companies must create dedicated cybersecurity budgets and report major breaches within four hours.
NCC Orders Telecom Operators to Create Dedicated Cybersecurity Budgets
For decades, cybersecurity in the telecommunications industry was often treated as an annoying cost centre. Network operators invested heavily in cell towers, fibre-optic cables, and subscriber growth. Security usually received whatever leftover funding remained at the end of the financial quarter.
That approach is no longer allowed in Nigeria.
The Nigerian Communications Commission has issued a directive requiring all licensed telecom operators to set aside dedicated cybersecurity funding. Under the regulator's newly released Cyber Resilience Framework for the Nigerian Communications Sector, cyber defense can no longer be treated as an optional operational expense. It must now be funded as a core business priority.
Why is the regulator taking this step now? The reason is straightforward. Nigeria's modern economy runs on digital rails. Banks, government services, schools, and small businesses depend entirely on mobile networks. If a coordinated cyberattack knocks out a major telecom provider, the economic damage spreads everywhere instantly.
The new framework requires operators to build clear leadership structures around security. Companies must assign direct oversight to senior executives and boards of directors. Telecom boards can no longer claim ignorance about their system vulnerabilities. They are now directly responsible for approving adequate funds for security tools, risk checks, staff training, and continuous network monitoring.
The regulation also introduces a strict timeline for transparency. If a telecom company suffers a major security breach, it must report the incident to the commission's Computer Security Incident Response Team within four hours of discovering it. Once the threat is contained, the operator must submit a complete post-incident report explaining what went wrong and how to prevent a repeat.
Abraham Oshadami, the executive commissioner for technical services at the commission, noted that cyber threats have changed significantly. Attacks are no longer just about stealing data or crashing websites. Sophisticated actors now target operational technology, which controls the physical infrastructure of networks. A successful breach can disrupt daily human activity and put public safety at risk.
For telecom investors and company leaders, this directive means corporate budgets will need rebalancing. Cybersecurity will now sit alongside major capital expenditures like network expansion and tower maintenance. While this adds immediate financial pressure on operators already dealing with high operational costs, it builds necessary long-term protection for the entire digital economy. In an interconnected market, a telecom network is only as strong as its weakest link.