NCC Orders Telecom Firms to Set Cybersecurity Budgets

The Nigerian Communications Commission has directed telecom operators to set up dedicated cybersecurity budgets. This is part of a bigger push to protect the country’s communications infrastructure from rising digital threats.

The directive builds on the Cyber Resilience Framework for the Nigerian Communications Sector. This is a Zero Trust based policy the Commission rolled out earlier in the year to tighten security across telecom networks. With the new budget requirement, operators must now set aside specific funding for cybersecurity. They can no longer treat it as a minor line item buried inside general IT spending.

According to the Commission, the goal is simple. Telecom companies need the financial muscle to run round the clock monitoring and respond fast when breaches happen. Threats keep growing more complex by the day. The rise of 5G networks, the surge in connected IoT devices, and increasingly smart AI driven attacks have exposed gaps that older, underfunded security setups just cannot handle.

SEE ALSO:IHS Shareholders Approve MTN’s Full Ownership Bid

 

Operators already have several obligations under the framework. They must appoint dedicated cybersecurity officers. They must run continuous risk assessments. They must also maintain solid incident response protocols. On top of that, they are required to set up Security Operations Centres that watch networks nonstop for suspicious activity. That alone demands steady investment in tools, staffing, and infrastructure. A dedicated budget line helps ensure these duties do not slip once the initial compliance rush fades.

The Commission has given telecom companies a 12 month window to comply. It says it will track progress using a new Cyber Capability Index. This scoring system measures how well each operator meets the required standards. Operators that fall behind could face regulatory scrutiny. Still, the NCC insists the real goal is sector wide resilience, not punishment.

This latest move comes after a tense year for telecom security in Nigeria. A high profile data breach at MTN earlier this year compromised customer information across several markets. Core systems stayed intact, but the incident still exposed how vulnerable the sector remains. The Commission has also introduced a separate rule requiring operators to report cyberattacks within four hours of detection. A confirmation report is due within 24 hours through a dedicated portal. Together, these steps show just how seriously the regulator now treats cybersecurity.

Industry watchers say the new budget mandate marks a shift. Cybersecurity is no longer an optional extra for Nigeria’s telecom regulator. It is now a core cost of doing business. More than 172 million mobile subscribers and over 140 million internet users depend on these networks every single day. So the stakes here reach far beyond the operators themselves, straight into the wider digital economy the sector supports.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

GoMed Rolls Out Free Contraceptives for UniLag Students

Next Post

Fraud and Data Billing Overtake Poor Network in Kenya Telecom Complaints

Related Posts