The NCC has told operators to stop treating cybersecurity as a line item buried inside general IT spending. The Nigerian Communications Commission has directed all licensed telecom operators, including MTN Nigeria, Airtel Nigeria, Globacom and T2mobile, to allocate an appropriate percentage of their operational budgets under a standalone cybersecurity line item.
What The New Guidance Requires
The directive is contained in an updated Guidance Note on the Implementation of the Cyber Resilience Framework for the Nigerian Communications Sector, which builds on the broader framework the NCC released earlier in 2026. The funds must be allocated under a separate budgetary category and will be used to detect, prevent, and monitor threats to operators’ systems and subscribers’ data. The regulator wants the allocation to sit apart from general IT or operational spending so that boards and senior management can track it directly rather than have it disappear into a broader technology budget.
Under a control the framework labels “Budget and Spending,” service providers are expected to keep dedicated financial resources on hand specifically for strengthening cybersecurity measures. That budgetary planning must line up with each company’s information security and privacy objectives, and operators are required to track how the money is actually spent, adjusting future allocations if the spending isn’t producing the desired security outcomes. Responsibility for cybersecurity risk sits with company boards and executive management, with operators also expected to appoint a Chief Information Security Officer.
Reporting And Oversight Rules Get Tighter
Beyond the budget mandate, operators must now report cybersecurity incidents and breaches to the NCC on a quarterly basis. This sits alongside an existing rule requiring operators to notify both the NCC and the Nigeria Data Protection Commission within four hours of detecting an attack, followed by a full post-incident analysis once the threat has been contained. Compliance will be checked through periodic audits, during which operators will need to show that their cybersecurity plans are actually reflected in their budgets rather than existing only on paper.
The framework also pushes operators toward more preventive habits. Companies are expected to run cybersecurity awareness sessions for staff and board members twice a year and to educate customers on threats such as phishing, password theft, and one-time passcode compromise. Call logs, subscriber identifiers, and traffic data must be retained locally for at least two years, subject to lawful access rules.
What It Means For Operators
For MTN, Airtel, Globacom, T2mobile, and the country’s internet service providers, the directive converts cybersecurity from a cost that could be trimmed in lean quarters into a fixed obligation with board-level accountability. It also gives the NCC a clearer audit trail: rather than asking operators to demonstrate general security readiness, the regulator can now check whether a specific, ring-fenced line item exists and whether spending against it matches stated risk priorities. Whether the mandate translates into meaningfully stronger defences will likely depend on how strictly the NCC enforces the audit requirement and how operators define “appropriate percentage” in practice, since the guidance does not appear to specify a fixed minimum threshold.





