Four Hours: Nigeria's New Deadline for Reporting a Cyberattack
- ESET Expert

- 7 hours ago
- 5 min read
NCC Mandates Dedicated Cybersecurity Budgets for Nigerian Telecom Operators

The Nigerian Communications Commission (NCC) has issued an updated Guidance Note under its Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), requiring telecom operators to allocate a dedicated, separately itemised budget for cybersecurity. Released in August 2026, the directive also introduces strict incident-reporting timelines, formal executive accountability, and new obligations for operators to educate their own subscribers on basic security practices.
Key points of this article:
Telecom operators must now set aside a specific, board-visible budget exclusively for cybersecurity, rather than folding it into general IT spend.
Detected cyberattacks must be reported to both the NCC and the Nigeria Data Protection Commission (NDPC) within four hours, with a full incident report due within 24 hours.
Every operator must appoint a Chief Information Security Officer (CISO) and file quarterly cybersecurity reports covering incidents, threats, and remediation.
Staff and board-level security training is now mandatory at least twice a year, with compliance verified through regular audits.
Operators must actively educate subscribers on phishing, password hygiene, and OTP safety.
The directive builds on a framework the NCC previewed through stakeholder consultations in 2025.
A budget line, not a discretionary spend. Cybersecurity investment inside a telecom operator has historically been absorbed into general technology budgets, making it easy to defer and difficult to hold any single person accountable for. The updated guidance closes that gap: operators must allocate a specific portion of their annual budget exclusively to cybersecurity, itemised separately and visible to the board rather than buried inside broader IT spend.
The NCC has also tied the requirement to each operator's overall risk management strategy, meaning funding levels are expected to reflect actual exposure, not a fixed or arbitrary figure.
Background: a framework years in the making
The guidance is not a sudden regulatory reflex. The NCC laid the groundwork through stakeholder consultations held in 2025 as it developed the wider Cyber Resilience Framework. At one such session in Abuja, Abraham Oshadami, the NCC's Executive Commissioner for Technical Services, warned that attackers were increasingly targeting essential infrastructure through coordinated digital and physical assaults, with risks extending beyond data breaches into potential threats to human safety when critical communications systems are disrupted. That framing positions telecom cybersecurity as a matter of national infrastructure resilience, which explains why the resulting accountability requirements sit so high in the organisational chart.
Incident reporting on a compressed timeline
The most demanding element of the guidance is its reporting window. Operators have four hours from detection of a cyberattack to notify the NCC and the NDPC, with a full incident report due within 24 hours and periodic updates required while response is ongoing. For comparison, the four-hour window is considerably tighter than the EU's GDPR, which allows 72 hours for breach notification and remains one of the most widely referenced international benchmarks.
Quarterly cybersecurity reports are also now mandatory, covering incidents, emerging threats, and remediation steps, making disclosure an ongoing obligation rather than a one-time requirement triggered by a single event.
Meeting a four-hour detection-to-notification window requires visibility into network activity at a level most compliance documentation alone cannot provide. That kind of real-time monitoring is where the broader cybersecurity research community, ESET among them, concentrates much of its work: tracking attacker behaviour across live networks rather than waiting for a scheduled audit to surface a problem. Meeting a regulatory deadline and maintaining genuine security are related but distinct outcomes; the first is a fixed point in time, the second is a continuous operational discipline that has to be in place well before a regulator asks for a report.
Accountability assigned by role
Every operator is now required to appoint a dedicated Chief Information Security Officer, responsible for cybersecurity strategy, incident response, and implementation of leadership-approved policy. Combining a named CISO role with a ring-fenced budget places both the funding and the formal mandate to act with a single accountable executive, rather than requiring a fresh business case each time a threat emerges.
Compliance will not rely on self-reporting. The NCC has stated it will assess adherence through regular audits, with operators required to demonstrate that cybersecurity plans are backed by adequate financial resources rather than existing only as policy documentation. Operators must also establish regulator-approved recovery plans capable of restoring services quickly following an incident, and retain call records, user identification data, and traffic information within Nigeria for a minimum of two years to support law enforcement investigations.
Training requirements extend in two directions
Internally, operators must run staff and board-level security awareness training at least twice a year, extending baseline cyber hygiene expectations beyond technical teams to those making budget and governance decisions. Externally, operators are required to help subscribers stay safe by discouraging the sharing of passwords and OTPs and encouraging prompt reporting of phishing attempts, placing telecom companies in an active role in public cybersecurity education rather than a purely infrastructural one.
Industry analysis has put the average attack rate at over 4,000 per week since the start of 2026, among the highest recorded on the continent, concentrated heavily on banks, fintech platforms, telecom providers, and government systems.
Telecom operators sit at the centre of that exposure, handling millions of customer records and high volumes of daily traffic that make them attractive, high-consequence targets. A breach at a single major operator extends well beyond that company, affecting every business and individual dependent on its network for communication and transactions.
Broader implications
The CRF-NCS guidance is sector-specific, but its underlying structure, dedicated budget, board-level visibility, named accountability, and hour-scale response timelines, is not unique to telecoms. As Nigeria's cybersecurity and data protection framework continues to develop, alongside parallel efforts from the NDPC around data localisation and reporting standards, similar expectations are likely to extend beyond this sector before many organisations are prepared for them. For businesses outside NCC oversight, the operating principle remains the same: a ring-fenced budget is only effective when paired with the visibility to detect an incident within hours and the operational discipline to respond once that clock starts running.
ESET AND THIS ISSUE
ESET research consistently shows that regulatory deadlines and genuine security readiness are not automatically the same thing. Meeting a four-hour detection-to-notification window depends on visibility into network activity that exists well before any incident occurs, the kind of continuous monitoring that identifies unusual behaviour in real time rather than after a scheduled review. This is the layer where global threat research, including ESET's own telemetry and analysis of attacker behaviour across live networks, becomes directly relevant to compliance frameworks like the CRF-NCS. A policy can mandate a four-hour clock. Only sustained visibility into what is actually happening on a network can make that clock achievable.
None of this is achievable through policy alone. A four-hour detection-to-notification window assumes an organisation already has real-time visibility into what's happening across its own network, not a retrospective view pieced together after the fact. This is the specific capability ESET's PROTECT platform is built to deliver at its higher tiers, where extended detection and response, powered by ESET Inspect, correlates behaviour across endpoints in real time, flags anomalies as they emerge, and compiles them into a clear incident an analyst can act on immediately rather than reconstruct hours later. It is a useful distinction to hold onto: a regulation can set a four-hour clock, but only continuous visibility of this kind determines whether an organisation is actually equipped to meet it. 1. https://ncc.gov.ng/sites/default/files/2026-03/Cyber-Resilience-Framework-for-Nigeria-Communication-Sector-(CRF-NCS).pdf



Comments