World Watch/Nigeria/Cybersecurity

Cybersecurity · Nigeria

Cybersecurity - Nigeria

Comprehensive lawCybercrimes (Prohibition, Prevention, etc.) Act 2015, as amended by the Cybercrimes (Amendment) Act 2024 — operationalized through the National Cybersecurity Policy and Strategy 2021, the Office of the National Security Adviser (ONSA) Directorate of Cybersecurity, and the Nigerian Computer Emergency Response Team (ngCERT). Sector-specific rules supplement it, notably the Central Bank of Nigeria's risk-based cybersecurity framework and breach-notification duties under the Nigeria Data Protection Act 2023.

Nigeria has a dedicated, comprehensive cybersecurity statute — the Cybercrimes (Prohibition, Prevention, etc.) Act 2015, amended in 2024 — covering offences, protection of critical national information infrastructure, incident reporting, and a cybersecurity levy/fund. It is reinforced by the National Cybersecurity Policy and Strategy 2021 and a national coordination body (ngCERT under ONSA). Sectoral overlays, especially the Central Bank's risk-based framework for banks and financial institutions, impose stricter incident-reporting duties.

Primary comprehensive law

The Cybercrimes (Prohibition, Prevention, etc.) Act 2015 is Nigeria's central cybersecurity/cybercrime statute, amended in 2024 (signed 28 February 2024) to revise 12 sections, strengthen ngCERT's role, increase penalties and expand surveillance/interception powers.

Incident reporting to ngCERT (72 hours)

Section 21 requires any person/institution that observes an attack, intrusion or disruption to report it to the National CERT (ngCERT). The 2024 amendment cut the reporting window from 7 days to 72 hours; the prior regime carried a fine and possible denial of internet service for failure to report.

Critical National Information Infrastructure (CNII)

Part II of the Act empowers designation of CNII and prescribes minimum standards, guidelines and procedures for its protection, preservation and management, with audit and inspection powers.

National strategy & coordination bodies

The National Cybersecurity Policy and Strategy 2021 sets governance direction; the ONSA Directorate of Cybersecurity is the lead agency, and ngCERT is the national coordination centre managing incidents and overseeing sectoral CSIRTs.

Cybersecurity levy and National Cybersecurity Fund

Section 44 of the Act establishes a National Cybersecurity Fund; to implement it the Central Bank issued a circular requiring banks/financial institutions to apply a 0.5% levy on electronic transactions.

Sectoral rules — CBN financial sector

The Central Bank of Nigeria's Risk-Based Cybersecurity Framework and Guidelines (for Deposit Money Banks/Payment Service Banks and, since 2022, Other Financial Institutions) mandate governance, monitoring and reporting of all cyber incidents to the Director of Banking Supervision within 24 hours of detection.

Data-breach notification (NDPA 2023)

Under the Nigeria Data Protection Act 2023, controllers must notify the Nigeria Data Protection Commission of personal-data breaches (within 72 hours where feasible) and affected individuals where risk is high; processors must promptly notify the engaging controller.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →