Nigeria, the largest economy in Africa and a significant player in the global digital economy, has advanced new cybersecurity regulations requiring organizations to disclose cyberattacks — a move that positions West Africa's most populous nation alongside the EU, the US, and Australia in mandating transparency around breaches.
The Regulatory Push
Nigeria's cybersecurity authority has introduced mandatory incident reporting rules that compel organizations across critical sectors to notify regulators and, in some cases, the public when they suffer significant cyberattacks. The framework targets sectors including financial services, telecommunications, energy, and government — areas that have faced sustained criminal targeting.
The move reflects a broader maturation of Nigeria's cybersecurity governance posture. Key elements include:
- Mandatory disclosure timelines for significant cyber incidents
- Sector-specific reporting thresholds based on data sensitivity and operational impact
- Penalties for non-disclosure or delayed reporting
- Coordination mechanisms between the Nigeria Computer Emergency Response Team (ngCERT) and sector regulators
The Threat Landscape Driving Reform
The regulatory push comes as cybercriminals targeting and operating from Nigeria continue to generate significant profits, evolving far beyond the legacy "419" advance-fee fraud schemes the country became notorious for.
Modern Nigerian cybercrime operations include:
Business Email Compromise (BEC): Nigeria-linked threat actors remain among the most prolific BEC operators globally. The FBI's Internet Crime Complaint Center (IC3) consistently ranks BEC as one of the costliest cybercrime categories, with Nigerian actors implicated in billions of dollars of losses annually.
Romance fraud and pig butchering: Organized criminal networks — some operating from scam compounds — run large-scale investment fraud and relationship scams targeting victims globally.
Ransomware: A newer but growing trend, with Nigerian actors both developing ransomware and serving as affiliates for established ransomware groups.
Commodity malware distribution: Nigerian actors are active distributors of information-stealing malware (AgentTesla, FormBook, Remcos RAT) targeting businesses across industries.
Why Mandatory Disclosure Matters
Breach transparency requirements serve several purposes that benefit the broader cybersecurity ecosystem:
-
Threat intelligence sharing: Disclosed incidents feed into national and sector CERTs, allowing defenders to share indicators of compromise and detect related attacks earlier.
-
Accountability pressure: Organizations that know they must disclose breaches face stronger incentives to invest in preventive controls rather than hoping incidents go undetected.
-
Accurate threat picture: Voluntary reporting systematically undercounts incidents — mandatory rules produce more accurate data for policymakers and researchers.
-
Victim notification: Affected individuals and partner organizations can take protective action more quickly.
The African Cybersecurity Landscape
Nigeria's regulatory advances come amid a broader wave of cybersecurity capacity-building across Africa:
- South Africa enacted the Protection of Personal Information Act (POPIA) with breach notification requirements.
- Kenya passed the Kenya Data Protection Act, establishing an independent data protection commissioner.
- The African Union adopted a Convention on Cyber Security and Personal Data Protection (Malabo Convention), though ratification has been slow.
- Ghana, Rwanda, and Egypt have all established national cybersecurity authorities in recent years.
The continent faces unique challenges: rapidly growing internet penetration, limited cybersecurity workforce depth, underfunded public sector IT, and being both a source and target of sophisticated cybercrime. Regulatory frameworks are one piece of the solution — they must be paired with enforcement capacity, technical assistance, and international cooperation.
What This Means for Organizations Operating in Nigeria
Businesses with operations, customers, or data processing activities in Nigeria should:
- Review incident response plans to ensure they include Nigerian disclosure obligations and timelines
- Map data flows involving Nigerian residents or Nigerian-regulated entities
- Establish relationships with ngCERT and sector regulators before an incident occurs
- Assess supply chain risk — vendors and partners operating in Nigeria may face new obligations that affect shared data
As African digital economies grow and regulatory frameworks mature, compliance obligations for multinationals operating on the continent will continue to expand.