📖 ABSTRACT/OVERVIEW
Telecommunications companies in Nigeria operate critical national information infrastructure and face sophisticated and persistent cyber threats, yet the security management practices in place across the sector have not been comprehensively professionally assessed. This study examines information systems security management in Nigerian telecommunications companies. A professional assessment methodology was applied, combining a structured security controls questionnaire (aligned with ISO 27001 Annex A and the NCC Cybersecurity Framework for Telcos) administered to security managers at eight major and tier-two telecom operators, with five supplementary expert interviews. Control implementation rates were analysed across thirteen security domains. Findings indicate strong performance in physical and environmental security, access management, and communications security, reflecting the operational maturity of the sector. Significant gaps were identified in supplier relationship security (assessed thoroughly by only 38 percent of operators), security incident response testing (conducted annually by only 50 percent), and cryptographic controls policy formalisation. All assessed operators experienced at least one significant security incident in the past two years, with SIM-swapping fraud being the most prevalent attack vector. The study concludes that Nigerian telcos demonstrate foundational security maturity but require improvements in third-party risk management, incident response practice, and customer authentication security. A Telecommunications Sector Security Improvement Roadmap is proposed for adoption by the Nigerian Communications Commission.
Keywords: information security, telecommunications, Nigeria, ISO 27001, NCC cybersecurity
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬