📖 ABSTRACT/OVERVIEW
Internet Service Providers are critical nodes in Nigeria's digital infrastructure and are subject to NCC cybersecurity compliance requirements, yet systematic assessment of their compliance status provides important evidence for regulatory enforcement and consumer protection policy. This study professionally assessed cybersecurity compliance among Nigerian Internet Service Providers operating in Lagos, Abuja, and Kano, representing the South West, North Central, and North West zones. A structured compliance assessment methodology was applied, combining review of NCC Quality of Service and Cybersecurity regulations, structured interviews with IT security managers from 12 licensed ISPs across the three cities, and technical compliance verification against NCC minimum cybersecurity requirements. Assessment covered network security architecture, incident reporting compliance, customer data protection, abuse response procedures, and staff security training. Results showed that NCC cybersecurity minimum requirements were fully met by only 41.7 percent of assessed ISPs. Incident reporting to NCC within required timelines was achieved by 50.0 percent. Customer data protection practices met minimum standards in 58.3 percent. Abuse and phishing complaint response procedures were documented in 66.7 percent. Staff cybersecurity training was conducted annually in 58.3 percent. The study concludes that ISP cybersecurity compliance is inconsistent and below full regulatory standard. Recommendations include NCC enforcement action against non-compliant ISPs, mandatory security audit submission for licence renewal, and a public-facing ISP security compliance rating system to drive consumer choice accountability.
Keywords: ISP cybersecurity compliance, NCC regulation, Nigeria, network security, internet service provider
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬