Connect with us

E-Business

NITDA Clarifies Regulatory Infractions Allegation By ALTON

Published

on

Isa Pantanmi, NITDA DG
Kindly share this post

The National Information Technology Development Agency (NITDA) has cleared the air on the allegations made by Association of Licensed Telecommunication Operators of Nigeria (ALTON) that it engages on regulatory infractions.

 

Emmanuel Edet Esq, head, Legal Services & Board Matters, National Information Technology Development Agency, made the clarifications in a statement released on Wednesday in Abuja.

 

According to the statement, “The attention of the National Information Technology Development Agency (NITDA) has been drawn to a publication ascribed to the President of the Association of Licensed Telecommunication Operators of Nigeria (ALTON) published in the media regarding certain regulations and guidelines issued by the Agency.

Advertisement

 

For avoidance of doubt, NITDA has enjoyed a cordial and cooperative relationship with all sector regulators and we have consistently engaged them on all regulations and guidelines issued by the Agency.  In this vein, NITDA has significantly socialized the Nigeria Data Protection Regulation (NDPR) 2019 and the Public Internet Access Regulation 2019 as referenced in the publication. The Agency is delighted with the support of several institutions in complying and promoting these regulations.

 

For clarity, no single regulator in Nigeria has a converged mandate on ICT in the country. Various Agencies have different roles to play in developing and regulating ICT in Nigeria as dictated by their mandates and enabling laws. Furthermore, no single entity is regulated by only one regulator in Nigeria, regulators in the country work in a cooperative and complementary capacity, resolving mandate overlaps in a cooperative manner.  ALTON, as with various industry groups, are expected to comply with various professional, sector, geographical and international regulators when their operations so demand. This understanding has been shared between NITDA and other regulators in Nigeria.

 

Advertisement

It may be recalled that NITDA issued five regulatory instruments on the 25th January, 2019, two of which were referenced in the publication. We wish to draw the attention of the public to the following:

 

  • The Framework and Guidelines for Public Internet Access(PIA) 2019 was issued to ensure the safe use of free or subsidized publicly accessible internet service in Nigeria. NITDA has been inundated by concerned stakeholders to check the regime of publicly accessible internet service considering its national security dimensions.

 

The Framework and Guidelines aims to create and promote a mutually beneficial and friendly environment for both public internet access providers and users in Nigeria. The Regulation is directed at Public Internet Access Providers (PIAPs). PIAPs include any business or other entity that provide internet access without charge or offers a partially subsidized internet access to members of the public. The concerns which NITDA aims to address through this regulatory instrument are:

 

  • Cyber security and cyber crime;
  • Personal data breaches; and
  • Crime detection, prevention and investigation.

 

NITDA is enabled to address these concerns by virtue of Section 6(c) and (m) of the NITDA Act which mandates the Agency to provide Guidelines for  electronic data interchange in Nigeria and to accelerate internet and intranet penetration in Nigeria and promote sound internet Governance.

Advertisement

 

  • The Directives for Registration of Data Centre Facilities in Nigeria was issued pursuant to Section 6 of the NITDA Act 2007 which empowers the Agency to:

 

  • Create a framework for the planning, research, development, standardization, application, coordination, monitoring, evaluation and regulation of Information Technology practices, activities and systems in Nigeria and all matters related thereto…;and
  • Create incentives to promote the use of information technology in all spheres of life in Nigeria including the development of guidelines for setting up of information technology systems and knowledge parks.

 

Data Centre operations are principally information technology systems which support the entire IT value-chain. Reference to Executive Orders 003(2017) and 005(2018) mainly cites the added Presidential Directives on local content promotion. The fundamental mandate arises from the NITDA Act which has been cited above. Furthermore, the Guidelines for Nigerian Content Development in ICT (2019)explicitly provides:

 

Data and Information Management Companies shall:

  1. Register their products, capabilities and organization on the NITDA portal. The service will be provided free of charge and devoid of bureaucracy and will ensure NITDA awareness of available resources.
  2. Host government data locally within the country and shall not for any reason host any government data outside the country without an express approval from NITDA and the SGF.

 

The Nigerian Content Guidelines is a salutary example of regulatory cooperation between NITDA and ICT stakeholders to promote Local Content in Nigeria. The above provisionsanticipate the role of NITDA in the regulation and promotion of Data Centers in Nigeria. The Agency is not averse to any Regulator demanding compliance as it relates to the operation of Data Centers that touches on the Regulator’s mandate. Interestingly, Data Center operators have openly commended NITDAfor the improved enforcement of regulations and policies which has led to significant increase in Data Centre patronage in the last three years.

Advertisement

 

  • The report further purports to take issues with the classification of Internet Protocol address, IMEI number, IMSI number etc. as personal data under the Regulation. The report assumes this amounted to usurpation of the NCC’s regulatory mandate. This is a patent misreading of regulatory frameworks. In the absence of a National Assembly-enacted legislation on Data Protection, Section 6 (c) of the NITDA Act 2007 specifically empowers the Agencyto:

“Develop guidelines for electronic governance and monitor the use of electronic data interchange and other forms of electronic communication transactions as an alternative to paper-based methods in government, commerce, education, the private and public sectors, labour, and other fields, where the use of electronic communication may improve the exchange of data and information.”

 

Furthermore, NITDA was established to implement the National IT Policy of 2000. Article 5(xix) of the Policy provides…Government will establish a National Information Technology Development Agency to implement the IT Policy, regulate, monitor, evaluate and verify progress on an ongoing basis…

 

Also, Strategy 13.3(iii) of the Policy further provides …Ensure the protection of individual and collective privacy, security, and confidentiality of information…

Advertisement

 

While it is global practice for sector regulators to give sector specific directives and regulations on how certain issues are to be addressed, this does not restrict the right of Government Agencies to issue regulations which cover the field as is the case in this matter. NITDA is in active collaboration with all sector regulators to ensure full compliance with the NDPR. The aggregate consensus of most stakeholders is that the NDPR is a laudable regulation which would further improve the Nigerian business environment and help attract foreign direct investment.

 

Finally, we advise that it is not in the strategic interest of interest groups to attempt to set Government Agencies against each other just because of its short-term benefits. NITDA is clear about its mandate as provided bythe enabling law and will not be overawed by powerful interest groups to implement its mandate which is to the overall benefit of all Nigerians.It should also be noted that violation of the Regulatory Instruments of NITDA is a criminal offence and punishable with fine, imprisonment or both.”

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

Kaspersky Uncovers Cyber Threats Defining the First Half of 2026 in Nigeria, Others

Published

on

Kindly share this post

Kaspersky’s Global Research & Analysis Team (GReAT) reveals key cyber threat trends for the first half of 2026 at the recent Cyber Security Weekend for the Middle East, Turkiye and Africa region (META).

As the cybersecurity landscape continues to evolve, cyberthreats are becoming increasingly diverse and sophisticated. The rapid adoption of artificial intelligence (AI), coupled with ongoing geopolitical and economic instability, is contributing to the rise of cybercrime and the growing complexity of cyberattacks.

According to Kaspersky’s telemetry, online threats exploiting vulnerabilities in websites, emails and web services continued to affect millions of users across the META region during the first half of 2026.

Specifically, Kaspersky detection systems stopped 1,6M attacks from various online resources in Nigeria. Turkiye recorded the highest percentage of users affected by web-based threats at 22.8%, followed by Kenya (21.2%), Qatar (19.3%), Nigeria (18.4%) and South Africa (17.2%). In contrast, Saudi Arabia, Jordan and Pakistan registered the lowest share of users targeted by web-borne attacks in the region.

AI is transforming attacker operations

Advertisement

Kaspersky experts report that threat actors are increasingly integrating AI into different stages of their operations. Large language models are already being used to generate phishing emails, malicious code and supporting operational content.

AI is also beginning to play a larger role in malware development. Modern language models are capable of generating substantial portions of malicious software, from initial code scaffolding to functional modules.

Researchers have already observed AI-assisted malware development in campaigns linked to the FunkSec group, which deployed Rust-based malware capable of data theft, encryption and process manipulation. Similarly, during the RevengeHotels campaign in 2025, threat actors used large language models to generate portions of the infector and downloader code.

“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” said Sergey Lozhkin, Head of Global Research and Analysis Team in APAC and META regions at Kaspersky. “By lowering the time and cost required to develop and adapt malicious tools, AI allows threat actors to iterate faster and scale their efforts. Defenders should be prepared for quicker shifts in tactics.”

Emerging trends shaping the cyber threat landscape

Advertisement

In addition to the growing use of AI by cybercriminals, Kaspersky experts identified several trends that organisations should monitor closely:

  • AI-driven malware evolution: generative models can rewrite malware in different languages or architectures, making malicious code harder to detect, and faster to deploy at scale.
  • Cloud-based data exfiltration: attackers increasingly route stolen data through legitimate cloud and file-sharing services to blend in with normal traffic.
  • Ransomware targeting operations: some groups disrupt production and business processes, not just encrypt data, to increase pressure for payment.
  • AI agents as persistence mechanisms: some AI agent solutions are granted broad or even full system access. If compromised, attackers could modify the system prompt or the agent’s configuration, for example, causing it to download a payload on every startup.
  • Malicious AI skills become a new attack vector: as AI agents gain broader access to enterprise systems, attackers start to exploit compromised skills to manipulate agent behaviour, steal sensitive data, execute unauthorised actions, and establish persistent access. This creates a new layer of risk where trusted AI tools can be turned into powerful mechanisms for cyberattacks.

As cyberthreats continue to evolve alongside emerging technologies, Kaspersky recommends that organisations strengthen their cybersecurity posture through continuous vulnerability management, timely patching, employee awareness training, threat intelligence, and advanced security solutions like Kaspersky Next, capable of detecting sophisticated and AI-assisted attacks.

 

Kindly share this post
Continue Reading

E-Business

Kaspersky Uncovers New Mirage Kitten Malware Used in Cyber-espionage Campaign Across Africa, Others

Published

on

Kindly share this post

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The findings were revealed at its annual Kaspersky Cyber Security Weekend for the Middle East, Turkiye and Africa (META).

The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organisations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organisations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioural similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.

It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network.

Advertisement

This lets them slip past network defences and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReAT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organisation in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods.

The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa.

“Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts.

Advertisement

“Given the persistence and sophistication of these techniques, organisations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.

 

Kindly share this post
Continue Reading

E-Business

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has directed all Data Controllers and Data Processors of Major Importance (DCPMIs), yet to register with the commission to do so immediately.

NDPC Directs DCPMIs to Register with Agency or Face Legal Consequences

This followed a Federal High Court judgment affirming NDPC statutory powers to designate and register such entities.

DCPMIs are entities operating in Nigeria that handle sensitive personal data or large volumes of information, requiring mandatory registration with the NDPC under the Nigeria Data Protection Act (NDPA).

In a statement issued on Tuesday by Babatunde Bamigboye, head of Legal, Enforcement and Regulations at the NDPC,  described the judgment as a major milestone for data accountability and regulatory oversight in Nigeria.

The commission said the ruling arose from a suit filed by Emmanuel Harunna against the NDPC in Emmanuel Harunna v. NDPC (FHC/L/CS/1116/2024), in which the applicant sought a declaration that Point of Sale agents were not Data Controllers or Processors of Major Importance under the Nigeria Data Protection Act and requested a perpetual injunction restraining the commission from registering them.

Advertisement

According to the statement, Justice F.N. Ogazi examined the commission’s Guidance Notice on Registration alongside Sections 5(d), 6(c), 44, 45 and 65 of the Nigeria Data Protection Act before concluding that the commission acted within its statutory powers in designating entities under the Major Data Processing – Ordinary High Level category as Data Controllers and Processors of Major Importance.

Quoting the judgment, the statement read, “The Nigeria Data Protection Act was enacted to promote accountability, transparency and responsible data governance. Registration enables the Respondent to identify entities engaged in significant data processing activities, monitor compliance.”

It added that the court held that, “Far from undermining the constitutional right to privacy, the registration framework is one of the statutory mechanisms designed to safeguard that very right by subjecting data controllers and data processors to effective regulatory oversight.”

The statement further quoted the court as saying, “Looking at the recitals of the Guidance Notice, there is every indication that the Guidance Notice is also aimed at protecting the privacy and security of data subjects, thus bringing the registration requirement of the Guidance Notice within the protective shield of Section 45 of the 1999 Constitution.”

According to the commission, the court also held that, “Remarkably, Section 63 of the Data Protection Act provides that the provisions of the Act shall prevail over any other law inconsistent with its provisions on matters relating to the processing of personal data.”

Advertisement

Reacting to the judgment, the commission described the decision as a significant boost to Nigeria’s data protection regime.

“The Commission appreciates the ground-breaking efforts of the court towards the advancement of the jurisprudence relating to data accountability in Nigeria, as eloquently demonstrated in this case,” the statement read.

Following the ruling, Vincent Olatunji, national commissioner and chief executive officer, had directed every Data Controller and Processor of Major Importance that had yet to comply with the registration requirement to register without delay.

The commission warned that entities failing to comply with the registration requirement could face legal consequences.

“Failure to register creates serious legal liabilities under the law, while compliance with registration requirements builds public trust and safeguards the fundamental rights and freedoms of data subjects in Nigeria,” the statement added.

Advertisement

 

Kindly share this post
Continue Reading

Trending