Protection of Critical National Information Infrastructure Against Cyber Attacks: An Evaluation of The Legal and Regulatory Framework in Nigeria

KELVIN BRIBENA

Abstract


The rapid digital transformation of contemporary societies has made information systems and communication networks essential components of national security, economic development, public administration and social stability. In Nigeria, critical sectors including banking, telecommunications, energy, healthcare, defence, transportation and government administration increasingly depend on interconnected digital infrastructure. While this digital dependency has enhanced efficiency and innovation, it has simultaneously created significant vulnerabilities to cyber attacks capable of disrupting essential services, compromising sensitive information and undermining national security. Critical National Information Infrastructure (CNII) has therefore emerged as a strategic national asset requiring effective legal protection. This study evaluated Nigeria’s legal and regulatory framework for protecting Critical National Information Infrastructure against cyber attacks. It examined the constitutional foundations of cybersecurity protection, by examining the extant laws like the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 as amended in 2024 and other relevant institutions including sector-specific regulators. The study employed the doctrinal research methodology by evaluating primary and secondary sources of relevant laws and declassified policy documents. The study found that although Nigeria has established important legal foundations for cybersecurity governance, the current framework remains too fragmented and inadequate to address the complexity of contemporary cyber threats targeting critical national information infrastructure. The study identified major weaknesses including the absence of a dedicated Critical National Information Infrastructure Protection Act, insufficient cybersecurity obligations for infrastructure operators, weak incident reporting mechanisms, institutional overlap, limited technical capacity and challenges associated with cross-border cybercrime enforcement. The study concluded with recommendations that Nigeria’s ability to protect its critical digital infrastructure will depend on moving beyond a reactive cybercrime framework towards a comprehensive and preventive governance model capable of securing digital infrastructure while protecting constitutional rights and supporting technological innovation.

Keywords: Critical National Information Infrastructure, Cybersecurity, Cyber Attacks, Nigeria, Cybercrime Law, National Security, Data Protection, Digital Infrastructure.

DOI: 10.7176/JLPG/152-10

Publication date: May 28th 2026


Full Text: PDF
Download the IISTE publication guideline!

To list your conference here. Please contact the administrator of this platform.

Paper submission email: JLPG@iiste.org

ISSN (Paper)2224-3240 ISSN (Online)2224-3259

Please add our address "contact@iiste.org" into your email contact list.

This journal follows ISO 9001 management standard and licensed under a Creative Commons Attribution 3.0 License.

Copyright © www.iiste.org