CYBERCRIMES (PROHIBITION, PREVENTION, ETC) AMENDMENT ACT, 2024
Section 21: Reporting of cyber threats (As amended by section 3 of the Cybercrimes (Prohibition, Prevention, etc.) Act, 2024)
1 A person or institution who operates a computer system or a network, whether public or private, shall immediately inform the National Computer Emergency Response Team (CERT) Co-ordination Center of any attack, intrusion and other disruption liable to hinder the functioning of another computer system or network, so that the National Computer Emergency Response Team Coordination Center through their respective sectoral CERTs or sectoral Security Operations Centres (SOC) can take the necessary measures to tackle the issues.
2 In such cases mentioned in sub-section (1) of this section, and in order to protect computer systems and networks, the National CERT Coordination Center may propose the isolation of affected computer systems or network pending the resolution of the issues.
3 A person or institution who fails to report any such incident to the National CERT within 72 hours of its detection, commits an offence and is liable to denial of internet services, and such persons or institution shall, in addition, pay a mandatory fine of =N2,000,000.00 into the National Cyber Security Fund.
Cite this section
Section 21, CYBERCRIMES (PROHIBITION, PREVENTION, ETC) AMENDMENT ACT, 2024 (2024).
https://repo.podus.ai/laws/cybercrimes-prohibition-prevention-etc-amendment-act-2024/section/21/