NITDA Releases Cyber Hygiene Guidelines as Nigeria Marks Cybersecurity Awareness Month 2026

The National Information Technology Development Agency (NITDA) has released a set of essential cyber hygiene recommendations for Nigerians as the country marks the 2026 National Cybersecurity Awareness Month, urging individuals, businesses and public institutions to take greater responsibility for protecting their digital information.

The month-long campaign, themed “Together for a Safer Cyberspace,” seeks to strengthen public awareness of evolving cyber threats and encourage safer online behaviour as digital technology becomes increasingly central to communication, commerce, financial services and public administration.

NITDA warned that the growing use of artificial intelligence (AI) and automated technologies has created new opportunities for cybercriminals, including AI-driven social engineering, deepfake impersonation, voice cloning and fraudulent QR-code attacks, commonly known as quishing.

The agency stressed that cybersecurity is no longer solely the responsibility of technology professionals and security agencies. Instead, individuals and organisations must adopt practical measures to protect their accounts, devices and sensitive information.

Strong Passwords and Multi-Factor Authentication

One of NITDA’s key recommendations is the use of strong, unique passwords across online accounts. Reusing the same password for email, banking, social media and other services can increase exposure if one account is compromised.

The agency also encouraged users to consider reputable password managers to generate and securely store complex passwords.

Additionally, Nigerians were advised to enable multi-factor authentication (MFA) on personal, professional and financial accounts wherever available. This security measure requires an additional verification step beyond a password, making unauthorised access more difficult.

These precautions are particularly important for email accounts, which may provide access to password-reset links and other services connected to a user’s digital identity.

Keep Devices and Software Updated

NITDA urged Nigerians to install software updates and security patches promptly on smartphones, computers and other connected devices.

Updates frequently address vulnerabilities that attackers could exploit to gain access to systems or compromise personal information. Delaying them can leave devices exposed to known security weaknesses.

Users should also download applications from trusted sources and remove software they no longer need, particularly unfamiliar applications that request excessive permissions.

For businesses and public institutions, regular updates should form part of a wider security programme that includes access controls, system monitoring and tested data-recovery procedures.

Never Share PINs, OTPs or Banking Credentials

The agency cautioned Nigerians against disclosing sensitive financial information, including one-time passwords (OTPs), personal identification numbers (PINs) and online banking login details.

Cybercriminals may impersonate bank employees, customer service representatives, government officials or trusted contacts to persuade victims to reveal these details.

NITDA advised users to verify suspicious requests independently rather than relying on the identity presented by a caller, text message or online profile.

When a message claims that an account will be blocked unless immediate action is taken, users should avoid rushing into a response. Instead, they should contact the relevant organisation through its official channels.

The agency’s warning reflects the growing sophistication of social engineering, in which criminals manipulate trust and urgency to persuade people to reveal information or authorise fraudulent transactions.

AI, Deepfakes and Voice-Cloning Scams

NITDA placed particular emphasis on emerging threats associated with artificial intelligence.

Deepfake videos and cloned voices can make fraudulent communications appear convincing, including messages that seem to come from relatives, colleagues, business executives or public figures.

Consequently, users should not treat a familiar voice, recognisable face or apparently authentic video as conclusive proof of identity.

Where a request involves transferring money, sharing confidential information or approving an unusual transaction, independent verification is essential. People can contact the individual through a known number or use an agreed verification method before taking action.

The agency also advised Nigerians to exercise caution when using public AI models and unfamiliar online platforms, particularly when sensitive personal, financial or corporate information is involved.

Submitting confidential documents, customer records or internal business information to an untrusted service can create privacy and security risks.

Verify Links, QR Codes and Unsolicited Messages

Another important recommendation concerns suspicious links, email attachments and unsolicited requests for information.

NITDA urged users to examine communications carefully before clicking links, downloading files or entering login details. Fraudulent messages may imitate legitimate websites, payment services or delivery notifications to steal credentials and financial information.

QR-code fraud, or quishing, presents a similar risk. Criminals can use deceptive QR codes to direct victims to malicious websites or fraudulent payment pages.

Before scanning an unfamiliar code, users should consider its source and whether the accompanying request is expected. After scanning, they should inspect the destination before entering personal information or authorising a payment.

When in doubt, accessing a service through its official application or manually entering its verified web address can reduce the risk of being redirected to a fraudulent platform.

Protect Personal Information and Back Up Important Data

NITDA also encouraged responsible social media use, warning that excessive disclosure of personal information could provide criminals with material for targeted scams and impersonation.

Public posts may reveal details about relationships, workplaces, travel plans and other personal circumstances that criminals can use to make fraudulent messages more believable.

Users should therefore review privacy settings and limit the information they share publicly.

The agency further recommended regular offline and cloud backups of important data. Backups can help individuals and organisations recover files following ransomware attacks, device failures or other disruptions.

For organisations, backups should be protected against unauthorised access and tested periodically to confirm that information can actually be restored when needed.

NITDA-CERRT Supports Cyber Incident Response

Through its Computer Emergency Readiness and Response Team, NITDA provides cybersecurity awareness, threat advisories and incident-response guidance to support individuals and organisations.

Members of the public can access cybersecurity resources through the team’s official website at cerrt.nitda.gov.ng. For incident reporting and enquiries, the published contact details include cerrt@nitda.gov.ng and +234 817 877 4580.

NITDA also encouraged Nigerians to follow its official communications channels for cybersecurity awareness tips and updates on emerging threats.

Building a Safer Digital Nigeria

The 2026 campaign highlights the importance of making cybersecurity a routine part of digital life rather than a concern addressed only after an attack.

Strong passwords, multi-factor authentication, updated devices, careful handling of financial credentials and independent verification of suspicious communications can all help reduce exposure to common threats.

For businesses and public institutions, these habits should be supported by staff training, appropriate security controls, incident-response plans and reliable data backups.

Ultimately, protecting Nigeria’s increasingly digital economy requires shared responsibility. As more citizens rely on online services for work, education, banking and communication, the ability to recognise threats and respond safely will remain essential to building a more secure and resilient cyberspace.