The Lesotho Communications Authority (“the LCA” or “the Authority”) has published its Cybersecurity Regulatory Guidelines, Version 1.0, dated March 2025 and classified TLP: CLEAR. For mobile network operators, internet service providers, infrastructure network providers and other players in Lesotho’s communications sector, the document is the clearest statement yet of what the regulator expects of a licensee’s cybersecurity posture, and, importantly, what documentary evidence it expects to see when it asks.
The Guidelines are short. Their consequences are not. Below we set out what they require, where the legal position is less settled than the drafting suggests, and what licensees should be doing in the meantime.
1. What the Guidelines are
The Guidelines are a framework document grounded in two international standards: the NIST Cybersecurity Framework and ISO/IEC 27001. They are organised into eleven substantive areas, running from governance and risk management through to awareness and training, and they close with a Security Measures and Evidence Table that maps each obligation to the evidence a licensee is expected to hold.
Their stated objectives are to strengthen sector resilience, align Lesotho with international best practice, promote awareness, mitigate risk, integrate physical and operational security, and strengthen governance.
2. Who is caught
The Introduction is directed at “Mobile Network Operators (MNOs), Infrastructure Network Providers, Internet Service Providers (ISPs), and other players in the Communications Sector in Lesotho.”
The operative provisions, however, are addressed throughout to “Licensees” a term the Guidelines use more than forty times but nowhere define, notwithstanding a detailed definitions section that does define “MNO” and “ISP.”
That gap matters. The LCA licenses a broad spectrum of activity: network and service operators, broadcasters, postal operators and various classes of value-added service provider. On the plain wording, a small community broadcaster would carry the same obligation to appoint a CISO, commission annual third-party penetration testing and maintain a documented DLP capability as a national mobile operator. That cannot have been the intention, and licensees at the smaller end of the market should not assume the burden is proportionate until the Authority says so.
Practical point: where scope is unclear, the answer is not silence. Licensees who consider themselves out of scope, or entitled to a lighter application, should say so in writing to the Authority and keep the record.
3. “Guidelines” but drafted as obligations
This is the question our clients ask first, and it is a fair one.
The document is titled Guidelines. Version 1.0 is described in its own revision history as a “First working document.” Neither feature suggests subordinate legislation.
Against that, the operative provisions are drafted almost entirely in the language of obligation: licensees “shall” develop a cybersecurity policy, “shall” conduct risk assessments, “shall” appoint a CISO, “shall” submit an implementation plan to the Authority. There is no “should” where it counts.
In our view the position is best understood as follows:
- The Guidelines are not, of themselves, regulations. They do not appear to have been made and gazetted as subsidiary legislation under the Communications Act 2012.
- They are nonetheless capable of acquiring binding force indirectly most obviously if the Authority incorporates them into licence conditions, makes compliance a condition of licence renewal or amendment, or treats them as the standard against which a licensee’s conduct is assessed following an incident.
- Independently of enforcement, they establish a documented standard of reasonable care for the sector. Once a regulator has published what good looks like, a licensee that suffers a breach while falling short of that standard is in a materially weaker position, before the Authority, before a court in a delictual claim, and before its own insurers.
Treating the Guidelines as optional because of the word on the cover is, therefore, a poor risk assessment.
4. The eleven obligation areas in summary
| Area | Core requirement |
|---|---|
| Governance and risk management | Board-approved cybersecurity policy aligned to ISO 27001 or NIST CSF; regular risk assessments; a governance structure or steering committee; a tested Business Continuity Plan; defined roles; segregation of duties; third-party risk management |
| Incident management and threat intelligence | Documented incident response plan with regular drills; reporting protocols to internal stakeholders and external authorities including the sectoral or national CSIRT; participation in information-sharing communities |
| Physical security | Controlled access to data centres, server rooms and network operations centres; surveillance, alarms, biometric access control and environmental controls |
| Access control | RBAC and least privilege; MFA for sensitive systems and privileged accounts |
| Operational security | Firewalls, IDS/IPS, endpoint protection, patching; continuous network monitoring; regular audits and vulnerability assessments; formal change management |
| Data protection | Redundancy and backup for availability; encryption at rest and in transit; DLP solutions |
| Asset management | Current inventory of hardware, software and data assets; classification by criticality and sensitivity |
| Network and information systems security | Firewall and IDS/IPS deployment at key network points; network segmentation, including separation of backup from production; tested backup and recovery |
| Continuous monitoring | SIEM and real-time monitoring capability |
| Audit and compliance | Periodic internal audits and penetration testing; annual external audits and penetration tests by a qualified third party; continuous compliance monitoring |
| Awareness and training | Training for all personnel including the board of directors; customer education; continuous technical training with encouragement toward CISSP, CEH or CISM certification; appointment of a CISO or equivalent; a dedicated security team |
Two further requirements sit in the Implementation section: licensees must implement in phases beginning with critical infrastructure, and must develop and submit an implementation plan to the Authority.
5. The Evidence Table is the part to read twice
Section 6 of the Guidelines is, in substance, the LCA’s audit checklist. For each measure it specifies the artefacts expected, approved policy documents, risk registers with threat and vulnerability ratings, organisational charts and governance committee minutes, BCP recovery testing results, RBAC matrices and access review reports, MFA logs, incident response team rosters and simulation records, communications with regulatory authorities, CCTV footage and visitor logs, network architecture diagrams showing firewall placement, VLAN configuration records, encryption key management procedures, DLP alert reports, training attendance records and certification records.
The practical implication is straightforward: compliance here is evidentiary, not merely operational. A licensee with excellent controls and poor documentation will present as non-compliant. Most of the remediation work we see in this area is not buying technology; it is reducing existing practice to writing, dating it, and having it approved by the right body.
6. How the Guidelines interact with the rest of Lesotho law
The Guidelines do not operate in isolation, and licensees should not read them as a self-contained compliance universe.
- Computer Crime and Cyber Security Act 2019. Lesotho’s cybercrime legislation and the institutional architecture around the national CSIRT sit behind the incident-reporting obligations in the Guidelines. A single incident may trigger obligations under both instruments.
- Data Protection Act 2011. The encryption, DLP and access-control requirements substantially overlap with a licensee’s obligations as a data controller. Where an incident involves personal data, licensees should expect a dual reporting analysis, to the Authority and to the data protection regulator and should build that branch into the incident response plan now rather than during an incident.
- Companies Act 2011. The requirements for board training, a governance structure and a CISO reporting line convert cybersecurity from an IT matter into a directors’ duty-of-care matter. Board minutes should reflect that the Guidelines were considered, that a compliance position was adopted, and on what basis.
- Licence conditions and consumer protection rules. Customer awareness obligations under section 4.11.2 overlap with existing consumer-facing duties. There is scope to satisfy both through a single, well-recorded programme.
- Group and cross-border arrangements. Section 4.1.7 requires due diligence, contractual security requirements and ongoing monitoring of third-party vendors. For the many Lesotho licensees whose IT, hosting, security operations or managed services are provided by a South African parent, affiliate or vendor, the intra-group provider is a third-party dependency. Existing service agreements will frequently need security schedules, audit rights, incident-notification timelines and flow-down obligations that they do not currently contain. This is contract work, and it is usually the longest lead-time item on the list.
7. Gaps worth raising while the document is still a working draft
Version 1.0 is expressly a first working document, and the Authority has reserved the right to update it. That makes now the time for licensees and industry bodies to engage. The following are, in our view, the points most worth putting to the Authority:
Substantive gaps
- “Licensee” is undefined, and the Guidelines contain no proportionality mechanism distinguishing systemically important operators from small licensees.
- “Promptly” is the only incident-reporting deadline. Comparable regimes specify a fixed period commonly 24 or 72 hours and distinguish initial notification from a full report. Licensees currently cannot know when they are late.
- The implementation plan required by section 5.1 has no deadline, no prescribed format and no approval process. Licensees do not know when to submit, what it must contain, or whether the Authority’s silence constitutes acceptance.
- No transitional period or commencement date is specified for the substantive obligations.
- No enforcement or sanction framework is articulated, which is precisely why the legal status question in section 3 above remains live.
- Sections 4.11.4 and 4.11.5 the CISO appointment and dedicated security team requirements appear under the heading “Cybersecurity Awareness and Training” and do not appear in the table of contents at all. These are among the most consequential obligations in the document and are structurally misplaced.
8. What licensees should do now
- Gap analysis against the Evidence Table, not against the narrative sections. Ask, for each row: do we hold this artefact, is it current, and is it approved?
- Fix the documentation deficit first. Policy, risk register, BCP, incident response plan, asset inventory and classification. These are low-cost, high-visibility, and they are the first things a regulator asks for.
- Appoint the CISO or equivalent and record the appointment, with a defined reporting line to the board.
- Take the incident response plan to the Authority’s standard, including the dual-reporting branch for personal data incidents and a documented drill.
- Review third-party and intra-group contracts for security schedules, audit rights and notification obligations. Begin here if resources are constrained, because contract renegotiation takes the longest.
- Budget for the annual external audit and penetration test. It is an express requirement and requires a qualified third party.
- Prepare the implementation plan, phased and prioritising critical infrastructure, and submit it with a covering letter recording the licensee’s position on scope and timing.
- Minute the board’s consideration of the Guidelines and the compliance approach adopted.
- Engage on the gaps individually or through industry structures while Version 1 remains open for revision.
How we can assist
Mayet & Associates Inc. advises operators, service providers and their South African parent companies on Lesotho regulatory compliance, licensing and cross-border commercial arrangements. We assist with:
- gap analyses and compliance roadmaps against the LCA Guidelines;
- drafting cybersecurity policies, incident response plans and board governance frameworks;
- reviewing and renegotiating third-party, vendor and intra-group service agreements to meet section 4.1.7;
- incident response advice, including regulatory notification strategy across the LCA and data protection regimes; and
- engagement and correspondence with the Authority, including submissions on the Guidelines.
Contact us to arrange a scoping discussion.
This article is provided for general information and does not constitute legal advice. The Cybersecurity Regulatory Guidelines Version 1.0 (March 2025) is a working document and may be revised. Readers should obtain advice specific to their licence class and circumstances.