Liberia's cyber-resilience posture for the private-sector duty-bearer rests on one narrow, sector-scoped safeguards duty inside its general telecommunications law, set against a much larger 2026 legislative wave whose operative text is not read here.
Section 51(5) of the Telecommunications Act 2007 requires a telecommunications service provider, whether the state-linked Liberia Telecommunications Corporation or a privately licensed operator, to protect customer information and customer communications in its custody with security safeguards appropriate to their sensitivity, a duty the Liberia Telecommunications Authority (LTA) enforces through its general investigatory and sanctioning powers and that the Act's own civil-liability section backs with a right of action for a customer who suffers loss from its breach.
President Joseph Nyuma Boakai signed the Cybercrime Act of 2025 into law on July 3, 2026, but the Ministry of Foreign Affairs' gazetted printing carries a text layer only on its cover page; every independent account of the Act's contents, an August 2026 disclosure by Post and Telecommunications Minister Sekou Kromah and a January 2026 report on the Senate's concurrence, describes it as criminalizing unauthorized access, digital fraud, identity theft, illegal interception and data misuse, establishing a Liberia National Cyber Security Council, and committing Liberia to the Budapest and Malabo Conventions, the intruder-offense and institutional-coordination shape the scraping topic covers rather than a duty on an operator's or manufacturer's own security posture, but the Act's own unread chapters leave that a researched gap rather than a settled absence.
The LTA has separately published a document titled Cybersecurity Regulations, dated February 2026, among its regulations for LTA licensees, but that PDF carries no extractable text beyond its filename, so its content is not described here.
President Boakai also signed Liberia's first Data Protection Act, officially titled "An Act for the Collection, Processing, Transmission, Storage, Protection, and Use of Personal Information in Liberia," on March 9, 2026; any security-of-processing duty it carries sits in Liberia's privacy-topic row rather than here, and its own gazetted printing has the same cover-page-only text layer.
No Central Bank of Liberia directive, regulation or guideline on its published Directives list or the first page of its Regulations list names cybersecurity or information-technology risk; the one CBL directive with "security" in its title, a 2010 Directive Concerning Security and Surveillance System at Financial Institutions, addresses physical premises security rather than systems security.
No Liberian instrument sets a general reasonable-security or information-security-programme baseline reaching a business with no sector gate, and no product-placement or market-entry security requirement for a connected device or software product is recorded here.