Kenneth Nnorom Logo
Kenneth Nnorom
Engineering & Law

The T-Shaped Engineer: An Engineer's Guide to Law in Nigeria

The Day a Router Command Became a Civil Rights Issue In June 2021, ISPs received directives across Nigeria to block Twitter at the network layer

The Day a Router Command Became a Civil Rights Issue

In June 2021, ISPs received directives across Nigeria to block Twitter at the network layer. For most of them, it was a routine Access Control List (ACL) update. A few lines of configuration, a policy applied, a ticket closed.

What happened next was anything but routine. The Socio-Economic Rights and Accountability Project (SERAP) filed a lawsuit against the Federal Republic of Nigeria, arguing that the ban violated constitutionally guaranteed rights to free expression. The case, SERAP v. Federal Republic of Nigeria, ended with a court ordering the government to restore access. Just like that, the ACL list has become evidence in a courtroom.

That moment reinforced something I had thought about as an engineer. You can design brilliant systems, systems that live in the real world, one shaped by contracts, regulations, and fundamental human rights. Your technical decisions carry legal weight, whether you understand that weight or not.

This is precisely where the concept of the T-shaped engineer becomes essential.


What Is a T-Shaped Engineer?

The term, originally popularised by IDEO CEO Tim Brown in the context of design thinking, describes a professional with deep expertise in one discipline (the vertical bar of the T) combined with broad, working knowledge across adjacent fields (the horizontal bar). In engineering, that vertical bar is your technical speciality. The horizontal bar is everything that surrounds it. The business, policy, communication, and increasingly, law.

For Nigerian engineers specifically, this horizontal bar is no longer optional. We are building the infrastructure that will carry Nigeria’s next decade of economic growth. The stakes are too high for purely technical thinking.


We engineers, love frameworks. They bring order to complexity. The OSI model, for instance, does not just describe how networks function. It gives us a shared mental model for diagnosing problems at any layer without getting lost in the layers above or below it.

A legal stack works the same way. Each layer maps legal realities to the technical work you already do.

Layers 1 and 2: Physical and Property Law

At the base of the stack, you work with hardware and physical cabling. The legal equivalent governs anything you can physically touch or build on. Consider fibre optic deployment. Before a single cable enters the ground, you are already operating inside property law. Right-of-way agreements determine whether you can trench through private land. Environmental regulations govern what happens near protected areas or waterways. A contractor who ignores this layer does not just face delays. They face injunctions, fines, and the demolition of infrastructure—the legal equivalent of forgetting to plug in the power.

Layers 3 and 4: Telecommunications Law and Interconnection

Here, you route traffic and ensure data delivery across networks. The legal layer at this level governs how that traffic flows across providers and what authority exists to restrict it. The Nigerian Communications Act and NCC licensing frameworks operate here. So do interconnection agreements between carriers.

The Twitter ban is the clearest illustration of what this layer means in practice. One routing decision became the subject of national litigation. Your BGP configuration and your ACL policies are not just operational tools. They are instruments of access, and access is a civil right.

This is where the legal exposure concentrates most heavily. At the application layer, you manage user sessions, encryption, and the data flowing through your systems. Three pieces of legislation define your obligations here.

The Nigeria Data Protection Act (NDPA) 2023 requires organisations to implement “appropriate technical and organisational measures” to protect personal data. That phrase is not decorative. It means that your encryption choices, your access control policies, and your incident response procedures all carry legal standing. The Nigeria Data Protection Commission has enforcement powers, including the authority to impose significant fines for non-compliance. The Cybercrimes (Prohibition, Prevention, etc.) Act 2015 further criminalises certain categories of unauthorised access and data interference.

When you implement encryption or design an authentication flow, you are not just writing technical specifications. You are discharging a legal duty of care to every user whose data passes through your system. That makes you a data custodian, with real, enforceable liability attached to the title.


Understanding the legal stack is one dimension of T-shaped thinking. Actively applying that understanding to create value is the other.

Intellectual Property: Moving from Defence to Offence

Consider the automation script you wrote last quarter to reduce provisioning time from two hours to fifteen minutes. That script likely qualifies as a copyrightable software work under Nigerian copyright law. The novel network architecture you designed for a client may meet the threshold for patent protection, depending on how it was documented and disclosed.

Without basic IP awareness, engineers routinely hand this value away. They write, build, and innovate inside employment contracts that assign all created works to their employer without negotiation, often without even knowing it.

The 2025 trademark dispute between Paystack and Zap Africa over product naming offers a useful illustration. An IP-aware engineer embedded in the product team might have flagged the risk of consumer confusion early in the naming process, potentially saving significant legal cost and reputational exposure. Technical teams are often the first people to notice naming conflicts with existing services because they interact with APIs, documentation, and developer ecosystems long before legal teams do.

Contracts: Reading the Fine Print as a Technical Specification

A Service Level Agreement is not just legal paperwork. For an engineer, it is an operational specification with financial consequences attached. The clause promising “99.99% availability” translates to a maximum of roughly 52 minutes of permitted downtime per year. That is a number with direct implications for redundancy architecture, failover design, and maintenance windows.

An engineer who reads an SLA as a technical document, not just a commercial one, can identify misalignments between what the contract promises and what the infrastructure can realistically deliver. Catching that gap before signing saves considerably more than catching it after a breach of contract claim.

Tort Law: Your Duty of Care Beyond the Contract

Contracts govern defined relationships. Tort law governs your obligations to everyone else. The relevant principle here is professional negligence, and it applies to engineers.

If a misconfigured firewall leads to a data breach that exposes thousands of customer records, the question a court will ask is not simply whether your employer had a contract with those customers. The court will ask whether a reasonably competent engineer, exercising proper professional care, would have made the same configuration decision. That standard applies to you personally in certain contexts, not just to your organisation.

This does not mean paralysis. It means asking a second question alongside “Does this work?” The second question is: “Have I taken all reasonably careful steps to prevent foreseeable harm?” That shift in thinking is the difference between an engineer who implements and an engineer who is accountable.


Engineers Are Literally Building the New Nigeria

The T-shaped model carries particular urgency right now because Nigerian engineers are operating at a genuinely historic scale. The National Development Plan 2021 to 2025 targets N348.1 trillion in investment across priority sectors, with private sector capital expected to drive the majority of that figure. A significant portion of that investment flows into engineering-driven projects.

Physical Infrastructure: Steel and Concrete

The Lekki Deep Sea Port and the Dangote Refinery represent the clearest examples at the physical layer. These are not construction projects in the ordinary sense. The Lekki port positions Nigeria to handle larger vessel classes and decongest Apapa, which carries direct implications for import costs across the economy. The Dangote Refinery, when operating at full capacity, targets an end to Nigeria’s dependence on imported refined petroleum. Both projects required engineers who understood procurement law, environmental impact assessment regulations, and the FIDIC contract frameworks that govern large-scale infrastructure delivery.

A purely technical engineer on projects of this scale is a liability, not an asset.

Digital Infrastructure: Bandwidth and Sovereignty

At the digital layer, the 5G rollout and the 2Africa submarine cable landing in Port Harcourt are reshaping Nigeria’s connectivity architecture. The Port Harcourt landing specifically breaks the historical concentration of international bandwidth in Lagos, which creates geographic redundancy for the country’s internet infrastructure and introduces real competition for fibre backhaul routes heading inland. These decisions involve spectrum licensing, international landing rights, interconnection agreements, and data sovereignty considerations. The engineers who understand that context contribute to those decisions. The ones who do not simply implement whatever they are told.


Where We Go From Here

The T-shaped engineer in Nigeria is not a future aspiration. The legal and regulatory environment already demands it. The NDPA 2023 creates enforceable data protection obligations. The NCC holds licensees accountable for network conduct. Courts have demonstrated, through cases like SERAP v. Nigeria, that technical actions carry constitutional consequences.

The encouraging reality is that most policymakers lack the technical fluency to understand what they are regulating. That gap represents an opportunity. An engineer who can translate between technical architecture and legal language becomes indispensable in policy discussions, procurement negotiations, compliance audits, and boardroom conversations that most technical professionals never enter.

You are already building the infrastructure of a nation. The question is whether you are doing it with full awareness of the legal and strategic weight that infrastructure carries, or whether you are leaving that awareness to someone else and hoping they get it right.

The T-shaped engineer chooses the former.

Feedback & Discussion

Have questions, corrections, or perspectives to share? Connect directly to discuss systems and security.

Table of Contents (14 sections)
navigate select
23 publications indexed