← Back to list

The Hidden Cost of Enterprise Networking in Nigeria: Why Your MPLS Circuit Is Quietly Bankrupting…

Part One — The Nigerian IT Trap: A Story Playing Out Across Boardrooms in Lagos

Joshua Ukpozi · 2026-05-26 10:50 · 0 claps · 15.6 min read
#banking #networking #mpls #azure-virtual-wan #nigerian-economy
Open on Medium ↗
Wiki topics: ECO · Economy · General ☁️ · DevOps & Cloud 🔧 · Data Engineering

The Hidden Cost of Enterprise Networking in Nigeria: Why Your MPLS Circuit Is Quietly Bankrupting You and How Azure Virtual WAN Changes the Equation

Part One — The Nigerian IT Trap: A Story Playing Out Across Boardrooms in Lagos

The year is 2024.

In a sleek glass boardroom overlooking Victoria Island, a CFO is staring at two documents that perfectly summarize the modern Nigerian enterprise dilemma.

The first is a diesel invoice.

Not long ago, the company’s monthly diesel spend for keeping branch infrastructure, cooling systems, routers, and UPS systems alive hovered around ₦4 Million monthly.

Now, after inflation, forex volatility, and energy instability, that same bill has exploded past:

  • ₦11 Million monthly.

The second document sitting on the polished conference table is even more painful.

It is a proposal from a major telecom carrier for an upgraded 50Mbps MPLS link.

The quote:

  • ₦1.8M — ₦2.5M monthly Per site.

For a company with:

  • 10 branches
  • a Lagos HQ
  • regional offices in Kano, Port Harcourt, Abuja, and Ibadan

that single WAN decision could push annual connectivity costs toward:

  • ₦180 Million+

before accounting for: diesel, generator maintenance, cooling, hardware replacement, support contracts, cloud services, downtime losses and more

This is the Nigerian IT Trap.

Paying premium prices for a private network that still goes dark the moment a road grader in Ibadan accidentally slices a fiber optic cable.

And yet for years, Nigerian enterprises accepted this as normal.

Because for decades, MPLS was the undisputed king of enterprise networking.

Part Two — The Private Jet of Networking and Why It’s Now a Liability

For approximately two decades, the enterprise networking gold standard for Nigerian banks, multinationals, oil companies, manufacturing firms, and government parastatals was the MPLS circuit.

MPLS (Multiprotocol Label Switching) is a technology that allowed carriers like MTN, Airtel, Globacom, and others to create what felt like a private highway across their national infrastructure. Instead of routing traffic over the chaotic public internet, MPLS carved out dedicated, labelled paths between enterprise locations. A branch in Kano could communicate with a core banking application in Lagos over a logically isolated corridor that no other customer’s traffic ever touched.

For its era, it was genuinely impressive. It offered;

Predictable latency — the branch in Kano could expect reliable, consistent round-trip times to Lagos because the path was controlled end to end.

Traffic prioritization — carriers could give your voice traffic a different class of service than your backup traffic, ensuring that critical applications were never starved by bulk data.

Perceived security — because the traffic never “touched” the public internet, the compliance teams, auditors, and regulators felt comfortable. MPLS was enterprise. MPLS was serious. MPLS was safe.

For the world of 2007, when enterprise applications lived on servers in the basement of the headquarters building and every branch accessed the same internal systems over private circuits, MPLS made perfect architectural sense. You were paying for a private corridor, and everything you cared about was at the end of that corridor.

But today, many organizations still run networking architectures designed for 2007 while operating businesses that increasingly live in the cloud.

The same company paying ₦2M monthly for MPLS is simultaneously using: Microsoft 365, Microsoft Teams, Azure, Salesforce, Zoom, cloud-hosted ERP platforms, remote work tools and more

And suddenly, a major problem emerges.

That expensive MPLS “private jet” now has to fly to a central hub in Lagos just to ask permission to access the internet.

A Teams call from Kano to London may first travel:

  • Kano → Lagos HQ → Internet → Microsoft Cloud

instead of: Kano → nearest internet breakout → Microsoft backbone.

The result is latency, congestion, slow SaaS performance, frustrated staff but more importanly, in a high-inflation economy like Nigeria’s, this becomes more than a technical issue. It becomes a financial liability.

A company may discover that: only 10–20% of its traffic truly requires ultra-private enterprise routing

while: 80–90% consists of cloud traffic, video calls, Windows updates, cloud backups, browsing, and SaaS applications.

Yet the organization continues paying premium MPLS rates for ALL traffic.

Here is the architectural problem that creates: when a staff member in a Kano branch opens Microsoft Teams for a meeting, that traffic must travel the following path in a traditional MPLS setup:

Kano branch → MPLS circuit → Lagos HQ → Internet breakout at HQ → Microsoft’s cloud infrastructure → back to HQ → back down the MPLS circuit to the Kano user.

The round trip adds latency at every hop. The HQ internet connection becomes a bottleneck shared by all branches. The 20Mbps MPLS link already expensive, is consumed not by sensitive enterprise data but by Teams notifications, SharePoint syncs, and Windows Update downloads.

The private jet is now flying passengers to an airport hub just to let them board a commercial flight. It is slow. It is expensive. And in a high-inflation, FX-volatile economy where every Naira of IT spend is under a microscope, it is becoming strategically indefensible.

Part Three — The Hidden Costs Nobody Puts in the Budget

The ~₦600,000 per month for a 20Mbps enterprise link MPLS circuit is actually the visible cost. In Nigerian enterprise environments, the invisible costs are frequently larger.

The Diesel Tax

Every MPLS branch runs on traditional enterprise-grade hardware. A Cisco ISR or ASR router the kind of equipment carrier-grade MPLS deployments typically require draws anywhere from 150 to 400 watts continuously. Add the network switches, UPS systems, cooling units, and server room air conditioning, and a single branch network room may consume 2–4kVA of power on a sustained basis.

In a country where PHCN power availability is unreliable and generator fuel costs have tripled, this hardware profile becomes a serious operational liability.

A medium branch running 10 hours of generator power daily at current diesel prices may spend an additional ₦400,000–₦700,000 per month in networking-related energy costs alone a figure that rarely appears on the IT budget but absolutely appears on the facilities and operations budget.

The Hardware Refresh Cycle

MPLS infrastructure is not merely circuit rental. It requires enterprise-grade CPE (Customer Premises Equipment) routers, switches, and sometimes carrier-provided managed devices that carry their own capital and maintenance costs. A full branch router refresh across ten sites using Cisco or equivalent enterprise equipment can run ₦15–₦30 Million in hardware alone, with annual support contracts adding 15–20% of hardware cost per year.

The Downtime Cost Nobody Quantifies

MPLS circuits are private, but they are not invulnerable. In Nigeria, the primary failure mode is the physical layer: construction work cuts a fiber cable, flooding damages a carrier exchange, or a base station loses power. When an MPLS circuit fails, the branch is typically offline for hours, sometimes days, depending on carrier SLAs and the physical nature of the fault.

For a branch doing ₦50–₦200M in monthly transactions, even four hours of downtime per month represents a measurable revenue and productivity loss that far exceeds the monthly circuit cost. Yet organizations almost never include downtime costs in their MPLS ROI calculations.

The real cost of a “₦600,000 MPLS circuit” is often closer to ₦900,000–₦1.2M per month when diesel, hardware amortization, and downtime risk are properly accounted for.

Part Four — Enter the Hybrid Backbone: Azure Virtual WAN

Imagine, instead of a rigid railway system with fixed tracks and a central station, a network that behaves more like an intelligent GPS.

It knows multiple routes. It reroutes in real time when it detects congestion. It gets you to the destination efficiently regardless of whether you start in Lagos or Maiduguri.

This is the architectural promise of Azure Virtual WAN.

Azure vWAN is frequently described as a cloud networking service, which is technically accurate but strategically underselling. It is better understood as Microsoft’s decision to open its global private backbone the same infrastructure that carries Microsoft Teams, Xbox Live, Office 365, and Azure services globally to enterprise customers as a managed WAN service.

Microsoft operates one of the largest private fiber networks on the planet. That network has points of presence in over 60 regions globally, including the West Africa hub serving Nigerian organizations. When a branch connects to Azure vWAN, it is not merely connecting to “the cloud.” It is connecting to Microsoft’s private global highway.

In practical terms, this transforms what branch-to-branch and branch-to-cloud communication looks like.

In a traditional setup, a branch in Kano communicating with a branch in Port Harcourt relies on carrier routing infrastructure. The quality of that communication is bounded by what the carrier’s terrestrial network can provide which in Nigeria can be highly variable depending on route, weather, cable health, and load.

With Azure vWAN, the Kano branch establishes a secure encrypted tunnel to the nearest Azure hub. So does the Port Harcourt branch. When they need to communicate, the traffic traverses Microsoft’s backbone between those hubs not the carrier’s terrestrial network. The branches’ connectivity quality is now bounded primarily by their local internet link to Azure, not by the full carrier path between them.

For cloud applications — Teams, SharePoint, Dynamics 365, Azure-hosted ERPs — the performance improvement is even more dramatic. Instead of traffic hairpinning through a Lagos HQ breakout, each branch accesses Microsoft services optimally from its own internet connection, while encryption and security policies are enforced centrally through Azure.

Part Five — The Strategy the Smart CTO Is Using Right Now

The mistake most organizations make when introduced to Azure vWAN is assuming it requires a complete, immediate elimination of existing MPLS infrastructure. That assumption creates organizational paralysis, because ripping out MPLS overnight is genuinely risky for regulated industries.

The smarter play the one that the most capable Nigerian technology leaders are executing is what might be called the MPLS Starvation Strategy.

They do not kill the MPLS. They starve it.

Here is how it works in practice, Instead of thinking in terms of: MPLS OR Cloud

and start thinking in terms of: MPLS + Cloud.

Instead of paying for: 50Mbps MPLS at ₦2M/month

The organization retains a lean MPLS circuit typically 5Mbps or 10Mbps rather than the previous 20Mbps or 50Mbps specifically for a narrow, defined set of traffic: core banking synchronization, regulated financial data, ERP replication, any workloads where the compliance team requires documented private circuit handling.

This small circuit satisfies the regulators. It costs a fraction of the previous full-MPLS bill. And it carries only the traffic that genuinely needs it.

Everything else, Teams calls, SharePoint activity, Zoom sessions, cloud backups, Windows updates, SaaS applications, email gets rerouted through a high-bandwidth broadband link protected by Azure vWAN.

This is not merely a networking redesign.

It is an economic optimization strategy.

The branch now has:

A ₦120,000/month 100Mbps business fiber line as the primary path. A ₦40,000/month 5G SIM card as automatic failover. A retained 5Mbps MPLS circuit at ₦150,000–₦200,000/month for regulated traffic only. Azure vWAN providing encryption, centralized policy, and cloud-optimized routing across all of it.

The total monthly spend per branch: approximately ₦310,000–₦360,000 plus the Azure vWAN hub costs.

Compare this to the ₦600,000–₦700,000 per-branch MPLS bill and the picture begins to look very different.

Part Six — The Security Question Every Nigerian IT Manager Will Ask

At this point in the conversation, Nigerian IT and compliance teams reliably raise the same concern.

“The public internet is not safe.”

This anxiety is understandable. It comes from a decade of being told by vendors, auditors, and security consultants that private circuits are inherently more secure than public internet paths. It is also, in important technical respects, a misunderstanding.

A traditional MPLS circuit is private. It is logically isolated from other customers’ traffic on the carrier’s network. But in most standard enterprise MPLS deployments, it is not encrypted. The traffic moves in clear text across the carrier’s infrastructure. If a sophisticated attacker compromises carrier equipment or if a malicious insider has access to carrier routing systems the traffic is visible.

Azure vWAN takes a different approach to security. Rather than relying on physical or logical isolation for protection, it relies on cryptographic protection. Every tunnel established between a branch and Azure uses IPsec/IKEv2 encryption the same encryption standards used by government and military networks globally. Even if traffic is intercepted at the physical layer even if someone literally taps the fiber they see encrypted ciphertext, not enterprise data.

For organizations in the banking, fintech, healthcare, and oil and gas sectors that require the strongest possible assurance, Microsoft offers ExpressRoute a service that combines the isolation properties of MPLS with the performance and scalability of Azure.

With ExpressRoute, a provider like MainOne or Medallion establishes a physical private circuit from the organization’s Lagos data center directly into Microsoft’s infrastructure. Traffic never traverses the public internet. The organization gets documented private connectivity AND Azure-scale performance AND the ability to use vWAN features for branch routing.

This is typically the architecture that Nigerian banks and telcos gravitate toward for their most sensitive workloads.

Part Seven — The Big Three: Choosing Your Foundation

At this point, the architecture discussion intersects with one of the most important practical decisions a Nigerian enterprise will make: which physical carriers will form the underlay of the hybrid network.

The answer is more nuanced than any single vendor will tell you.

MainOne — The Cloud Gateway

Since its acquisition by Equinix, MainOne has positioned itself as the most sophisticated enterprise cloud on-ramp in Nigeria. Through its MDXi data centers and direct cross-connects to major cloud providers including Microsoft, MainOne has become the preferred path for organizations pursuing ExpressRoute or requiring the lowest possible latency to Azure.

For a Lagos headquarters in Victoria Island, Ikoyi, or Lekki, there is a strong argument that MainOne is the optimal primary carrier — particularly for traffic that needs to reach Microsoft’s infrastructure. The physical proximity of their facilities to Microsoft’s peering points translates into measurably lower latency for Azure-bound traffic.

The honest limitation: MainOne’s fiber footprint is strongest in the major commercial hubs. An organization with branches in secondary cities in the North or deep East may find that MainOne’s last-mile delivery requires third-party leasing, which raises costs and can reduce the reliability guarantees that make MainOne attractive in the first place.

Pricing: For a 20Mbps enterprise-grade link with a 99% availability SLA, expect to pay ₦500,000–₦700,000 per month. Installation costs for a dedicated fiber drop typically run ₦500,000–₦750,000.

MTN Business — The National Infrastructure Empire

MTN owns more fiber in Nigerian soil than almost any other operator. If an organization has 30 branches spread from Sokoto to Calabar or needs genuine national reach, including secondary cities and states that other carriers treat as edge cases MTN Business is frequently the only carrier capable of serving every location with owned infrastructure.

The subsea diversity is also worth noting. MTN has investment across multiple subsea cable systems including WACS and ACE, providing meaningful redundancy at the international layer. When one cable system experiences a fault as happens periodically across West African subsea infrastructure MTN’s multi-cable positioning provides options that single-cable operators cannot offer.

For the typical 30-branch Nigerian enterprise, a hybrid strategy often looks like: MainOne for the HQ and primary data centers, MTN for the regional and secondary branch network.

The limitation: scale brings bureaucracy. Getting personalized, rapid escalation during a major outage can be difficult without a named account manager and an active enterprise relationship. Organizations running MTN links should invest in the enterprise account relationship, not just the circuit.

Pricing: Comparable to MainOne for similar specifications in major cities ₦450,000–₦650,000 per month for a 20Mbps enterprise link. Installation fees of ₦300,000–₦600,000 may be waived or amortized under multi-year contracts.

Airtel Business — The Aggressive Challenger

Airtel has made a strategic decision to compete hard for enterprise WAN business, and it shows in their pricing and flexibility. For organizations willing to commit to multi-year managed service contracts, Airtel frequently delivers the most competitive total cost of ownership particularly when bundling circuit provision with CPE management and SD-WAN overlay services.

For hybrid Azure vWAN deployments, Airtel’s managed SD-WAN offerings can provide a useful integration layer the carrier handles the physical circuit, the edge device management, and the basic SD-WAN policy, while Azure vWAN handles the cloud-side routing and security.

The limitation: Airtel’s fiber reach, while growing rapidly, does not yet match MTN’s depth in rural and northern Nigeria. For an organization with heavy branch concentration outside major commercial hubs, Airtel may end up leasing last-mile from other carriers for a subset of sites, which affects both pricing and SLA quality.

Pricing: Often 10–20% below MTN and MainOne for equivalent services in areas where Airtel has strong infrastructure. This is their deliberate competitive strategy to win market share.

The Practical Carrier Decision Framework

For HQ in Victoria Island, Ikoyi, or Lekki the cloud performance case for MainOne is strong for ExpressRoute and Azure-bound traffic.

For 20–50 branches spread across Nigeria including northern and eastern states MTN’s national footprint makes it the most practical primary carrier for branch connectivity.

For the backup or secondary link at any branch Airtel Business 4G/5G managed SIM services or Starlink terminals provide cost-effective resilience. At ₦25,000–₦50,000 per month per site, Starlink Business in particular has become a serious enterprise failover option especially for branches where terrestrial fiber cuts are a recurring problem.

The professional recommendation: never design around a single carrier. The Nigerian WAN environment has too many single points of failure at the physical layer for any single-carrier strategy to be defensible.

Part Eight — The Naira and Kobo Reality: A Full Three-Year Comparison

Let us construct the complete financial picture for a representative Nigerian enterprise: a firm with a Lagos headquarters and nine regional branches, for a total of ten locations.

Three-year difference: approximately ₦250 Million.

At current Naira/Dollar exchange rates, that difference represents roughly $150,000–$200,000 USD material capital that could fund an entire SD-WAN program, a cloud operations team, a security monitoring platform, or all three.

But framing this purely as cost savings misses the larger point.

That ₦250 Million is not just savings. In the Nigerian enterprise context, it is optionality. It is resilience capital. It is the difference between an IT organization that is perpetually firefighting under budget pressure and one that has room to invest in the capabilities that create competitive advantage.

It is the budget that buys the lithium battery systems that keep the Kano branch online during a 12-hour grid outage. It is the Starlink Business kit that keeps the Ibadan office functional when the contractor’s excavator severs the metro fiber cable. It is the security monitoring tooling that would otherwise be cut as a “nice to have.”

In Nigeria, network resilience is not a technical preference. It is a business continuity requirement. The ₦250 Million difference is your Resilience Fund.

Part Nine — The Power Story Nobody Budgets For

The single most underappreciated dimension of Nigerian enterprise WAN economics is the power story.

A typical enterprise MPLS router a Cisco ISR 4331 or 4351, for example draws 100–200 watts under normal operating conditions, rising higher under load. Add a managed Layer 2 switch, a UPS system, and the cooling required for even a small network room, and a branch networking closet routinely pulls 600W–1.5kW on a sustained basis.

In a country where PHCN supplies power for perhaps 6–10 hours daily in many locations, that load spends a significant portion of its life on generator power.

At current diesel prices, running a 3kVA generator for 14 hours daily to support a branch network room costs approximately ₦300,000–₦500,000 monthly in fuel alone, before maintenance and depreciation.

The Fortinet FortiGate 60F a capable enterprise firewall and SD-WAN device that handles full Azure vWAN integration draws approximately 15–18 watts. It runs comfortably and indefinitely on a modest 1kVA solar inverter system.

That single hardware substitution changes the entire power calculus for branch networking. The branch may still require generator power for workstations, printers, and lighting. But the network itself — the connectivity that keeps the branch productive can now run on clean, cheap solar power even through extended grid outages.

For a 10-branch organization, the difference in networking-related power costs between the two architectures can exceed ₦3.7 Million per month — nearly ₦135 Million over three years. This figure appears nowhere in a typical “connectivity cost” comparison, because it is usually buried in facilities and operations budgets. But it is very real, and it belongs in any honest ROI analysis.

Part Ten: Where Azure vWAN Is NOT the Right Answer

Any credible technology advisor will tell you when a solution is not appropriate, not just when it is.

Azure vWAN is a powerful architecture, but it is not universally correct.

Organizations with extremely low cloud adoption those still running entirely on-premise infrastructure with no Microsoft 365, no Azure, and no SaaS applications will see limited benefit from vWAN. The architecture is optimized for cloud-first or hybrid-cloud environments. If everything lives in a Lagos datacenter, a refined MPLS design may still be the most appropriate primary WAN.

Environments with genuinely unstable local internet in every branch location some rural operations in Nigeria face internet quality so inconsistent that even SD-WAN dual-link failover cannot maintain adequate application performance. In those environments, MPLS may remain the only reliably serviceable option until local internet infrastructure matures.

Ultra-low-latency trading systems and real-time financial infrastructure for applications where single-digit millisecond determinism is a hard requirement, a dedicated carrier circuit with guaranteed QoS may still outperform an internet-based overlay, even an encrypted one.

Organizations without cloud operational maturity — Azure vWAN is managed through Azure Portal and typically requires Infrastructure-as-Code practices (Terraform, Bicep) for proper deployment at scale. Organizations without Azure expertise or the budget to develop it may find operational complexity a barrier.

Heavily regulated organizations with explicit MPLS requirements — some regulatory frameworks or specific central bank circulars may explicitly mandate private circuit use for particular data categories. These requirements must be satisfied first, and the architecture built around them.

Part Eleven — The Final Verdict: An Economic Hedge, Not Just a Technology Choice

The conversation that began with a CFO staring at a diesel invoice and an MPLS proposal ends with a reframing.

For the Nigerian enterprise in 2024 and beyond, Azure Virtual WAN is not primarily a networking technology decision. It is an economic hedging strategy against the structural costs of running enterprise infrastructure in a high-inflation, FX-volatile, power-unstable operating environment.

It converts fixed, inflexible carrier circuit costs into variable, consumption-based cloud expenditure. It substitutes power-hungry enterprise routers for lean, solar-compatible edge devices. It eliminates single-carrier dependency through software-defined multi-path routing. It gives the IT organization the architectural flexibility to add a new branch in 48 hours not eight weeks and to scale bandwidth up or down without re-negotiating carrier contracts.

Most importantly, it frees the CFO from the mathematical trap of paying premium private-circuit pricing for traffic that was always going to the internet anyway.

The boardroom in Victoria Island can stop watching the diesel invoice grow. The IT leader can stop explaining why Teams calls are choppy. The CTO can stop justifying expensive MPLS renewals to a board that has started asking why the network costs more than three full engineering salaries per branch per month.

The architecture has matured. The economics have shifted. The carrier ecosystem in Nigeria MainOne, MTN, Airtel, and the emerging role of Starlink provides more than enough building material for a resilient, modern hybrid WAN.

The only question remaining is whether the organization will move before the next MPLS renewal forces the conversation anyway.

This article is Part One of an ongoing series on enterprise hybrid networking in Nigeria. Future installments will cover ExpressRoute design patterns for Nigerian financial institutions, Terraform deployment blueprints for Azure vWAN at scale, Zero Trust Network Architecture in the Nigerian enterprise context, and the real cost of branch downtime quantified by sector.

Author: Joshua Ukpozi — Cloud Infrastructure Engineer | linkedin.com/in/joshua-ukpozi


메타데이터
post_id
bb959252c997
slug
the-hidden-cost-of-enterprise-networking-in-nigeria-why-your-mpls-circuit-is-quietly-bankrupting-bb959252c997
url
https://medium.com/@jukpozi/the-hidden-cost-of-enterprise-networking-in-nigeria-why-your-mpls-circuit-is-quietly-bankrupting-bb959252c997
canonical_url
https://medium.com/@jukpozi/the-hidden-cost-of-enterprise-networking-in-nigeria-why-your-mpls-circuit-is-quietly-bankrupting-bb959252c997
author_url
https://medium.com/@jukpozi
status
ok
fetched_at
2026-06-20 20:29:01