New Cybersecurity Proclamation Strengthens Protection of Ethiopia’s Strategic Digital Infrastructure: INSA - ENA English
New Cybersecurity Proclamation Strengthens Protection of Ethiopia’s Strategic Digital Infrastructure: INSA
Addis Ababa, August 7, 2026 (ENA) — Ethiopia’s new Critical Infrastructure Cybersecurity Proclamation introduces a comprehensive legal framework to protect strategic national infrastructure from rising cyber threats, Information Network Security Administration (INSA) Director General Tigist Hamid said.
Briefing the media today, the director general said the Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 marks a strategic milestone in strengthening the security of Ethiopia’s digital landscape, protecting national interests, and providing a solid cybersecurity foundation for the country’s ongoing digital transformation.
The proclamation comes at a time when Ethiopia is expanding digital public services, including digital identity, electronic payment systems, and electronic procurement platforms, all of which manage vast volumes of strategic data, she noted.
Protecting these systems through a robust cybersecurity framework is therefore essential to safeguarding citizen information, ensuring service continuity, and advancing the country’s digital transformation agenda, she added.
The director general further said the proclamation was necessitated by the growing frequency and sophistication of cyberattacks targeting critical infrastructure, as well as the absence of a comprehensive legal framework to guide institutions in preventing, responding to, and recovering from cyber incidents.
She explained that the new law establishes the regulatory foundation for cybersecurity monitoring and coordinated incident response, while identifying 12 critical infrastructure sectors that require enhanced protection based on national strategic priorities.
The 12 major critical infrastructure sectors are information and communication technology (ICT), financial services, security and public safety, transportation, education, health, water and energy, government services, emergency and disaster response services, agriculture, trade and commerce, and industry.
Under the proclamation, owners and operators of critical infrastructure are required to fulfill 18 core cybersecurity obligations, including conducting regular risk assessments, implementing cyber audit systems, and strengthening institutional security governance.
The law also establishes a Critical Infrastructure Cybersecurity Fund to support sustainable cybersecurity protection, research, innovation, and human capacity development, which the director general said will significantly enhance the country’s cyber resilience.
To facilitate implementation, INSA will develop sector-specific standards and operational guidelines, provide technical support to institutions, establish modern regulatory and compliance mechanisms, strengthen the professional cybersecurity workforce, and conduct nationwide public awareness campaigns.
Institutions responsible for critical infrastructure are expected to use the transition period to prepare their technology, operational procedures, and organizational systems for full compliance.
The preparations include deploying qualified cybersecurity professionals with the required security clearance, acquiring modern security technologies, strengthening database protection, and addressing system vulnerabilities in a timely manner.
During the transition period, INSA will finalize implementation guidelines, provide technical assistance, and work closely with institutions to ensure effective enforcement of the proclamation, the director general stated.
She also underscored the role of the media in promoting cybersecurity awareness, describing cybersecurity as an issue of national survival.
Recently, the House of People’s Representatives unanimously ratified the Draft Proclamation on the Cybersecurity of Critical Infrastructure, aimed at strengthening the protection of critical infrastructures.