Ethiopia has introduced a new cybersecurity law that gives the Information Network Security Administration (INSA) greater powers to monitor and protect important digital systems across the country.

The law comes as cyberattacks on Ethiopia’s digital infrastructure continue to rise. INSA recorded 27,773 attacks in the six months to January 2026, compared with about 8,000 attacks during the whole of 2023/24. The agency says it was able to stop 99 percent of the attacks.

The new law, approved unanimously by parliament on June 9 and signed by President Taye Atske Selassie, puts 12 areas of the economy under special cybersecurity requirements. They include banking and finance, energy, health, agriculture and trade.

What institutions will have to do

Banks, hospitals, power companies and other organizations considered critical to the country will have to meet a set of cybersecurity requirements.

Among other things, they will need to:

  • Create and maintain a cybersecurity plan.
  • Have their cybersecurity systems checked and approved.
  • Report serious cyber incidents to INSA within 48 hours.
  • Check the security background of employees in sensitive positions.
  • Review new software before introducing it into their systems.

Organizations will have one year after the law is published in the Federal Negarit Gazette to comply.

Failure to meet the requirements could result in fines ranging from 500,000 birr to 2 million birr. In serious cases where a person deliberately causes major damage, the law also allows for prison sentences of up to 10 years, particularly when national security, public health or the power supply is affected.

A new cybersecurity fund

The law also creates a permanent Critical Infrastructure Cyber Security Fund.

The fund will receive monthly payments from organizations covered by the law, although the government has not yet announced how much they will have to pay. It will also receive money from fines, service fees and voluntary contributions.

INSA says the money will help finance cybersecurity training, research and technology.

For businesses, however, the size of the monthly payment could become an important additional cost. The impact will depend on the amount eventually set by the government.

New rules for cybersecurity companies

The law also creates a licensing system for private companies that provide cybersecurity services.

Companies offering services such as security testing, system checks and help during cyberattacks will need an INSA license. They will also have to meet requirements relating to capital, their business location and legal history.

This could create new opportunities for cybersecurity companies as organizations look for outside help to meet the new requirements.

However, not every institution will necessarily be allowed to outsource its cybersecurity work. INSA can require organizations in particularly sensitive areas to keep certain security functions in-house.

Another layer of regulation

The new law adds to existing cybersecurity and data protection rules in Ethiopia.

Banks, for example, already follow cybersecurity requirements issued by the National Bank of Ethiopia. Ethiopia also has separate legislation governing the protection of personal data.

The new law does not replace those rules. Instead, organizations may now have to satisfy requirements from more than one regulator.

For large institutions, this could mean additional reporting and security checks. It could also create a need to coordinate evidence and information already submitted to different government agencies.

Why the law matters

Ethiopia has rapidly expanded its use of digital services. More than 50 million people have been enrolled in the Fayda digital ID system, while banks, mobile money services and government institutions increasingly rely on digital platforms.

That expansion has also increased the potential impact of a major cyberattack.

The new law is therefore aimed at making organizations responsible for protecting the systems that millions of people and businesses depend on.

The law is expected to take effect about one year after its publication in the Federal Negarit Gazette, giving institutions until roughly July 2027 to prepare.

During that period, INSA is expected to issue detailed rules and technical requirements explaining exactly what organizations will need to do.

Source: Kana TV