Ethiopia's New Cybersecurity Law: What Banks, Hospitals and Power Companies Now Have to Do
A proclamation two years in drafting gives INSA audit power over 12 sectors, a licensing regime for private cyber firms, and a fund fed by fines up to 2 million birr — with one year for institutions to comply.

In the six months to January 2026, Ethiopia's Information Network Security Administration counted 27,773 cyberattacks on national digital infrastructure, up from roughly 8,000 in the whole of 2023/24 and under 100 a year two decades ago. INSA says it stopped 99 percent of them. The other one percent is the reason a proclamation now sits signed by President Taye Atske Selassie, after passing the House of People's Representatives unanimously on June 9 and clearing more than two years of review at the Ministry of Justice.

The law is short on drama and long on paperwork. Twelve sectors — from finance and energy to agriculture and trade — are now designated critical infrastructure. Owners of anything on that list face 18 separate obligations: write a cybersecurity program, get it certified, report incidents within 48 hours, screen staff for security clearance, vet every new piece of software before it goes live. Miss a deadline and the fines start at 500,000 birr and climb to 2 million. Do it negligently and it is a fine. Do it intentionally, and cause real damage, and it is prison — up to ten years if the breach hits national security, public health or the power grid.

The Fayda digital ID system alone has enrolled more than 50 million people, banking and mobile money have moved onto shared cloud platforms, and government procurement runs increasingly through a single electronic window. Every one of those systems is now a bigger target than it was two years ago, and the law INSA had to defend them with dated to well before most of that migration happened.
Money is the part regulators usually leave for later. This proclamation does not. It creates a Critical Infrastructure Cyber Security Fund, permanent rather than project-based, paid for by monthly contributions from designated critical infrastructure operators — the exact amount left to a future Council of Ministers regulation — plus administrative fines, service fees and voluntary donations. INSA Director General Tigist Hamid has framed it as financing for training, research and the technology platforms operators need to comply, not just enforcement overhead. Whether the monthly contribution lands as a rounding error for a commercial bank or a real cost for a mid-sized hospital or university depends entirely on a number nobody has published yet.
The proclamation also opens a market. Anyone offering cybersecurity products or services — audits, penetration testing, incident response — now needs an INSA license, minimum capital, a permanent Ethiopian address and clean legal history. Critical infrastructure owners can delegate their compliance work to these licensed firms rather than build capacity in-house, except where INSA rules the sector too sensitive for outsourcing. That single clause turns an 18-point compliance checklist into a commercial opportunity for whichever local and international firms move first to get licensed — while smaller institutions without the budget to hire either an in-house team or an outside auditor absorb the same fines as the ones that can afford both.

Ethiopia is not writing this alone. A 2023 National Bank of Ethiopia directive already binds commercial banks to its own cybersecurity standard, and a separate Personal Data Protection Proclamation covers how citizen data gets handled. The new law does not replace either — it adds a third layer, built around INSA's own audit and certification system. For an enterprise that is already reporting to the central bank, the honest question is how much of that evidence will overlap with what INSA now demands, and how much will mean two audits instead of one.
The law takes effect one year after its publication in the Federal Negarit Gazette — roughly July 2027 — during which INSA has promised directives, technical standards and support to help institutions get ready.
