Critical Infrastructure Operators Face Up to 2 Mln Birr Fines Under New Cybersecurity Law

Critical Infrastructure Operators Face Up to 2 Mln Birr Fines Under New Cybersecurity Law

August 10, 2026
By Mintesinot Nigussie

Critical infrastructure operators in Ethiopia could face administrative fines of between 1.5 million birr and 2 million birr for failing to report cyber incidents within 48 hours or neglecting required corrective measures under a new cybersecurity proclamation. The legislation, introduced by the Information Network Security Administration (INSA), imposes 18 specific cybersecurity obligations on owners and operators of critical infrastructure. These include conducting cyber risk assessments, obtaining audit certifications, establishing dedicated Security Operations Centers and implementing measures to secure supply chains.

According to a report by The Reporter, organisations will also be required to employ qualified cybersecurity professionals, develop cybersecurity strategies and report detected incidents to the National Computer Emergency Response Team within 48 hours. The proclamation identifies 12 sectors as critical infrastructure requiring enhanced protection. They include information and communications technology, finance, security and public safety, transport, education, healthcare, water and energy, government services, emergency services, agriculture, trade and industry.

Operators have been given one year from the publication of the proclamation in the Federal Negarit Gazette to comply with the new requirements. During the transition period, institutions will be able to upgrade their technological infrastructure and human resources, while INSA will provide technical support, issue directives and publish technical standards. The law also establishes a permanent Critical Infrastructure Cyber Security Fund intended to provide sustainable financing for cybersecurity measures. The fund will support the adoption of security frameworks and technology platforms, as well as research and development.

It will also finance national and international capacity-building programmes, training exercises, public awareness campaigns and community-led cybersecurity initiatives. The fund will receive monthly contributions from critical infrastructure entities, with the amounts to be determined through Council of Ministers regulations. Other sources will include administrative fines, service fees and voluntary contributions from institutions and individuals. The revenues will be deposited into a dedicated bank account opened by the Ministry of Finance. The proclamation establishes a comprehensive legal framework aimed at protecting national interests, citizens’ data and vital assets from increasingly complex cyber threats.

Source: FSX Business News