Back to BlogTech News Ethiopia

Ethiopia's New Cybersecurity Proclamation 1426/2026 Explained

27 August 2026

Get a Free Quote

Tell us what you need — we'll reply within one business day.

Ethiopia's New Cybersecurity Proclamation 1426/2026 Explained

Ethiopia's House of People's Representatives has unanimously ratified the Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 — a significant escalation in how the country regulates cybersecurity, and the clearest signal yet that "we'll deal with it if it happens" is no longer an acceptable security posture for Ethiopian organisations.

The proclamation was drafted by the Information Network Security Administration (INSA) following a two-year legal review by the Ministry of Justice. INSA Director General Tigist Hamid described it as establishing a comprehensive framework for monitoring cyber risk and coordinating response across critical sectors.

What sectors does it cover?

The law applies to critical infrastructure operators across finance, telecommunications, health, energy, water, transport and government services — sectors where a cyber incident doesn't just cost one company money, it disrupts services people depend on.

What does it actually require?

  • Formal risk assessments and regular cyber audits, not one-off exercises.
  • Documented security governance — clear ownership of cybersecurity decisions, not an informal arrangement where "IT handles it".
  • Reporting cyberattacks to the National Computer Emergency Response Center within 48 hours of detection.
  • Administrative fines of 1.5 million to 2 million birr for institutions that fail to report incidents or neglect required corrective action.

The proclamation also establishes a dedicated cybersecurity fund to support resilience, innovation and skills development — alongside INSA's commitment to publish sector-specific standards and operational guidelines as implementation proceeds.

Why now — the scale of the problem

Ethiopia recorded 27,773 cyberattacks against national digital infrastructure in the first half of the 2025/26 fiscal year alone, with authorities reporting a 99% neutralisation rate. For context, the country averaged fewer than 100 recorded cyberattacks a year two decades ago. The threat has scaled by orders of magnitude as Ethiopia's digital economy — mobile money, e-government services, online banking — has grown.

Financial-sector leaders have specifically flagged AI-driven cyberattacks as a rising concern, and fraud incidents (including SIM-swap attacks against mobile money accounts) have already hit a majority of Ethiopian banks. The regulatory response is catching up to a threat that has already arrived.

Does this apply to your business?

The proclamation's formal reporting duties and fines target designated critical infrastructure operators — large-scale banks, telecoms, utilities and government service providers, not every small business. But two things are worth taking from it regardless of whether your organisation is formally in scope:

  • If you supply, integrate with, or process data for a critical infrastructure operator (a bank, a telecom, a hospital system), their new compliance obligations will likely flow down to you contractually.
  • The core practice the law demands — a documented incident-response plan with a clear reporting timeline — is good practice for any business, not just the ones legally required to have one. See our cybersecurity checklist for the practical version of this that any Ethiopian SME can implement.

How Bright IT Solutions helps

Our cybersecurity services help Ethiopian businesses build the underlying capability this proclamation assumes exists: risk assessments, security hardening, MFA rollout, email authentication, and a written incident-response plan with named accountables and a realistic reporting timeline — whether or not your organisation is formally designated as critical infrastructure.

Frequently asked questions

What is Proclamation No. 1426/2026?

It's Ethiopia's Critical Infrastructure Cybersecurity Proclamation, ratified by the House of People's Representatives in 2026 after being drafted by INSA and reviewed by the Ministry of Justice. It creates a formal cybersecurity compliance framework — risk assessments, audits, incident reporting and fines — for operators across finance, telecoms, health, energy, water, transport and government services.

What happens if a covered organisation doesn't report a cyberattack in time?

The proclamation sets administrative fines of 1.5 million to 2 million birr for institutions that fail to report a cyber incident to the National Computer Emergency Response Center within 48 hours of detection, or that neglect required corrective action.

Is this new legislation, or is it still being confirmed?

This is confirmed, ratified legislation as of 2026, reported by Ethiopia's official state news agency (ENA) and independent Ethiopian press. That said, sector-specific standards and operational guidelines from INSA are still being developed. If your organisation may be a designated critical infrastructure operator, confirm your specific obligations and timeline directly with INSA or a licensed Ethiopian legal adviser — this article is general information, not legal advice.

Ready to Upgrade Your IT Infrastructure?

Get a free consultation on cloud hosting, software, cybersecurity, networking, and data management for your Ethiopian business.

Get a free consultation

Share a few details and we'll reach out within one business day.