Ethiopia Strengthens Digital Defenses With New Cybersecurity Legislation


  • Ethiopia’s Parliament unanimously approved a new law governing the cybersecurity of critical infrastructure sectors, including telecommunications, energy, finance, transport, and digital public services.
  • The legislation creates a dedicated cybersecurity fund and introduces a licensing framework for private cybersecurity providers and auditors.
  • Ethiopia recorded 27,773 cyberattacks against national digital infrastructure during the first half of fiscal year 2025/2026, with authorities neutralizing 99% of the incidents.

Ethiopia’s House of Peoples’ Representatives (HPR) unanimously ratified a law on the cybersecurity of critical infrastructure on June 9, strengthening the country’s digital defense framework as cyber threats continue to rise alongside rapid digital transformation.

Lawmakers approved the legislation during the chamber’s 24th regular session. The Information Network Security Administration (INSA) drafted the law, while the Ministry of Justice conducted a two-year legal review before its adoption.

The law has now entered into force. The legislation defines critical infrastructure as any infrastructure or institution whose disruption or compromise through a cyberattack could significantly affect national security or national interests. The framework covers eleven strategic sectors, including telecommunications, energy, finance, transportation, and digital public services.

The law establishes a dedicated critical infrastructure cybersecurity fund to finance implementation programs, professional training, research initiatives, and technology capacity-building efforts.

In addition, the legislation authorizes third-party providers to deliver cybersecurity services and conduct audits. However, the law requires service providers to meet strict eligibility criteria and complete a formal selection process before receiving authorization.

Authorities will impose penalties on unlicensed operators. The law subjects any entity providing cybersecurity services without a license to fines of up to 2 million birr. Authorities will increase the penalty to three times that amount for repeat violations.

Authorities introduced the legislation as cyberattacks increasingly target Ethiopia’s expanding digital infrastructure. During the first half of fiscal year 2025/2026 alone, INSA recorded 27,773 cyberattacks against national digital infrastructure. The agency said it successfully neutralized 99% of those incidents.

The figures underscore the rapid escalation of cyber threats. Ethiopia recorded fewer than 100 cyberattacks annually on average two decades ago. By comparison, the country registered approximately 8,000 cyberattacks during fiscal year 2023/2024.

Recent incidents have also exposed vulnerabilities within government systems. A hacking group known as “Velvet Ant,” which cybersecurity researchers have linked to Chinese state-backed operations, reportedly remained undetected inside Ethiopian government networks for five months.

The incident highlighted the scale of the cybersecurity challenges facing the country’s public institutions.

Source: Agence Ecofin

Back