New Cybersecurity Law Puts Ethiopian Banks Under a Second Regulator
A proclamation two years in the making gives INSA audit and certification power over the banking sector, with fines up to 2 million birr and a compliance deadline of roughly July 2027.
Ethiopia’s Information Network Security Administration counted 27,773 cyberattacks on national digital infrastructure in the six months to January 2026, up from roughly 8,000 for all of 2023/24 and under 100 a year two decades ago. INSA says it stopped 99 percent of them. The other 1 percent is part of the reason banks now answer to a second cybersecurity regulator. President Taye Atske Selassie has signed a proclamation naming finance among 12 sectors designated critical infrastructure, following unanimous passage in the House of People’s Representatives on June 9 and more than two years of review at the Ministry of Justice.

WHAT BANKS MUST DO
Institutions on the critical infrastructure list face 18 separate obligations: build and certify a cybersecurity program, report incidents to INSA within 48 hours, screen staff for security clearance, and vet new software before it goes live. Missed deadlines carry fines starting at 500,000 birr and rising to 2 million. Negligent breaches draw fines; intentional breaches that cause serious damage draw prison terms of up to ten years where the harm touches national security, public health or the power grid.
A FUND WITH AN UNKNOWN PRICE TAG
The proclamation also creates a permanent Critical Infrastructure Cyber Security Fund, financed by monthly contributions from designated operators alongside fines, service fees and donations. The exact contribution amount is left to a future Council of Ministers regulation, so banks do not yet know whether the levy will be a rounding error or a meaningful new line item. INSA has framed the fund as financing training, research and compliance tooling rather than pure enforcement overhead.
ONE MORE AUDIT, OR TWO
Banks are not new to cybersecurity regulation. A 2023 National Bank of Ethiopia directive already sets cybersecurity standards for commercial banks, and a separate Personal Data Protection Proclamation governs how customer data is handled. The new law does not replace either; it adds a third layer built around INSA’s own audit and certification regime. For compliance teams already reporting to the central bank, the practical question is how much of that evidence satisfies INSA’s requirements and how much amounts to a second, parallel audit.
AN OPENING FOR OUTSOURCED COMPLIANCE
The law also creates a licensing regime for private cybersecurity firms offering audits, penetration testing and incident response, with minimum capital and residency requirements. Critical infrastructure operators can delegate compliance work to these licensed firms, except where INSA rules a sector too sensitive for outsourcing. Whether that carve-out applies to core banking systems is not yet clear, and it will shape whether banks build compliance capacity in-house or buy it from newly licensed vendors.
TIMELINE
The law takes effect one year after publication in the Federal Negarit Gazette, roughly July 2027. INSA has said it will issue directives and technical standards during that window, including the contribution formula for the new fund. Banks Ethiopia will update this coverage as those directives and the fund’s contribution levels are published.
Source: Kana