Data Protection & PrivacySeptember 2, 20266 min read

Proclamation No. 1426/2026 Just Put a 48-Hour Clock on Every Ethiopian Bank's Cyber Incidents

Ethiopia's Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 gives banks 48 hours to report a cyber incident or face a fine. What compliance teams need to build before the one-year grace period ends.

D
Daracorp Team

On 7 August 2026, Ethiopia's House of Peoples' Representatives ratified the Critical Infrastructure Cybersecurity Proclamation No. 1426/2026, the law the Information Network Security Administration (INSA) had tabled to Parliament earlier in the year and has since begun explaining through its own public statements on the new framework, reported by Ethiopia's state news agency ENA and confirmed separately by state broadcaster EBC. It names twelve sectors as critical infrastructure, financial services among them, and gives operators in each a fixed clock: report a cyber incident to the National Computer Emergency Response Center within 48 hours of detection, or face an administrative fine.

Who this is for: Compliance Officers and MLROs at Ethiopian banks, insurers and MFIs who will now own an incident-reporting duty that did not exist in this form a year ago.

Why compliance owns this file, not only IT

It is tempting to read a cybersecurity proclamation as a technology-department problem. INSA's own framing does not support that reading. The law sets eighteen core obligations for critical infrastructure owners and operators, covering regular risk assessments, cyber audit systems and, notably, institutional security governance, the kind of structural accountability that has traditionally sat with a bank's risk and compliance functions rather than its server room. A finance-sector operator that treats this as purely technical will find, at the first incident, that nobody owns the 48-hour clock, because nobody was ever told it started when the security team pressed a button.

That governance framing should feel familiar. Ethiopia's AML/CFT regime already asks compliance officers to run a reporting clock against the Financial Intelligence Service the moment a suspicious pattern is identified, not the moment it is confirmed beyond doubt. Proclamation No. 1426/2026 asks for the same discipline against a different regulator and a different trigger: detection of a cyber incident, not confirmation of its scale or root cause.

The 48-hour window, and what breaks it

Two things trigger a fine under the proclamation, according to consistent reporting across Ethiopian outlets: failing to report a cyber incident to the National Computer Emergency Response Center within 48 hours of detection, and neglecting the corrective action a reported incident requires. The administrative fines run from 1.5 million to 2 million birr, alongside a new licensing regime for private cybersecurity firms and a permanent Critical Infrastructure Cyber Security Fund, financed in part by those fines, that INSA says will support security frameworks, technology platforms and skills development across the twelve sectors.

Forty-eight hours sounds generous until an institution maps what has to happen inside it: detection, internal escalation, a decision on whether the incident meets the reporting threshold, and a filing that someone in the organisation is authorised to make. Most Ethiopian banks have never timed that sequence, because nothing before this proclamation forced them to.

What the one-year grace period is actually for

Institutions have one year from the proclamation's publication in the Federal Negarit Gazette to come into compliance, during which INSA says it will issue directives, publish technical standards and provide implementation support. A year sounds long. It is not long enough to build an incident-response capability from nothing in the final quarter, which is the pattern this sector keeps falling into with directive deadlines, from the six-month runway insurers were given to prove their boards fit and proper to the longer capital-adequacy windows banks and payment issuers are already tracking against 2028 deadlines.

The honest use of this grace year is to treat it as a build phase, not a countdown to worry about later. That means the incident-response owner, the escalation path and the reporting template all need to exist and be tested well before month eleven.

Building the reporting file before the clock starts

A compliance function does not need to wait for INSA's implementing directives to start this work. The structural pieces are already knowable from the proclamation itself:

  1. Name a single owner of cyber-incident reporting, distinct from whoever runs day-to-day IT security, and give that person the authority to file a report to the National Computer Emergency Response Center without waiting for board sign-off on every incident.
  2. Write down, in minutes not hours, the internal path an incident takes from detection to that named owner, and time-test it at least once before the grace period ends.
  3. Draft a reporting template now, covering what the National Computer Emergency Response Center is likely to ask for, so the first real incident is not also the first time anyone has filled the form in.
  4. Log every past cyber incident the institution can document, even minor ones, to build the baseline a risk assessment under the new law's eighteen obligations will expect to see.
  5. Set a recurring cyber-audit and risk-assessment schedule now, rather than treating "regular" as a word to interpret loosely once INSA's technical standards are published.
  6. Cross-check this file against the National Bank of Ethiopia's own draft directive on bank data storage, localisation and security, so a single incident does not trigger two uncoordinated reporting processes inside the same institution.

Where this lands on top of everything else 2026 has asked of risk teams

Ethiopian banks and payment providers are not meeting this proclamation on a clean slate. NBE's ONPS/10/2025 already forced two-factor authentication testing at defined transaction thresholds, a control-testing discipline we set out in more detail in nine questions every Ethiopian payment provider's risk team should be able to answer, and NBE is separately drafting its own directive on data storage and security for banks. Proclamation No. 1426/2026 sits above both, as the whole-of-sector legal floor rather than a banking-specific rule, which means a bank's existing 2FA-testing and data-security work should feed the new incident-reporting file rather than duplicate it. The same "build the evidence before it is asked for" discipline runs through how banks are already expected to document source-of-funds decisions under FXD/04/2026, covered in FXD/04/2026: when 100% FX retention doesn't mean zero questions; the habit transfers directly to cyber-incident evidence, even though the regulator and the trigger are different.

Embedding a tested incident-reporting routine into a compliance function's standing calendar, rather than reconstructing one under pressure at hour forty of the forty-eight, is exactly the discipline DaraCorp's Cybersecurity & Data Protection course is built around, and it pairs naturally with Risk Management & Compliance for the wider governance structure the proclamation's eighteen obligations now expect.

This article describes how Ethiopian financial institutions are preparing for Proclamation No. 1426/2026 and is not legal advice or a definitive interpretation of the proclamation or INSA's forthcoming implementing directives. Confirm your institution's specific obligations against INSA's own publications at insa.gov.et and take professional advice on your organisation's particular circumstances.

Filed under
INSAProclamation 1426/2026cybersecuritycritical infrastructuredata protectionbanking regulationrisk managementNational CERT
DaraCorp AI assistant

How can I assist you today?

Powered by CopilotKit

Proclamation 1426/2026: Ethiopia's New Cyber Reporting Duty