CyberMela
አማ
Research prototypeLegal explanations are source-led but not yet reviewed by an appointed Ethiopian legal reviewer.About this status
OFFICIAL CHANNEL GUIDE

How to report a cyber incident in Ethiopia

CyberMela does not accept incident reports. This page helps you recognize the official destination and prepare to report directly.

READ THIS IN 60 SECONDS
Where to report

Submit directly through the official Ethio-CERT incident form or INSA cyber-issue route.

What we receive

Nothing. CyberMela does not collect, copy, relay or store your incident information.

What to verify

Check the official domain, use an authorized contact and follow your internal response procedure.

If systems, money, safety or essential services are at immediate risk

Follow your organization's emergency and incident-response procedures first. Preserve evidence and avoid making unnecessary changes that could destroy records.

A safe route from discovery to official reporting

01Stabilize

Follow the organization's response plan and protect people and essential services.

02Prepare facts

Record what happened, when it was observed, impact and actions taken—without exposing secrets.

03Submit directly

Use the official Ethio-CERT or INSA destination shown below.

04Keep the record

Retain the official reference and follow authorized internal and regulator instructions.

General preparation guidance only. Your approved incident plan and the official form control the actual response.

OFFICIAL DESTINATIONS

Send the report directly to the government channel

1

Ethio-CERT incident report

The dedicated online incident-report route on the official Ethio-CERT domain.

Go to ethiocert.gov.et
2

INSA “Report a Cyber Issue”

INSA's general cyber-issue reporting route on its official website.

Go to insa.gov.et

Before entering sensitive information, check that the browser address ends in ethiocert.gov.et or insa.gov.et. CyberMela never asks you to paste incident details here.

What to prepare before opening the form

Use your internal policy and the official form as the final authority. It may help to have:

A short, factual description of what happenedWhen the incident was first observed and whether it is ongoingAffected service or business function—not passwordsA responsible contact authorized to communicateActions already taken to contain harmRelevant records preserved under your internal procedure

Do not include passwords, private keys or unrelated personal data. Share only what the official channel requests and your organization is authorized to disclose.

Does the 48-hour rule apply?

Article 7(14) of Proclamation No. 1426/2026 sets a 48-hour notification duty for owners of designated critical infrastructure. Article 28 delays the proclamation's effective date until one year after its 21 July 2026 publication.

Whether the rule applies to a particular organization, when the clock starts, and what format is sufficient may depend on designation and implementing rules. Treat those as questions for INSA or qualified Ethiopian counsel—not for an automated tool.

What CyberMela does not do

  • We do not receive or relay your report.
  • We do not store incident descriptions, logs or evidence.
  • We do not contact INSA or Ethio-CERT on your behalf.
  • We do not decide whether an event legally qualifies as a reportable incident.
  • We do not replace emergency, legal or professional incident-response support.
Last reviewed 10 August 2026 • Official destination links checked