Choose where to report a cyber incident in Ethiopia
Start with the situation that best matches yours. CyberMela then sends you directly to the relevant official government channel without receiving your incident details.
Which situation best describes what you need to report?
Selecting an option does not submit anything to CyberMela.
A system, account, network or service may be affected
Use Ethio-CERT's dedicated official incident-report form.
Open the Ethio-CERT formYou need INSA's general cyber-issue route
Use INSA's official “Report a Cyber Issue” form for a general cyber matter.
Open the INSA formYou need to organize the facts first
Review the minimum information to prepare without entering incident details on CyberMela.
See what to prepareCyberMela does not receive or forward reports. The first two buttons open official government websites in a new tab.
Follow your organization's emergency and incident-response procedures first. Preserve evidence and avoid making unnecessary changes that could destroy records.
What to prepare before opening the form
Use your internal policy and the official form as the final authority. It may help to have:
Do not include passwords, private keys or unrelated personal data. Share only what the official channel requests and your organization is authorized to disclose.
A safe route from discovery to official reporting
Follow the organization's response plan and protect people and essential services.
Record what happened, when it was observed, impact and actions taken—without exposing secrets.
Use the official government destination shown below.
Retain the official reference and follow authorized internal and regulator instructions.
General preparation guidance only. Your approved incident plan and the official form control the actual response.
Send the report directly to the government channel
Ethio-CERT incident report
The dedicated online incident-report route on the official Ethio-CERT domain.
Go to ethiocert.gov.etINSA “Report a Cyber Issue”
INSA's general cyber-issue reporting route on its official website.
Go to insa.gov.etBefore entering sensitive information, check that the browser address ends in ethiocert.gov.et or insa.gov.et. CyberMela never asks you to paste incident details here.
Does the 48-hour rule apply?
Article 7(14) of Proclamation No. 1426/2026 sets a 48-hour notification duty for owners of designated critical infrastructure. Article 28 delays the proclamation's effective date until one year after its 21 July 2026 publication.
Whether the rule applies to a particular organization, when the clock starts, and what format is sufficient may depend on designation and implementing rules. Treat those as questions for INSA or qualified Ethiopian counsel.
Make the next incident easier to handle.
Keep the official reference, update your internal record and assign lessons learned. If your team needs a reporting workflow or tabletop exercise, compare the preparedness package.
See incident-preparedness support