Legal measures
Strongest national pillarLaws, regulations and legal frameworks for cybersecurity and cybercrime.
These charts explain the national statistics published by Ethio-CERT: what they measure, what they suggest, and what they cannot tell you about a particular organization.
The Global Cybersecurity Index measures a country's commitment across laws, institutions, capabilities, skills and cooperation. It is not a measure of how many attacks happen, whether systems are secure, or whether your organization is compliant.
Ethio-CERT publishes Ethiopia's total as 76.34 out of 100 in the ITU Global Cybersecurity Index 2024. ITU places this result in Tier 3: Establishing—a tier for countries demonstrating a basic national cybersecurity commitment while still developing and integrating measures.
In simpler terms: Ethiopia has many important building blocks in place, especially legal measures, but the five areas are not equally developed.
A national-level category—not an organizational grade.
Each pillar can contribute up to 20 points. The bar length shows the share of that pillar's maximum, making unlike-looking decimals easy to compare.
Laws, regulations and legal frameworks for cybersecurity and cybercrime.
Domestic and international partnerships, agreements and information sharing.
Skills, training, research, public awareness and workforce development.
National technical capabilities such as incident-response teams and operational mechanisms.
National strategy, responsible institutions, governance and coordination mechanisms.
Legal measures score highest at 18.83/20. Organizational measures score lowest at 12.12/20. This identifies a relative national-level difference within the index; it does not prove that every Ethiopian organization is strong in law or weak in governance.
A July 2026 Ethio-CERT article says INSA defenders intercepted more than 50,000 attempted attacks against Ethiopian digital systems in the referenced 2025/26 period. “Attempted attacks” can include repeated or automated activity, and “intercepted” indicates defensive action. The figure should not be read as 50,000 organizations compromised, 50,000 unique attackers, or 50,000 confirmed data breaches.
Read the Ethio-CERT articleIt helps compare the presence and maturity of national legal, technical, organizational, capacity and cooperation measures.
A national score cannot replace a scoped assessment of your governance, risks, controls, evidence, suppliers or incident process.
Translate relevant obligations into owners, evidence and prioritized security actions that match your systems and operating risk.
Published on the Ethio-CERT homepage for the 2024 ITU Global Cybersecurity Index.
Ethio-CERTITU methodology and 2024 report explain the national commitment benchmark and five pillars.
ITU GCI 2024Reported by Ethio-CERT in a 9 July 2026 article citing INSA's defensive activity.
Ethio-CERT articleCyberMela offers cybersecurity compliance consulting, assessments, roadmaps and staff briefings for organizations preparing for Ethiopia's cybersecurity requirements.