Legal measures
Strongest national pillarLaws, regulations and legal frameworks for cybersecurity and cybercrime.
Start with the headline indicators, then explore exactly what each measure captures, how it is calculated and what it cannot tell you about an individual organization.
Ethio-CERT publishes a total of 76.34 out of 100 in the ITU Global Cybersecurity Index 2024. ITU places this result in Tier 3: Establishing—a tier for countries demonstrating a basic national cybersecurity commitment while still developing and integrating measures.
In simpler terms: Ethiopia has many important building blocks in place, especially legal measures, but the five areas are not equally developed.
A national-level category—not an organizational grade.
Each pillar can contribute up to 20 points. The bar length shows the share of that pillar's maximum, making unlike-looking decimals easy to compare.
Five horizontal bars compare Ethiopia's scores across the Global Cybersecurity Index pillars. Legal measures are highest at 18.83 out of 20 and organizational measures are lowest at 12.12 out of 20.
Laws, regulations and legal frameworks for cybersecurity and cybercrime.
Domestic and international partnerships, agreements and information sharing.
Skills, training, research, public awareness and workforce development.
National technical capabilities such as incident-response teams and operational mechanisms.
National strategy, responsible institutions, governance and coordination mechanisms.
| Pillar | Score out of 20 | Percent of maximum |
|---|---|---|
| Legal measures | 18.83 | 94.15% |
| Cooperation measures | 15.69 | 78.45% |
| Capacity development | 15.33 | 76.65% |
| Technical measures | 14.37 | 71.85% |
| Organizational measures | 12.12 | 60.6% |
Legal measures score highest at 18.83/20. Organizational measures score lowest at 12.12/20. This identifies a relative national-level difference within the index; it does not prove that every Ethiopian organization is strong in law or weak in governance.
A July 2026 Ethio-CERT article says Information Network Security Administration (INSA) defenders intercepted more than 50,000 attempted attacks against digital systems nationwide in the referenced 2025/26 period. “Attempted attacks” can include repeated or automated activity, and “intercepted” indicates defensive action. The figure should not be read as 50,000 organizations compromised, 50,000 unique attackers, or 50,000 confirmed data breaches.
Read the Ethio-CERT articleIt helps compare the presence and maturity of national legal, technical, organizational, capacity and cooperation measures.
A national score cannot replace governance and evidence review performed under an agreed written scope.
Translate relevant obligations into owners, evidence and prioritized security actions that match your systems and operating risk.
Published on the Ethio-CERT homepage for the 2024 ITU Global Cybersecurity Index.
Ethio-CERTITU methodology and 2024 report explain the national commitment benchmark and five pillars.
ITU GCI 2024Reported by Ethio-CERT in a 9 July 2026 article citing INSA's defensive activity.
Ethio-CERT articleCyberMela offers cybersecurity consulting, readiness roadmaps, governance and evidence review under a written scope, and staff briefings.