INSA Introduces Critical Infrastructure Cybersecurity Fund | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The Information Network Security Administration (INSA) has introduced a landmark Critical Infrastructure Cybersecurity Protection Proclamation, with officials hoping the legislation will play a key role in reinforcing national digital sovereignty.

A core feature of the proclamation is the establishment of a permanent Critical Infrastructure Cyber Security Fund. Designed to provide sustainable financing, the fund will support the adoption of security frameworks, technology platforms, and research and development initiatives.

It will also finance national and international capacity-building programs, training exercises, public awareness campaigns, and community-led cybersecurity initiatives, according to officials.

Funding will be gathered through monthly contributions from critical infrastructure entities as determined by Council of Ministers regulations, alongside administrative fines, service fees, and voluntary contributions raised from institutions and individuals. All collected revenue will be deposited into a dedicated bank account opened by the Ministry of Finance.

From The Reporter Magazine

Announced by INSA Director-General Tigist Hamid, the new legislation establishes a comprehensive legal framework designed to defend national interests, secure citizens’ data, and protect vital assets from increasingly complex cyber threats.

Under the new proclamation, twelve key sectors have been designated as critical infrastructure requiring enhanced cybersecurity measures. These include information and communications technology, finance, security and public safety, transport, education, healthcare, water and energy, government services, emergency services, agriculture, trade, and industry.

The law mandates 18 specific cybersecurity obligations for infrastructure owners and operators. Key requirements include establishing dedicated Security Operations Centers, executing cyber risk assessments, obtaining audit certifications, implementing corrective strategies, and enforcing supply chain security.

From The Reporter Magazine

Organizations must also employ qualified cybersecurity professionals, develop clear strategies, and report any cyber incidents to the National Computer Emergency Response Team within 48 hours.

To support compliance, institutions have been granted a one-year grace period from the proclamation’s publication in the Federal Negarit Gazette. During this transition window, organizations can upgrade their technological infrastructure and human resources, while the Information Network Security Administration provides technical support, issues directives, and publishes technical standards to ensure a smooth transition.

Critical infrastructure operators face administrative fines ranging between ETB1.5 million and ETB2 million in situation of failing to report cyber incidents to the National Computer Emergency Response Center within 48 hours of detection or neglect necessary corrective measures, as per the new legislation.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW