Building Ethiopia’s Digital Resilience
- Tewodros Guday

- 9 minutes ago
- 6 min read
Article 2: From Compliance to Resilience — The Real Goal of Critical Infrastructure Protection

Passing an audit may show that controls exist. Resilience shows whether they work when they are needed most.
In the first article, we started with a simple idea: cybersecurity is no longer only about protecting computers. It is about protecting the services that people depend on every day.
Ethiopia’s Critical Infrastructure Cybersecurity Proclamation No. 1426/2026 provides an important legal foundation for doing this. But establishing a law is only the beginning. The more difficult question comes afterward: What does successful implementation actually look like?
It is tempting to answer this question with one word: compliance.
An organization receives requirements from the regulator. It develops policies, installs security controls, prepares documents, completes an audit, corrects identified weaknesses, and demonstrates that it has followed the required rules.
All of this is important. But it is not enough. Imagine that a bank has passed its cybersecurity audit. Its policies are complete, its systems have been assessed, and its reports show that the required controls are in place.
Then, one morning, the bank experiences a serious cyberattack. Customers cannot access their accounts. Payments cannot be processed. Some systems must be shut down to stop the attack from spreading. At that moment, the most important question is no longer whether the bank passed an audit six months earlier.
The important questions are much more practical.
Can the bank continue providing its most important services?
Can it understand what is happening?
Can it contain the attack?
Can it communicate with customers and authorities?
Can it restore its systems safely?
How long will recovery take?
And what will it learn from the incident?
These questions take us beyond compliance and into resilience. Compliance asks whether an organization is following the required rules. Resilience asks whether the organization can continue operating when something goes wrong.
Both are necessary, but they are not the same thing. This distinction is especially important when we talk about critical infrastructure. The purpose of protecting electricity, banking, telecommunications, healthcare, transportation, government systems and other essential services is not simply to produce good audit reports. The real purpose is to make sure that important services remain available and can recover quickly when disruption occurs.
This thinking is already visible in the foundation of the proclamation. Its preamble does not speak only about technical security. It connects cyber threats with Ethiopia’s economy, social interaction, national security, peace, stability and sovereignty. It also emphasizes risk-based protection, coordinated information exchange, financial capacity and clear responsibilities.
That wider view matters. A cyberattack does not care whether an organization has completed its compliance checklist. It looks for weaknesses. Those weaknesses may be technical. But they may also come from people, processes, suppliers, poor decisions, weak leadership, outdated systems or lack of preparation.
This is why critical infrastructure protection must begin with risk. Every organization should understand what it is protecting and why it matters. For example, not every computer inside a hospital has the same importance. A computer used for ordinary office work and a system supporting emergency patient care do not create the same level of risk if they become unavailable.
The same principle applies to banking, energy, telecommunications, transportation and government services. Organizations therefore need to identify their most important services, understand the systems supporting those services, identify their dependencies and prepare for what could happen if those systems become unavailable.
The operational blueprint connected to the proclamation reflects this risk-based thinking. It describes critical infrastructure designation using factors such as societal disruption, sovereign risk and cascading effects across sectors.
The idea of a cascading effect is particularly important. Consider electricity. A cyberattack against an electricity provider may initially appear to be an energy-sector problem. But if electricity is interrupted for a long period, telecommunications may be affected. Banks may experience difficulties. Hospitals may need emergency power. Businesses may stop operating. Government services may become unavailable.
One failure can create another. This is why resilience requires organizations to look beyond their own walls. They must understand what they depend on and who depends on them. This also changes how leaders should think about cybersecurity.
Cybersecurity cannot remain a discussion only between engineers and the IT department. Senior management and boards must understand the risks because many of the important decisions are business decisions.
How much disruption can the organization tolerate?
Which service must be restored first?
How much should be invested in security?
Which risks can be accepted?
What happens if an important supplier fails?
Who has authority during a major incident?
These are leadership questions. Technology supports the answers, but technology cannot make those decisions alone.
There is another important change that comes with resilience thinking. We must accept that it is impossible to prevent every cyber incident. This does not mean accepting poor security. Organizations should continue investing strongly in prevention. But even organizations with good cybersecurity can be attacked.
The goal therefore cannot be simply: “We must never be attacked.”
A more realistic goal is: “We will work hard to prevent attacks, detect them quickly when they happen, limit their impact, continue our most important services and recover safely.”
That is resilience. It also changes the role of business continuity. Cybersecurity and business continuity should not be treated as separate activities. If an important digital system becomes unavailable, the organization must already know how essential services will continue.
A plan written in a document is not enough. It must be tested. Organizations need exercises that ask difficult questions.
What happens if our main systems are unavailable for six hours?
What happens if they are unavailable for three days?
What happens if our backup does not work?
What happens if the cyberattack also affects our main supplier?
What happens if employees cannot access the building?
What do we tell customers?
Who informs the authorities?
Who makes the final decision about restoring systems?
These exercises expose weaknesses before a real crisis exposes them. This is also why awareness is so important.
Rules and penalties have a place in regulation. There must be consequences when organizations repeatedly ignore serious responsibilities or place critical services at unnecessary risk. But penalties alone cannot create a strong cybersecurity culture. People protect what they understand. When employees understand how their actions can affect the organization, security becomes part of their work rather than simply another requirement. When executives understand the financial and operational consequences of cyber incidents, cybersecurity investment becomes a business decision rather than an IT expense. When organizations understand that incident reporting can help protect other organizations, information sharing becomes part of national defense rather than something to fear.
This is the culture that Ethiopia should work toward as the proclamation moves from law into practice. The strongest measure of success should therefore not be how many organizations have been punished. It should be how much national capability has improved.
Are organizations identifying their critical assets more clearly?
Are senior leaders discussing cyber risk?
Are incidents being detected earlier?
Are organizations sharing important threat information?
Are recovery times improving?
Are employees becoming more aware?
Are suppliers becoming more secure?
Are organizations learning from incidents and audits?
And most importantly, can essential services continue when something goes wrong?
These are signs of maturity. This will take time. Ethiopia should not expect every critical infrastructure organization to reach the same level of cybersecurity maturity immediately. Organizations have different technologies, resources, skills and starting points.
The proclamation should establish the direction and minimum expectations. Implementation should then encourage organizations to improve continuously based on their risks and responsibilities.
Cybersecurity is not something an organization completes. The technology changes. The threats change. Organizations change. Suppliers change. The services citizens depend on change. Security must therefore change with them. This brings us to an important conclusion.
Compliance provides a minimum standard. Resilience must be the larger goal. The question should not simply be, “Are we compliant?”
The better question is: “If something serious happens tomorrow, are we ready?”
And once we ask that question, another immediately follows. Who is responsible for making sure that Ethiopia is ready?
Is it INSA? Is it the organization operating the infrastructure? Is it the private cybersecurity industry? Is it technology providers? Is it universities?
The answer cannot be only one of them. Protecting a digital nation requires shared responsibility.
That is where the next article will continue: how INSA, critical infrastructure owners, the private sector, academia and other stakeholders can work together, while keeping their different responsibilities clear to build Ethiopia’s national cybersecurity capability.


Comments