top of page

Building Ethiopia’s Digital Resilience

Writer: Tewodros Guday
Tewodros Guday
Aug 21
7 min read

Article 3: Cybersecurity Is Everyone’s Responsibility


“A country cannot protect its critical infrastructure through one institution alone. Digital resilience is built when everyone understands both their responsibility and their role in protecting others.”

In the previous article, we discussed an important difference between compliance and resilience. Compliance asks whether an organization follows the required rules. Resilience asks a harder question: if something serious happens tomorrow, can the organization continue providing its most important services and recover safely?

That question leads naturally to another one.


Who is responsible for making this happen?

The simple answer is: everyone has a role. But saying that “cybersecurity is everyone’s responsibility” can also create confusion. It does not mean that everyone has the same responsibility. A government regulator, a bank, a hospital, a cybersecurity company, a software supplier, a university and an ordinary employee clearly have different roles.

Shared responsibility therefore does not mean unclear responsibility.

It means that every participant in the digital ecosystem must understand what it is responsible for, what it depends on, who depends on it, and how its actions can affect others.

This is particularly important for critical infrastructure because our digital systems are increasingly connected.

Imagine a hospital. The hospital may operate the health service, but it does not operate alone. It may depend on an electricity provider, telecommunications networks, banking services, medical equipment suppliers, software companies, cloud or data-centre services, identity systems and many other organizations.


If one important dependency fails, the hospital can be affected even when its own systems have not been attacked. The same is true for banks, telecommunications companies, government institutions, transport operators and energy providers.

This is why national cybersecurity cannot be built as a collection of isolated organizational security programs. It must be built as an ecosystem. Ethiopia's Critical Infrastructure Cybersecurity Proclamation recognizes this need. Its foundation calls for integrated, effective and rapid information exchange among stakeholders so that cyber incidents can be shared and mitigated. It also calls for clear responsibilities and obligations for organizations managing critical infrastructure and those involved in cybersecurity protection.

The important word here is coordination.

An organization can have strong security internally and still remain exposed through the organizations around it. National resilience therefore depends not only on how well individual organizations protect themselves, but also on how effectively they work together.


INSA's role: lead, coordinate and build national capability

The Information Network Security Administration, INSA, has a central role in this ecosystem.

As the national authority, INSA needs to provide direction. Organizations need clear national frameworks, minimum security expectations, technical guidance and a common understanding of what good cybersecurity looks like.


The accompanying blueprint reflects this division of responsibility. It presents INSA's regulatory role around national cybersecurity frameworks, monitoring implementation, national risk and maturity assessment, early-warning capability, coordination, audits and security assurance. Critical infrastructure owners, meanwhile, are expected to establish their own cybersecurity programs, classify and protect assets, assess risks, use competent professionals, address supply-chain security and report incidents. This distinction is important.

INSA cannot operate the cybersecurity program of every bank, hospital, telecommunications company, government institution or energy provider.

Nor should critical infrastructure owners wait for INSA to solve every cybersecurity problem for them.

The national authority establishes direction and oversight. The organizations operating critical infrastructure must turn those expectations into daily operational practice.

This relationship works best when regulation and cooperation support each other.

A regulator must sometimes enforce requirements. Serious or repeated negligence cannot simply be ignored. But enforcement should not be the only relationship organizations have with the regulator.

Organizations should also be able to approach the national cybersecurity authority when they discover threats, need guidance or experience serious incidents.

That requires trust.


Critical infrastructure owners must own their risk

The organization operating a critical service must remain responsible for protecting that service. This responsibility cannot simply be outsourced. A bank may hire a cybersecurity company. A hospital may use an external cloud provider. A government institution may purchase software from a technology company. An energy provider may use international equipment suppliers.

Those partners can provide important capabilities. But the organization still owns the risk associated with the service it provides. Its leadership therefore needs to know which services are critical, which systems support them, what risks could interrupt them, what third parties they depend on and how the organization would continue operating during a serious incident.

This is also why cybersecurity must reach the boardroom and senior management.

If cybersecurity remains only inside the IT department, important decisions about investment, acceptable risk, business continuity, procurement and organizational priorities may never receive the attention they require. Technical teams protect systems.

Leadership protects the organization by making informed decisions about risk.

Both are necessary.


The private sector should be treated as a national capability

There is another important participant in this relationship: Ethiopia's private cybersecurity sector. Private companies should not be viewed simply as businesses selling security products. They can become an important part of Ethiopia's national cybersecurity capability.

Government cannot employ every penetration tester, security architect, auditor, incident responder, cloud security specialist, digital forensic investigator or industrial cybersecurity expert that the country will need. It does not need to.


A strong national model can develop these capabilities across government, critical infrastructure organizations and the private sector. Private companies can support security assessments, cybersecurity audits, security operations, incident response, penetration testing, digital forensics, architecture, training, research and specialist services.

This creates another benefit. It develops a domestic cybersecurity industry.

Instead of relying heavily on expertise from outside the country, Ethiopia can gradually build local companies and professionals capable of protecting Ethiopian institutions while also competing internationally. But this requires quality.


Not every organization calling itself a cybersecurity company should automatically be trusted with critical infrastructure. Professional competence, ethical conduct, independence, confidentiality and appropriate certification become very important.

The relationship between INSA and the private sector should therefore include both opportunity and accountability.


The government can establish standards and qualification requirements. Professional organizations can support ethical practice and professional development. Private companies can invest in skills and innovation. Critical infrastructure owners can select competent providers based on risk and demonstrated capability.

The result should be a stronger national professional ecosystem.


Information sharing must not become a source of fear

One of the most difficult parts of cybersecurity cooperation is incident reporting.

Imagine that a major organization discovers that attackers entered its network.

Its first reaction may be concern.

  • Will customers find out?

  • Will our reputation suffer?

  • Will the regulator punish us?

  • Will the media misunderstand what happened?

  • Will competitors use the information against us?


These concerns are understandable. But if organizations hide important cyber incidents, the entire country may lose an opportunity to prevent the same attack elsewhere.


Suppose attackers discover a new method of compromising one financial institution. If useful technical information can be shared quickly and safely, other financial institutions may be able to block the same attack before they become victims.

One organization's experience can therefore become another organization's early warning.

That is why incident reporting should not be designed only as an enforcement mechanism.

It should also function as a national learning mechanism.

Organizations need confidence that sensitive information will be handled responsibly. Information sharing should protect legitimate confidentiality while allowing useful threat information to reach organizations that need it. Trust does not remove accountability.

It makes cooperation possible.


Universities and professional associations also have a role

National cybersecurity capability cannot grow without education.

Universities have an important responsibility to prepare the next generation of cybersecurity professionals. But this should not happen separately from industry.

Universities need to understand what skills organizations actually require. Industry should help universities understand emerging technologies and real operational problems. Government can help identify national capability priorities.

Professional associations can provide another bridge.

They can support ethical standards, professional education, knowledge sharing, conferences, research discussions and continuous professional development.

This is particularly important in areas such as cybersecurity auditing, where technical knowledge alone is not enough. Professionals may have access to highly sensitive systems and information. Competence must therefore be accompanied by integrity and professional ethics. We will examine this much more closely when we discuss cybersecurity audit later in this series.


The individual remains part of the system

Shared responsibility eventually reaches every employee. A sophisticated security system can still be weakened by a stolen password, an unsafe attachment, poor handling of sensitive information or an employee who does not know how to report something unusual.

This does not mean employees should be blamed whenever something goes wrong.

It means organizations must give people the knowledge, tools and working environment needed to make safer decisions.

Cybersecurity awareness should therefore move beyond annual training that employees complete simply because it is required. People should understand why security matters to their own work. A hospital employee should understand how cybersecurity can affect patient care. A bank employee should understand how it protects customer money.

A government employee should understand how it protects public services and citizens' information. An engineer working with critical infrastructure should understand how a small technical change can affect service continuity. When people understand the reason behind security, behavior begins to change.


From institutional responsibility to national responsibility

The strongest cybersecurity model is therefore not one in which government tries to control everything. Nor is it one in which every organization is left to protect itself. It sits between those two extremes. Government provides national leadership, regulation, coordination and oversight. Critical infrastructure owners protect and operate their services. Private companies provide expertise, innovation and specialist capability. Technology suppliers secure the products and services on which others depend. Universities develop knowledge and future professionals. Professional associations strengthen competence and ethics. Employees apply security in everyday work.


And these participants communicate when risks cross organizational boundaries.

That is what shared responsibility should mean. Ethiopia's Critical Infrastructure Cybersecurity Proclamation provides an important opportunity to build such a relationship. But it will require time, trust and continuous dialogue between INSA, critical infrastructure owners, private companies, universities, professionals and other stakeholders. There will be disagreements. There will be capability gaps. Some requirements will need clarification as organizations begin applying them in practice. New technologies and new threats will create questions that cannot all be answered today. That is normal.


A mature cybersecurity ecosystem is not created by getting everything perfect on the first day. It develops when institutions learn together, correct weaknesses and continuously improve. The important thing is to establish the right direction from the beginning.

Cybersecurity is everyone's responsibility, but responsibility must be clear. Cooperation is essential, but cooperation requires trust. Regulation is necessary, but regulation should also help build capability. And this leads to the next major challenge.

Even if responsibilities are clearly defined, do we currently have enough skilled people to carry them out?

A country can buy technology. It can publish standards. It can establish regulations. But without skilled professionals, capable leaders, trained employees, competent auditors and strong institutions, those investments cannot achieve their full purpose.

That is where our next article continues:

Article 4 — Ethiopia's Biggest Cybersecurity Challenge May Not Be Technology: It Is Capacity.

Comments


bottom of page