Cyber Security & INSA-Ready Secure Software

Secure software for Ethiopian government and banks, engineered and security-tested to pass INSA’s security audit before go-live.

Cyber Security in Ethiopia, Engineered Into the Software We Build

360Ground builds government and banking software designed to pass INSA’s security audit, and backs it with security testing and compliance support. Our accreditation: INSA — Accredited for government technology delivery. We have delivered systems for INSA and the Ethiopian Statistics Service that meet INSA’s security protocols, with encryption, role-based access, audit trails and penetration testing, as well as a secure web portal for the African Union’s CISSA and Abay Bank’s secure mobile banking app. Security is designed in from the first review, not added after the code is written. We then test what we build or support, fix the findings and prepare the evidence auditors expect.
Servers, Storage & Data Centre in Ethiopia – overview

Top Organizations Trust 360Ground

Ethiopian Capital Market Authority logo
Ethiopian Securities Exchange
Ministry of Health Ethiopia logo
Awash Bank logo
zemen bank Web Design & Development
Agricultural Transformation Agency (ATA) logo

Here are Some of the Specific Services We Offer

INSA Audit Readiness & Pre-Audit Hardening

We review your system against INSA's published security testing requirements, fix weaknesses before submission and prepare the documentation auditors ask for, so fewer findings come back.

Secure Software Development Lifecycle

Threat modelling, secure coding standards, peer code review and dependency checks at every stage, so security is designed into government and banking systems from day one.

Web & Mobile App Security Testing

Security testing of the web, mobile and API systems we build or support, including penetration testing before go-live, with prioritised findings, fixes and a retest.

Vulnerability Assessment & Remediation

Scheduled scans and manual review of the applications, servers and cloud environments behind your platform, followed by patching and hardening by the engineers who maintain it.

Data Protection & Cyber Law Compliance

We map your systems to Proclamation No. 1321/2024 on personal data and Proclamation No. 1426/2026 on critical infrastructure, then build the controls and records they require.

Secure Hosting, Monitoring & Audit Trails

Hardened hosting, encryption, role-based access, immutable audit logs and security monitoring for the platforms we run, with firewall and endpoint protection we can supply.

Case Studies

Every project is a journey, and we measure success by the results our clients achieve. From MVPs that disrupt industries to enterprise solutions that scale globally, these stories show how we transform ideas into market-leading solutions.

Questions? Answers.

What is INSA's cyber audit and evaluation?

INSA, Ethiopia’s Information Network Security Administration, runs a cyber audit and evaluation service that security-tests systems before or after they go live. Government bodies and many financial institutions submit web, mobile and network systems for testing against INSA’s published requirement documents, such as its web application security testing requirements. INSA reports findings, the owner fixes them and the system is retested. 360Ground builds and prepares systems for this process; the audit itself is carried out by INSA.
Plan for it from the start, not after development. Build on a secure development lifecycle, use INSA’s published testing requirements as acceptance criteria and run your own security testing before submission. Weak authentication, missing input validation, exposed configuration and poor session handling are common findings, so check those first. Keep architecture, access roles, hosting design and test reports documented. Our INSA audit-readiness assessment does this review and closes the gaps before you submit.
Proclamation No. 1426/2026 covers owners and operators of critical infrastructure in 12 sectors, including finance, government services, ICT, health and trade. As reported at its adoption, it sets 18 obligations, such as cyber risk assessments, cyber audits, incident reporting, security operations and supply-chain security, with a one-year transition period. It is also reported to require an INSA licence for cybersecurity service providers. We help you build software and records that meet these obligations; check the final text with counsel.
In practice, usually yes. Ethiopian banks routinely have mobile and internet banking systems security-tested by INSA before go-live, National Bank of Ethiopia directives call for periodic independent security assessments, and finance is a critical infrastructure sector under Proclamation No. 1426/2026. Build the app to pass: backend validation of transfer PINs, smart session management, biometric login and screenshot blocking, as we did for Abay Bank’s mobile banking app, then test it before submission.
A secure SDLC builds security into every stage of software development instead of testing for it only at the end. It covers security requirements and threat modelling at design, secure coding standards and peer review during build, automated code and dependency scanning in the CI/CD pipeline, security testing before release, and patching once live. Flaws cost far less to fix early. The systems we built for ESS and INSA show the result: role-based access, encryption and immutable audit logs designed in.
Application security testing examines one application, including its code, APIs and business logic, for flaws such as broken access control or injection. VAPT, or vulnerability assessment and penetration testing, is broader: it scans networks, servers and applications for known weaknesses, then tries to exploit them to prove real risk. Most regulated systems need both. We provide them as part of delivering and supporting your systems, and the same team fixes what the tests find.