Skip to content

Research · authority data, public-interest

← Back to Legal library

National Cyber Security Strategy (draft 1.0)

NCSS · v1 · release faf85cbc

cdpg
non binding
published 2026-07-30
reviewer-approved transcription
Educational information — not legal advice.Sanitised transcription for research. The linked PDF remains the authoritative source; consult a qualified practitioner for advice on specific facts.
Download PDF
Original PDF

National-Cyber-Security-Strategy-NCSS-draft-1.0.pdf

application/pdf · 3.1 MB

Sanitised text

National Cyber Security Strategy (NCSS) — Draft 1.0 — Verbatim Transcription

Citation key: NCSS · Category: Associated policy · Pages: 48

Source PDF: Associated Policies/National Cyber Security Strategy (NCSS) draft 1.0.pdf

Faithful, unedited text-layer extraction for quotation. Page markers preserve pagination.


Page 1 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

Ministry of ICT, Postal and Courier Services

NATIONAL CYBER

SECURITY STRATEGY

(NCSS) DRAFT 1.0

0 2025-2030 1

Page 2 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

Table of Contents

Content Page

GOVERNMENTOFZIMBABWE NATIONALCYBER SECURITYSTRATEGYANDACTIONPLAN 10/30/2024

Abbreviations 2

PART 1

President’s Remarks 4 Minister’s Remarks 5

Introduction 6

Vision, Mission and Objectives 7 Background 8 Rationale 9 Cyber Security Landscape (CSL) 11 Cyber Threat Landscape (CTL) 14

PART 2

Cyber security Principles, Norms and 17 Pillars 18 19

PART 3

National Cyber Security Institutions and Governance (NCSIG) 20 National Cybersecurity Strategy Coordination Taskforce (NCSCT) 22 Minister responsible for ICT 23 Minister responsible for Cyber security and monitoring centre 24 Cyber Security Committee (CSC) 25 Cyber Security Directorate (CSD) 26 Data Protection Authority 27 Zimbabwe Child Online Protection Committee (ZICOP) 28 Zimbabwe Information Sharing and Analysis Centre (ZISAC) 29 National Network Security Centre (NSOC) 30 Computer Incident Response Team (ZIM-CIRT) 31 Stakeholders 32 Cyber Security Strategy Secretariate 33

PART 4

Strategies 36

PART 5

Action Plan Strategy Review 40

Conclusion 44

44

PART 6 45

Definitions

PART 7

Annexure – Consultation Process 47

2

Page 3 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

List of Abbreviations CI Critical Infrastructure CII Critical InformationInfrastructure CIIP Critical Information Infrastructure Protection Governmentof Zimbabwe CSL Cyber Security Landscape (CSL) CTL Cyber Threat Landscape (CTL) NCSIG National Cyber Security Institutions and Governance (NCSIG) NCSCT National Cybersecurity Strategy Coordination Taskforce (NCSCT) CSMIC Minister’s responsible Cyber security and monitoring of interception communication centre (CSMIC) CSC Cyber Security Committee (CSC) CSD Cyber Security Directorate (CSD) DPA Data Protection Authority (DPA) ZICOP Zimbabwe Child Online Protection Committee (ZICOP) ZISAC Zimbabwe Information Sharing and Analysis Centre (ZISAC) NSOC National Network Security Centre (NSOC) ZIM-CIRT Computer Incident Response Team (ZIM-CIRT) 3

Page 4 of 48

PRESIDENT’S

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

REMARKS

PRESIDENT ‘S REMARKS

4

Page 5 of 48

MINISTER’S

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

REMARKS

Minister’s Remarks 5

Page 6 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

PART 1

Introduction

Vision, Mission and Objectives for Cyber Security

1.1 INTRODUCTION

Working towards attainment of ‘Vision 2030’ in an era where digital transformation is rapidly reshaping economies and societies, the need for robust cyber security measures has never been more critical. Zimbabwe, as a participant in the global digital landscape, recognizes the imperative to safeguard its information infrastructure, protect its citizens, and ensure the integrity of national systems against an ever-evolving array of cyber threats. In contrast to land, air, sea and space, cyberspace poses the following unique difficulties: First, due to the global reach of ubiquitous networks, threat actors can launch distressing attacks far from victims and often in jurisdictions with weak laws and/or no enforcement. Second, fast connection speeds give victims little time to defend against attacks. Thus, at best, States and organisations only know about an attack when it is in process. At worst, victims do not discover the compromise of their critical systems. Third, whereas States pursue national interests through a rules-based international system, cyberspace does not have accepted norms and principles of proportionality. Indeed, whilst a country typically requires the approval of the United Nations to participate in the activities of the community of nations, any actor can setup in cyberspace and do whatever they please. Actors such organised criminals, insurgents and terrorists do not worry about norms and do not fear retaliation mainly due to the difficulty of attributing an attack to a given actor. The lack of accepted norms in cyberspace is reducing confidence in the use of ICTs (ITU, 2011) The National Cyber Security Strategy (NCSS) for Zimbabwe serves as a comprehensive framework aimed at enhancing the country's cyber resilience. It outlines a proactive approach to identify, prevent, and respond to cyber incidents while fostering a culture of cyber awareness among citizens and organizations alike. By aligning with international best practices and standards, this strategy not only seeks to protect national interests but also to promote confidence in the digital economy, thereby facilitating economic growth and development. This strategy emphasizes collaboration among government agencies, private sector stakeholders, and civil society to create a unified front against cyber threats. It aims to establish clear roles and responsibilities, enhance capacity building, and promote information sharing to strengthen the national cyber security posture. In doing so, Zimbabwe will strive to create a secure and resilient digital environment that empowers its citizens and businesses to thrive in the digital age. As we embark on this critical journey, the NCSS will serve as a guiding beacon, driving efforts to protect our nation’s digital assets and ensuring a secure future for all Zimbabweans to and beyond ‘Vision 2030’. 6

Page 7 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

1.2 VISION, MISSION AND OBJECTIVES OF NCSS

1.2.1.Vision: A secure and resilient cyberspace that fosters trust and innovation.

GOVERNMENTOFZIMBABWE NATIONALCYBER SECURITYSTRATEGYANDACTIONPLAN 10/30/2024

1.2.2.Mission: To protect national interests, enhance cybersecurity awareness, and promote stakeholder collaboration.

1.2.3 Objectives

a. Strengthen the cybersecurity framework and governance. b. Enhance the capacity of institutions and individuals to respond to cyber threats. c. Promote public-private partnerships in cybersecurity. d. Foster cybersecurity awareness and education. e. Develop incident response capabilities. f. Promote innovation in the field of cyber security Improve the nations cyber resilience and risk management posture. 7

Page 8 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

1.3 BACKGROUND

The rapid advancement of technology has ushered in a new era of connectivity and digital innovation across the globe, including Zimbabwe. As the nation embraces digital transformation, the integration of technology into various sectors such as finance, healthcare, education, and governance has become

GOVERNMENTOFZIMBABWE NATIONALCYBER SECURITYSTRATEGYANDACTIONPLAN 10/30/2024

increasingly pronounced. However, with these advancements come significant risks and challenges posed by cyber threats that can undermine national security, economic stability, and public safety. Zimbabwe has witnessed a growing incidence of cyber-related incidents, including data breaches, ransomware attacks, and phishing schemes, which have highlighted vulnerabilities in its cyber landscape. The increasing reliance on digital platforms for both governmental and private sector operations necessitates a strategic response to mitigate these risks. Recognizing the potential impact of cyber threats on its development goals, the government of Zimbabwe has prioritized the establishment of a comprehensive cyber security framework. In recent years, various initiatives have been undertaken to enhance national cyber security capabilities, including the formation of specialized cyber security units, the development of legal frameworks, and participation in international cyber security collaborations. However, the fragmented nature of these efforts underscores the need for a cohesive National Cyber Security Strategy that aligns resources, policies, and stakeholders towards a unified goal. The enactment of the Cyber and Data Protection Act [Chapter 12:07] in 2021 marked a significant legislative milestone, underscoring the nation's commitment to fostering a secure and resilient digital ecosystem. The Act establishes a comprehensive framework for data protection, addressing the growing concerns of privacy and cyber threats. With that in mind and taking into consideration our capabilities, needs, threats and national values as the basis of this strategy. We take heed of ITU’s perspective that culture and national interests shape risk perception and the success of cyber defences. Our strategy is based on national values to ensure maximum buy-in from all stakeholders. The National Cyber Security Strategy for Zimbabwe aims to address these challenges by providing a structured approach to enhance the nation's cyber resilience. It seeks to create a secure digital environment that fosters innovation, protects critical infrastructure, and safeguards the rights of citizens in the digital space. By establishing clear objectives, promoting public-private partnerships, and encouraging awareness and education on cyber security issues, this strategy will lay the foundation for a safer and more secure cyber ecosystem in Zimbabwe. Ultimately, the strategy is not only a response to the current cyber threat landscape but also a proactive measure to position Zimbabwe as a competitive player in the global digital economy. Through concerted efforts and collaboration, Zimbabwe aims to build a robust cyber security framework that protects its national interests and promotes sustainable growth in the digital age. 8

Page 9 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

1.4 RATIONALE

The Republic of Zimbabwe identifies cybersecurity as a national economic and security challenge. The most prevalent cybersecurity challenges in Zimbabwe include exploitation of GOVERNMENTOFtZhIMeBA BnWeEw oNpATeIOrNaALtiCnYBgER eSEnCUvRIiTrYoSTnRAmTEGeYnANt DbAyCT IOaNdPvLAeNrsaries to conduct w10a/3r0/ 2l0i2k4e activities such as disruption of operations of critical infrastructure. Most ICT infrastructure and users in the Republic of Zimbabwe have prioritized efficiency, cost and convenience and overlooked security during development and implementation. As many organisation join the automation train, data safety has taken centre stage. Interconnected ICTs have inherent vendor/manufacturer vulnerabilities that can be exploited by adversaries and expose the Zimbabwean citizens, businesses and government to global threats. Despite a growing number of incidents, governance of cyberspace has remained uncoordinated with no clear structure. Cyber resilience and compliance issues have been growing and need deliberate attention. While Zimbabwe has enacted some laws and formulated policies, there remains need for regular review in order to effectively address emerging risks and threats. Additionally, cybersecurity awareness of citizens is evolving with changes of the threat landscape thus increasing susceptibility to cyber threats. On the other hand, Zimbabwe increasingly continues to face cybersecurity threats leveraging on the above-mentioned challenges. There have been instances where the notorious threat actors and corporate entities have used cyber espionage to gain access to sensitive/classified data for financial gain, political reasons and to gain competitive advantage. Furthermore, as ICTs become more interconnected, systems become susceptible to sabotage through deliberate and malicious acts that may disrupt normal processes and functions or destroy/damage equipment and information. Similarly, cyber subversion through propaganda, fake news and misinformation may undermine trust in the government, authority and competence of leaders thus posing a threat to Zimbabwe’s stability. In addition, terror groups continue to leverage on ICTs (virtual private networks, internet, global applications, social media platforms and websites) for recruitment, radicalization, incitement, financing, training, planning and execution of attacks. Also, there has been an increase in cyber fraud cases through banking/finance, sim swaps and online scams such as digital Ponzi schemes, job scams, fake websites & lotteries, crypto and forex scams, hawala and chop chop schemes among others 9

Page 10 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

GOVERNMENTOFZIMBABWE NATIONALCYBER SECURITYSTRATEGYANDACTIONPLAN 10/30/2024

Cybersecurity domains (includes these/but not limited) 10

Page 11 of 48

GOVERNMENT OF ZIMBABWE NATIONAL CYBER SECURITYSTRATEGY ANDACTION PLAN

1.5 CYBER SECURITY AND THREAT LANDSCAPE IN ZIMBABWE

The cyber security landscape in Zimbabwe is shaped by a combination of technological advancements, GOVERNMENreTgOFuZlIaMtBoABrWy EframNAeTwIONoArLkCsYB,E RaSnECdU ReITYmSTeRArTgEiGnYgAN DthArCeTIaONtsP.L AUN nderstanding this land10s/3c0/a20p24e requires an examination of key components such as the current threat environment, institutional responses, challenges faced, and opportunities for improvement. Zimbabwe as any other connected country has seen an increase in cyber threats, including data breaches, ransomware attacks, and phishing scams. The shift towards digital services, especially during the COVID-19 pandemic, has made organizations more vulnerable to these attacks. Critical sectors such as finance, healthcare, and government are primary targets due to the sensitive data they handle. The financial sector, in particular, has reported incidents of fraud and cyber attacks that threaten consumer trust and financial stability. Criminals and Employees with access to sensitive information pose a risk, whether intentionally or through negligence. This highlights the need for robust internal security measures and training programs. Cyber threat actors are on rise as the threat landscape is increasing. Cybercriminals seeking financial gain through illegal activities like ransomware and fraud have been identified and prosecuted in the country. Hacktivists using hacking to promote political or social causes, terrorists, script-kiddies and organized crime groups coordinating cyber crimes as part of broader criminal enterprises and state-sponsored actors are issues the country is dealing with as any other county. Understanding these diverse actors is crucial for developing effective cyber defense strategies. The enactment of the Cyber Security and Data Protection Act in 2021 marked a significant step towards establishing a legal framework for cyber security in Zimbabwe. This Act provides mechanisms for data protection, incident response, and the prosecution of cyber offenses. The Act also aims to foster collaboration between government, private sector, and civil society. Despite the establishment of some cybersecurity institutions, a fragmented approach to cyber security exists, with varying levels of engagement and capacity among different sectors and stakeholders. Efforts to raise awareness about cyber security risks among citizens and businesses are being implemented, though more extensive campaigns are needed to ensure widespread understanding and preparedness. Many organizations, especially in the public sector, face budget constraints that hinder their ability to invest in comprehensive cyber security measures, personnel training, and technology upgrades. There is a shortage of skilled professionals in the field of cyber security in Zimbabwe, making it challenging to build capable teams to manage and mitigate cyber threats effectively. 11