Incident-Report Drafting for Operators of Critical Infrastructure
Once Zambia’s Cyber Security Act is in force, operators of registered critical information infrastructure must notify the national agency of incidents immediately and file a preliminary report within twelve hours of that notice, in a form the agency prescribes.
Evidence
Zambia’s Cyber Security Act, 2025 (No. 3 of 2025) requires a “controller” of registered critical information or critical information infrastructure to notify the Agency immediately of a perceived or actual cyber security incident, in a manner the Agency determines (section 17(1)); to submit a preliminary incident report within twelve hours of notifying the Agency, in a prescribed manner and form (17(2)); and to file a detailed report once the incident is resolved (17(3)). The Zambia Cyber Incident Response Team is to provide alerts and warnings on threats and vulnerabilities (6(1)(c)) and to coordinate sectoral response teams (6(1)(e)). The Act comes into operation on a date the President appoints by statutory instrument; commencement, the prescribed report form, and which operators will be registered were not verified. For scale in a neighbouring market, the Communications Authority of Kenya’s Q4 FY2025/26 statistics (Table 22) show 11.12 billion cyber threats detected in FY2025/26 (up 29.0 percent) and 83.1 million advisories issued (up 60.8 percent). DDoS detections rose 114.3 percent over the year to 72.2 million, but about 63 million of them fall before January 2026 and DDoS is under 1 percent of all detections. Detection counts may reflect sensor coverage rather than any one operator’s exposure. A report-drafting and advisory-triage assistant is an AfriAI build hypothesis; these sources do not show demand or willingness to pay.
First customer
Operators whose systems are registered as critical information infrastructure in Zambia (which operators will be registered was not verified), and the sectoral response teams that would collect and coordinate their reports.
Build path
- 1. Build a configurable preliminary-report drafter that maps an operator’s alerts and logs to the report fields the Agency prescribes and tracks the twelve-hour clock; rehearse it in tabletop drills.
- 2. Ingest advisories, match them to the operator’s asset inventory, and use a language model only to summarise them into plain-language actions with citations and human approval.
- 3. Pilot with one operator or sectoral response team and measure time-to-report and mis-prioritisation.
Risks
- Incident data is sensitive and must stay in-country or on-premises.
- A model error in security guidance can cause harm; the assistant must cite its sources and defer to people.
- The report form, the registration process, and the commencement date are not yet known.
Next action
Ask the Zambia Cyber Security Agency for the prescribed section 17 report form and the registration timetable; interview six security leads at likely operators on how long a preliminary report takes today.
Last reviewed 2026-09-29 · Monthly review cadence
Get the next Field Desk brief by email
Sourced African tech signals — one email, every Monday.
Read the weekly radar
Signals that mature into teardowns like this one — delivered every week.
Subscribe on the blogOpportunity teardowns are editorial analysis, not investment, financial, or business advice. Market sizes and projections are estimates — do your own diligence. Read the full disclaimer.