(2) A sectoral CERT shall, within thirty days, submit to the Malawi CERT a monthly report covering the operations of that CERT, including a report of a cybersecurity incident. (3) The Malawi CERT shall establish a cybersecurity incident reporting and information sharing platform to enable a sectoral CERT, an owner of critical information infrastructure, individuals and any other relevant institution, report a cybersecurity incident. (4) The Malawi CERT shall, upon receipt of information in respect of a cybersecurity incident, circulate the information to the relevant sectoral CERT, the owner of critical information infrastructure, individual and any other relevant institution. (5) A person in charge of an institution shall report a cybersecurity incident to the relevant sectoral CERT and to the Malawi CERT within twenty four hours after the incident is detected. (6) A person who contravenes subsection (5) is liable to pay to the Authority the administrative penalty specified in the Schedule. Cybersecurity incident point of contact 25. - (1) The Malawi CERT shall establish a cybersecurity incident point of contact to facilitate – (a) the reporting of a cybersecurity incident by the general public; and (b) international co-operation in cybersecurity matters. (2) An institution that is not affiliated to a designated sectoral CERT shall report a cybersecurity incident to the Malawi CERT through the cybersecurity incident point of contact established under subsection (1). (3) An individual may report a cybersecurity incident to the Malawi CERT through the cybersecurity incident point of contact established under subsection (1). 22

Select target paragraph3