(2) A sectoral CERT shall, within thirty days, submit to the Malawi CERT a monthly
report covering the operations of that CERT, including a report of a cybersecurity
incident.
(3) The Malawi CERT shall establish a cybersecurity incident reporting and information
sharing platform to enable a sectoral CERT, an owner of critical information
infrastructure, individuals and any other relevant institution, report a cybersecurity
incident.
(4) The Malawi CERT shall, upon receipt of information in respect of a cybersecurity
incident, circulate the information to the relevant sectoral CERT, the owner of critical
information infrastructure, individual and any other relevant institution.
(5) A person in charge of an institution shall report a cybersecurity incident to the relevant
sectoral CERT and to the Malawi CERT within twenty four hours after the incident is
detected.
(6) A person who contravenes subsection (5) is liable to pay to the Authority the
administrative penalty specified in the Schedule.
Cybersecurity
incident point
of contact
25. - (1) The Malawi CERT shall establish a cybersecurity incident point of contact to
facilitate –
(a) the reporting of a cybersecurity incident by the general public; and
(b) international co-operation in cybersecurity matters.
(2) An institution that is not affiliated to a designated sectoral CERT shall report a
cybersecurity incident to the Malawi CERT through the cybersecurity incident point of
contact established under subsection (1).
(3) An individual may report a cybersecurity incident to the Malawi CERT through the
cybersecurity incident point of contact established under subsection (1).
22