ICT Authority steps up cybersecurity for government systems

  • Government systems face stronger cybersecurity safeguards.
  • Stakeholders are testing new risk assessment tools.
  • Framework gaps are being addressed before certification.

Kenya is stepping up efforts to protect government digital systems and Critical Information Infrastructure (CII) from cybersecurity threats that could disrupt essential services, compromise sensitive information and undermine confidence in the country’s rapidly expanding digital economy.

More public services and critical operations are moving onto interconnected digital platforms, raising the stakes and the need for institutions to identify vulnerabilities early, assess their exposure and put in place coordinated measures to manage cyber risks.

Against this backdrop, the ICT Authority, through the Kenya Digital Economy Acceleration Project (KDEAP), has convened a weeklong stakeholder workshop in Nairobi to assess the status and progress of the Vulnerability Assessment for National ICT Cybersecurity Risk and Critical Information Infrastructure project.

This initiative seeks to establish a common national approach to cybersecurity risk management across the public sector and nationally designated CII.

Stakeholders are reviewing the standards, controls, tools and operational frameworks outlined in the National Cybersecurity Strategy. Once endorsed, the measures are expected to be adopted uniformly across the public sector and nationally designated CII.

Also under scrutiny is whether the proposed framework is practical enough for national implementation before certification begins. Participants are assessing the practicality of the proposed standards and certification process, including the skills, resources and time institutions will require to use the National Information Security Framework Audit and Risk Register Toolkit s effectively.

READ ALSO:

Sacco sector assets hit Sh1.25 trillion in Q2 2026

Beyond that, stakeholders are examining gaps and inconsistencies in the framework documents, control wording, scoring methodology and supporting toolkits. Addressing these weaknesses before national certification is actualised is critical to ensuring that institutions apply the framework consistently and that cybersecurity assessments provide a reliable picture of the risks facing government systems and critical infrastructure.

This review is also intended to strengthen institutional capacity to identify vulnerabilities, assess their potential impact, document risks and track mitigation measures.

Structured risk management

The Risk Register Toolkit s will provide a structured mechanism for recording and managing identified cybersecurity risks, while the audit framework is expected to support assessment of institutional compliance and preparedness.

For CII, the implications of weak cybersecurity can extend beyond individual institutions. Disruption of systems supporting essential services and nationally significant operations could have wider consequences, making resilience and risk preparedness a critical component of Kenya’s digital transformation.

Consequently, the workshop forms part of broader KDEAP efforts to ensure that the expansion of Kenya’s digital economy is matched by stronger cybersecurity governance, technical capacity and operational safeguards.

Its outcomes will inform refinement of the national cybersecurity framework and guide the next steps towards implementation, validation and certification. Ultimately, the test will be whether the final framework can translate national cybersecurity standards into practical measures that institutions can consistently apply.

By Hillary Muhalya

Get more stories from our website: Sacco Review

For comments and clarifications, write to: Saccoreview@shrendpublishers.co.ke

Kindly follow us via our social media pages on Facebook: Sacco Review Newspaper for timely updates

Stay ahead of the pack! Grab the latest Sacco Review newspaper!  

Sharing is caring!

Leave a Reply

Don`t copy text!