The IRA Cybersecurity Guidance Note: A Compliance Guide for Kenyan Insurers
Kenya’s insurers and reinsurers now run underwriting, policy administration and claims on digital platforms wired to banks, insurtechs and payment gateways. The regulator has issued an IRA Cyber Security Guidance which is a practitioner’s guide to monitoring and managing major and emerging cyber security risks, cyber breach notification rule and board obligations.
A cyber attack on an insurer is not merely an IT outage. It halts claims settlement when policyholders need it most, exposes the KYC and medical data of thousands, invites regulatory sanction, and quietly erodes the trust on which every policy is sold. With the IRA’s Guidance Note on Cybersecurity now in force, cyber risk has moved from the server room to the boardroom, and become a supervised compliance obligation with hard deadlines.
Why Cyber Risk Is Now an Insurance Board Issue
Kenya’s insurance industry has digitised rapidly. Insurers regulated by the Insurance Regulatory Authority (IRA) now onboard customers online, price risk with actuarial engines, process claims through digital platforms, and integrate with bancassurance partners, mobile money, credit bureaus and a growing insurtech ecosystem. Each integration widens the attack surface, and each holds some of the most sensitive personal data any institution keeps such as national ID copies, medical histories, financial records and beneficiary details.
In 2025 the IRA issued its Guidance Note on Cybersecurity for the Insurance Industry, signed by the Commissioner of Insurance. The message was unambiguous: cybersecurity is no longer an IT-department concern but a governance responsibility carrying supervised, enforceable obligations. All licensed insurers and reinsurers are required to familiarise themselves with the Guidance Note and implement it fully and on time. Get Our Insurance IT Audit Compliance Bundle.
A successful attack strikes at four things every insurer exists to protect:
Compromise of policy administration, claims or underwriting systems can delay or deny legitimate claims, expose sensitive personal and medical data, and leave vulnerable policyholders without the financial protection they paid for.
Ransomware against a claims platform or core policy system can freeze settlements, renewals and new business for days, a direct hit to solvency, service and reputation.
Insurance is a promise to pay when things go wrong. A publicised breach or a data leak of policyholder records corrodes that promise, driving lapses, distribution-partner flight and reputational damage that outlasts the incident.
The IRA Guidance Note, the Data Protection Act, 2019 and the Computer Misuse and Cybercrimes Act now converge on the insurer. A breach frequently exposes gaps in exactly the governance, reporting and control areas these regimes police, inviting directives, penalties and heightened supervision.
The Core Message
Cyber risk in an insurer is not an IT problem. It is a policyholder-protection, regulatory-compliance and institutional-survival problem, and the IRA Guidance Note has made board and senior-management ownership of it a supervised requirement, not a matter of good practice.
Major Cyber Security Risks Facing Insurers
Across IT audit and assurance work with regulated financial institutions in Kenya and East Africa, the same risk themes recur in the insurance sector, sharpened by the industry’s data sensitivity and its dependence on a chain of third parties:
Underwriting files, medical records, ID copies and claims documentation leaking from unsecured databases, misconfigured storage or discarded hardware trigger both IRA and ODPC obligations.
Encryption of claims and policy administration systems halts settlements, while data-theft extortion threatens release of policyholder records. Insurers with untested or co-located backups face the hardest recovery choices.
Manipulated claims workflows, redirected settlement payments and collusive insider adjustments convert weak application controls and poor segregation of duties directly into financial loss.
Spoofed emails targeting finance and claims staff redirect supplier or beneficiary payments and harvest credentials for core systems. Human error remains the thinnest control layer.
Core system vendors, TPAs, aggregators, bancassurance partners, bulk-SMS and payment providers hold privileged, often remote, access. A compromise at one supplier can cascade across many insurers at once.
Shared administrator accounts, dormant IDs of exited staff and agents, absent multi-factor authentication and unreviewed access to policy and claims systems are among the most frequent audit findings.
Staff or vendors with excessive rights can alter policy records, suppress alerts, create fictitious claims or exfiltrate data. Small IT teams magnify the segregation-of-duties gap.
Ageing policy administration platforms, unpatched servers and flat networks give attackers easy lateral movement once a single workstation or web front-end is compromised.
Emerging Cyber Risks to Watch
Deepfake voice and video in support of fraudulent claims, synthetic-identity applications, and highly convincing AI-written phishing in English and Kiswahili are lowering the skill barrier for attackers while insurers’ own adoption of AI in underwriting and claims introduces model-integrity and data-poisoning risks.
As insurers connect to aggregators, bancassurance channels, mobile money and credit reference bureaus, insecure or undocumented APIs become an attack surface that traditional perimeter controls never see.
Migration of policy systems, data lakes and backups to the cloud introduces exposed storage, weak tenant isolation and unclear shared-responsibility boundaries, a leading cause of large data exposures.
Malicious updates or compromised components in widely used insurance software could affect multiple carriers simultaneously, a systemic risk regulators across Africa increasingly flag.
Since Kenya’s February 2024 FATF grey-listing, AML/CFT scrutiny of the sector has intensified. Cyber-enabled fraud, account takeover and identity abuse now sit at the intersection of cybersecurity and money-laundering controls, demanding a joined-up response.
Beyond the Guidance Note, the draft Insurance (Corporate Governance) Guidelines, 2025 and proposals to recognise cyber and virtual-asset insurance as new business classes signal that supervisory expectations will keep tightening. Yesterday’s acceptable posture becomes tomorrow’s compliance finding.
What the IRA Guidance Note Requires
The Guidance Note sets minimum standards for managing cybersecurity risk across the sector. The core obligations that every licensed insurer and reinsurer must be able to demonstrate are:
| # | Requirement | What Good Looks Like |
|---|---|---|
| 1 | Formal cybersecurity strategy, policy and procedures | Documented, risk-based, framework-aligned (ISO 27001, NIST CSF), and covering the full insurance technology estate |
| 2 | Board and senior-management approval and ownership | Strategy approved by the board; cyber risk a standing board/risk-committee agenda item with clear accountability |
| 3 | Cybersecurity expertise on the board | At least one director with demonstrable cybersecurity experience or expertise |
| 4 | 24-hour reporting of material incidents | Defined triage and escalation so a material incident reaches IRA within 24 hours of confirmation or reasonable detection |
| 5 | Quarterly incident reporting | All cybersecurity events reported to IRA within 15 days after the end of each quarter |
| 6 | Annual policy review and update | Cybersecurity policies reviewed and refreshed at least annually against the evolving threat and regulatory landscape |
| 7 | People controls — awareness & hygiene | Staff-wide security awareness training, regular phishing simulations and cyber-hygiene practices |
| 8 | Resilience & recovery | Robust, tested backup protocols and incident response capable of restoring critical services within tolerance |
Two features distinguish this regime from generic good practice. First, the cybersecurity strategy is not only board-approved but visible to the regulator, posture becomes a supervised artefact. Second, the obligations are time-bound and evidenced: the regulator can now ask precisely when an incident was detected, when it was reported, and when policies were last reviewed. Documentation that cannot answer those questions is itself a finding.
Additional Cybersecurity controls should also be implemented, these include controls listed in our Cybersecurity risks in SACCOs article.
The 24-Hour Breach Reporting Requirement
The headline obligation and the one insurers are least prepared for is mandatory reporting of material cybersecurity incidents to the IRA within 24 hours of the incident being confirmed or reasonably detected. The Guidance Note defines what qualifies as material, and the clock starts on detection, not on convenience.
What Counts as a Material Incident
Disruption to critical systems, services or platforms; unauthorised access to, or loss of, sensitive customer data; and financial losses affecting the insurer, its clients or third parties. In practice, a ransomware attack that shuts a claims platform, or an exposure of policyholder records, triggers the 24-hour clock.
Meeting a 24-hour deadline is a detection-and-decision problem long before it is a reporting problem. An insurer that only reviews logs at end of day, or that has no pre-agreed definition of “material,” will miss the window not because it is negligent but because it is unprepared. A workable reporting capability has four moving parts:
Continuous monitoring and alerting on core, claims and customer-facing systems so a material event is actually noticed in hours, not discovered days later. The 24-hour clock is only as good as the moment of detection.
A pre-agreed materiality standard mapped to the Guidance Note’s criteria, so the on-call team can decide “is this reportable?” against a checklist rather than debating it while the clock runs.
A named accountable owner, a drafted notification template and a known IRA submission route, plus parallel awareness of the separate 72-hour ODPC obligation where personal data is involved.
A defensible timeline evidencing detection, classification, escalation and submission, the record the regulator will ask for, and the feed into the 15-day quarterly return.
IT Audit Methodology, Approaches, Tools & Best Practices
Assuring an insurer’s posture against the Guidance Note calls for a structured, risk-based IT audit rather than a checklist walk-through. Our methodology draws on ISACA IT Audit Standards, COBIT 2019, the NIST Cybersecurity Framework and ISO/IEC 27001:2022, adapted to the IRA-regulated insurance environment and the sector’s distinctive application landscape. Get Our Insurance IT Audit Compliance Bundle.
Map the insurer’s critical systems and data flows such as policy administration, claims management, underwriting and actuarial engines, the digital insurance platform, reinsurance and regulatory-reporting systems, and payment and bancassurance integrations, and align scope to the Guidance Note, the risk profile and the board’s appetite.
Assess inherent risk across IT governance, identity and access management, change management, operations, cybersecurity, data protection, third-party risk and resilience, and prioritise procedures where risk to policyholders and compliance is greatest.
Evaluate IT general controls and insurance-application controls through inquiry, observation, inspection and re-performance, using data analytics (CAATs) over claims and policy data where volumes justify automated testing.
Test the 24-hour reporting capability end-to-end i.e., detection, materiality classification, escalation and submission — and validate backup and recovery through evidence of actual restore tests, not policy statements.
Issue a board-level report with risk-rated findings, root causes and actionable, owner-and-date remediation, then track findings to closure, the discipline the regulator increasingly expects to see evidenced.
Tools & Best Practices That Should Be in Place
Board-approved cybersecurity strategy and policies mapped to ISO 27001 / NIST CSF, the Data Protection Act and the IRA Guidance Note, with a maintained cyber risk register.
MFA on all remote and privileged access, unique accounts, least-privilege, and quarterly access reviews across policy, claims and underwriting systems.
Centralised, tamper-evident logging and SIEM/alerting over critical systems, enabling detection within the hours the 24-hour rule demands.
Offline or immutable backups, network segmentation, and a rehearsed, regularly tested incident response and business-continuity plan.
Security assessments, contractual security clauses and monitored, time-bound remote access for TPAs, insurtech partners and core-system vendors.
Annual security awareness training, recurring phishing simulations, and clear reporting channels i.e., the human controls the Guidance Note explicitly requires to be in place.
A Practical Risk Assessment Matrix
Insurers should assess each cyber risk for likelihood and impact (financial, regulatory, operational, customer and reputational), record inherent scores, then re-score after considering control effectiveness to obtain the residual risk, the figure that should be compared against the board-approved risk appetite thresholds as part of the health insurers’ IT compliance obligations.
| Likelihood ↓ / Impact → | Minor | Moderate | Major | Severe |
|---|---|---|---|---|
| Almost Certain | Medium | High | Critical | Critical |
| Likely | Medium | High | High | Critical |
| Possible | Low | Medium | High | Critical |
| Unlikely | Low | Low | Medium | High |
Illustratively, a policyholder data breach in an insurer with no continuous monitoring typically scores Likely × Severe = Critical inherently; with encryption, access controls, logging and tested response in place, the residual score may fall to Possible × Major = High and onto a defined remediation path. Risk appetite threshold breaches must always be measured against residual scores.
How Management Should Monitor Cyber Risk: KPIs & KRIs for the Board
The Guidance Note puts the board on the hook, so the board needs numbers not a technical narrative. A concise set of Key Risk Indicators (leading signals of rising exposure) and Key Performance Indicators (control-health measures) turns cyber posture into something a board can govern quarter on quarter.
| Metric | Type | Example Threshold | Why the Board Cares |
|---|---|---|---|
| Material incidents reported to IRA within 24h | KPI | 100% within window | Direct measure of Guidance Note compliance |
| Mean time to detect a material incident | KRI | < 12 hours | Determines whether the 24h notification can be met |
| Confirmed fraud / breach losses per quarter | KRI | Within board-set appetite | Policyholder-fund and P&L exposure |
| Critical vulnerabilities open beyond 30 days | KRI | 0 tolerated | Leading indicator of breach likelihood |
| Policy & claims system uptime | KPI | ≥ 99.5% | Operational resilience and policyholder service |
| Privileged accounts reviewed in the quarter | KPI | 100% | Insider-threat control health |
| Backup restore tests passed | KPI | 100% of scheduled tests | Ransomware survivability |
| Phishing simulation failure rate | KRI | < 10%, trending down | Human-layer exposure |
| Critical third parties with current assessments | KPI | 100% | Insurtech and vendor supply-chain exposure |
| High-rated audit findings overdue | KRI | 0 overdue | Governance discipline; IRA readiness |
A Simple Board Reporting Dashboard
A one-page dashboard, (RAG-rated), trended quarter-on-quarter and annotated with actions is far more effective than a fifty-page technical report. An illustrative snapshot:
Each red or amber indicator should arrive with a named owner, a remediation action and a remediation date turning the dashboard from a scoreboard into a management tool. Between quarterly reports, management should operate continuous monitoring and escalate appetite breaches immediately rather than waiting for the next committee cycle.
We have created a complete IRA-aligned IT compliance toolkit purpose-built for Kenya’s insurers, reinsurers and intermediaries with a Risk Register that has 126 controls across 19 domains, 126+ IT audit procedures, and 6 management and board reporting dashboards, Get Our Insurance IT Audit Compliance Bundle – Instant download
Enforcement Posture
The IRA has framed the Guidance Note as a floor, not a suggestion. The Commissioner’s circular requires all licensed insurers and reinsurers to familiarise themselves with it and ensure full and timely implementation, language that establishes a clear supervisory expectation and a baseline against which firms will be assessed.
Three signals define the enforcement direction of travel. First, the obligations are time-bound and measurable: 24-hour incident reports, 15-day quarterly returns and at-least-annual policy reviews give supervisors objective tests of compliance rather than subjective judgements of “adequacy.” Second, accountability is personal: by requiring board approval and a cyber-competent director, the regime makes senior individuals answerable, not just the IT function. Third, cybersecurity sits within a tightening wider framework i.e., the Data Protection Act’s ODPC penalties, the Computer Misuse and Cybercrimes Act, and the draft Insurance (Corporate Governance) Guidelines, 2025, so a single incident can trigger overlapping obligations and multiple regulators.
The Practical Reality
Industry practitioners have warned that many insurers remain under-prepared for the mandatory reporting deadlines. The gap is rarely intent, it is the absence of the detection, classification and escalation machinery needed to meet a 24-hour clock. That gap is precisely what a targeted IT audit surfaces before the regulator, or an attacker.
Persistent Challenges
Even well-intentioned insurers face structural obstacles to meeting the Guidance Note, and naming them honestly is the first step to closing them:
Ageing policy administration and claims platforms are hard to log, patch and monitor to the standard continuous detection now demands, yet replacing them is a multi-year investment.
The requirement for a cyber-competent director is difficult to satisfy in a shallow local talent pool, and a single appointment does not by itself build genuine board oversight.
Many insurers still rely on periodic log review rather than continuous monitoring, leaving the 24-hour clock structurally unreachable until detection capability is built.
Reliance on TPAs, aggregators, bancassurance partners and insurtechs spreads accountability and data across parties the insurer does not directly control.
Medical, financial and identity data across underwriting and claims raises the stakes of any breach and the bar for data-protection compliance.
Competition for scarce security skills and pressure on expense ratios leave many carriers running a bank-grade technology estate on a fraction of the resourcing.
Conclusion: Cyber Resilience as a Policyholder-Protection Duty
For Kenya’s insurers, the IRA Guidance Note reframes cybersecurity as inseparable from the core promise of the industry to protect policyholders and pay when it matters. Layered defences, disciplined access management, tested resilience, credible 24-hour reporting and honest board-level measurement are what stand between policyholder data and a well-equipped population of attackers. Insurers that treat cyber risk as a governed, measured and independently assured discipline will satisfy the IRA, protect their policyholders, and preserve the trust on which every policy depends.
In an era where insurers process the most sensitive personal data any institution holds, the cost of weak cyber governance is measured not only in breach losses and regulatory sanction, but in the erosion of the trust that makes insurance possible. Robust cybersecurity is an investment in the promise itself.


