IT Audit & Cybersecurity Experts in Kenya.
Helping banks, fintechs & corporates reduce risk, improve compliance & strengthen IT controls.
Book Free Risk Assessment.

  • Cyber Resilience

    Kenya’s National Cybersecurity Agency (NCSA): Legal Notice No. 89 Explained.

    In June 2026, Parliament approved the National Cybersecurity Agency Order, 2026 issued under Legal Notice No. 89, establishing the National Cybersecurity Agency (NCSA) as Kenya’s central institution for cybersecurity regulation, coordination and response. For every board that believed its cyber compliance story ended with its sector regulator, the landscape…

    Continue Reading

  • Technology Risk Management Guide for SACCOs: Identify, Quantify, Monitor and Report.

    A practical, end-to-end framework for deposit-taking SACCOs in Kenya and East Africa — from risk governance and identification through inherent and residual scoring, risk appetite, KRIs, board dashboards, treatment planning and maturity assessment, aligned to SASRA expectations.

    Continue Reading

  • Staff performing fraud detection analysis

    Cyber Security Risks in SACCOs: Protecting Member Funds, SASRA Compliance and Trust

    Cyber risk in a SACCO is not an IT-department problem. It is a member-funds, SASRA-compliance and institutional-survival problem. Kenya’s deposit-taking SACCOs now run the technology stack of a bank i.e core banking, mobile and USSD channels, M-Pesa integrations, agency banking often with the security budget of a small business,…

    Continue Reading

  • SASRA 2026 IT Audit Requirements: A Compliance Guide for Kenyan SACCOs.

    SASRA has entered its most demanding regulatory cycle to date. With tightened audit standards, mandatory audited financial statement deadlines, auditor quality controls, and licence revocations for non-compliance, Kenya’s 176 deposit-taking SACCOs face a technology governance environment that demands professional, risk-based IT audit coverage — not just to satisfy the…

    Continue Reading

  • Preparing for an ODPC Data Protection Compliance Audit in Kenya

    Kenya’s data protection landscape has shifted from awareness to active enforcement. The Office of the Data Protection Commissioner (ODPC) has issued 184 compensation orders, 134 enforcement notices, and 20 penalty notices — and the proposed amendment bill threatens to multiply financial exposure dramatically. For organisations across Kenya and East…

    Continue Reading

  • Continuous IT Monitoring

    CBK’s New Banking Sector Cybersecurity Operations Centre (BS-SOC): What Your Bank Must Do Now

    The Central Bank of Kenya has established the Banking Sector Cybersecurity Operations Centre and commenced harmonising its cybersecurity guidelines with the Computer Misuse and Cybercrimes Regulations 2024. For every regulated financial institution in Kenya, this creates new reporting obligations, control requirements, and governance expectations that demand immediate attention —…

    Continue Reading

  • Third-Party Cybersecurity Risk

    When an organisation shares its data, systems, or network access with external vendors, it inherits that vendor’s cybersecurity posture—whether it knows it or not. Understanding, assessing, and continuously monitoring third-party risk is now a core governance imperative. Executives and directors must ensure that third-party cyber risk management is integrated…

    Continue Reading

  • Understanding County Government ICT Operations Technology Risks: A Framework for IT Audit Risk, and Controls

    Kenya’s 47 county governments collectively manage billions of shillings annually, operate critical citizen-facing services, and run increasingly complex ICT environments. Kenya’s devolved governments represent one of the most consequential — and most under-audited — ICT environments in East Africa. The stakes are high: county systems process revenue that funds…

    Continue Reading

  • A woman using a laptop navigating a contemporary data center with mirrored servers.

    Understanding Hospital Technology Risks: An IT Audit Risk & Controls Guide

    The hospitals of East Africa are at an inflection point. Digital transformation is arriving at scale — through SHA, through the Digital Health Act etc, with this digital expansion comes a enlarged risk surface. Patient data is among the most sensitive personal information in existence. Clinical system failures can…

    Continue Reading