2017-08-18
The Central Bank of Kenya issues a Guidance Note on Cybersecurity to licensed institutions, outlining minimum requirements for developing and implementing strategies, policies, and procedures to mitigate cyber risks. The board and senior management are responsible for formulating and implementing cybersecurity strategies, with internal and external auditors assessing cyber threat landscapes. Institutions should ensure third-party compliance with legal and regulatory frameworks and provide cybersecurity awareness training to all employees. Regular reviews of cybersecurity strategies are mandated, with immediate and quarterly incident reporting to the Central Bank of Kenya.