- The ICT Authority is reviewing cybersecurity standards and tools for government systems and Critical Information Infrastructure.
- Stakeholders are assessing whether proposed audit, risk-management and certification mechanisms are practical for national implementation.
- The initiative seeks to strengthen Kenya’s capacity to identify vulnerabilities and manage cybersecurity risks consistently.
Kenya is stepping up efforts to protect government digital systems and Critical Information Infrastructure (CII) from cybersecurity threats that could disrupt essential services, compromise sensitive information and undermine confidence in the country’s rapidly expanding digital economy.
The stakes are rising as more public services and critical operations move onto interconnected digital platforms, increasing the need for institutions to identify vulnerabilities early, assess their exposure and put in place coordinated measures to manage cyber risks.
Against this backdrop, the ICT Authority, through the Kenya Digital Economy Acceleration Project (KDEAP), has convened a week-long stakeholder workshop in Nairobi to assess the status and progress of the Vulnerability Assessment for National ICT Cybersecurity Risk and Critical Information Infrastructure project.
The initiative seeks to establish a common national approach to cybersecurity risk management across the public sector and nationally designated Critical Information Infrastructure.
Stakeholders are reviewing the standards, controls, tools and operational frameworks outlined in the National Cybersecurity Strategy. Once endorsed, the measures are expected to be adopted uniformly across the public sector and nationally designated CII.
The workshop is also testing whether the proposed framework is practical enough for national implementation before certification begins.
Participants are assessing the practicality of the proposed standards and certification process, including the skills, resources and time institutions will require to use the National Information Security Framework Audit and Risk Register Toolkits effectively.
Stakeholders are further examining gaps and inconsistencies in the framework documents, control wording, scoring methodology and supporting toolkits.
Addressing these weaknesses before national certification is actualised is critical to ensuring that institutions apply the framework consistently and that cybersecurity assessments provide a reliable picture of the risks facing government systems and critical infrastructure.
Identifying and managing cyber risks
The review is also intended to strengthen institutional capacity to identify vulnerabilities, assess their potential impact, document risks and track mitigation measures.
The Risk Register Toolkits will provide a structured mechanism for recording and managing identified cybersecurity risks, while the audit framework is expected to support assessment of institutional compliance and preparedness.
The emphasis on systematic risk assessment is consistent with the ICT Authority’s longstanding information-security mandate, which includes developing information-security standards, undertaking risk assessments of government ICT infrastructure and strengthening protection of critical information assets.
For Critical Information Infrastructure, the implications of weak cybersecurity can extend beyond individual institutions. Disruption of systems supporting essential services and nationally significant operations could have wider consequences, making resilience and risk preparedness a critical component of Kenya’s digital transformation.
Securing Kenya’s digital transformation
The workshop therefore forms part of broader KDEAP efforts to ensure that the expansion of Kenya’s digital economy is matched by stronger cybersecurity governance, technical capacity and operational safeguards.
Its outcomes will inform refinement of the national cybersecurity framework and guide the next steps towards implementation, validation and certification.
The immediate test will be whether the final framework can translate national cybersecurity standards into practical measures that institutions can consistently apply.
READ ALSO: TSC may change how co-curricular activities are assessed in promotion interviews
As Kenya becomes increasingly dependent on digital infrastructure, securing the systems behind government and critical services is no longer simply an ICT responsibility — it is a key requirement for protecting the continuity, reliability and trustworthiness of the country’s digital economy.
By Hillary Muhalya
Get more stories from our website: Education News
To write to us or offer feedback, you can reach us at: editor@educationnews.co.ke
You can also follow our social media pages on Twitter: Education News KE and Facebook: Education News Newspaper for timely updates.
>> Click here to stay up-to-date with trending regional stories
Stakeholders during a cybersecurity workshop convened by the ICT Authority through the Kenya Digital Economy Acceleration Project in Nairobi. The initiative seeks to strengthen protection of government digital systems and Critical Information Infrastructure. Photo: Courtesy





