Principal Secretary for Internal Security and National Administration, Dr. Raymond Omollo, said cases of cyber-attacks targeting government institutions had risen in recent years, with the state estimating losses running into billions of shillings annually.
Speaking during the official opening of the sixth annual Information Security Management Systems (ISMS) Conference in Naivasha, the PS said the government was committed to ensure that threats posed by AI and cybercrime were addressed promptly.
“We need to make amendments to some of the regulations, including the Act, and I want to assure all that the government is fully committed to delivering a secure cyberspace,” he said.
The PS said AI presented both opportunities and risks, warning that the country faced heightened exposure to criminal activities hence the need develop new legislation to confront new forms of fraud, identity manipulation and misinformation ahead of the next general election.
“As we get ready for the next general elections, we are seeing a lot of increased risks associated with AI-generated defects and manipulation of public opinion online,” he said.
On digital service delivery, Omollo said the eCitizen platform now supports more than 24,000 government services, serves over 15 million users, and processes roughly 500,000 transactions daily
He added that a major digital push was under way in the health sector, including digitization of health records supported by the Digital Health Authority and Social Health Authority.
He said measures are already in place, including enforcement of the existing Act, the operationalization of the National Computer and Cybercrimes Coordination Committee (NC4), and the rollout of the Critical Information Infrastructure Protection and Cybersecurity Management Regulations, 2024.
Omollo welcomed Parliament’s recent approval of the National Cybersecurity Agency, saying it would strengthen coordination and improve the country’s readiness against evolving threats.
The PS urged local investment in cybersecurity innovation, saying Kenya should aim to export, not just import, cybersecurity solutions.
On his part, the Director National Computer and cybercrimes coordination committee (NC4) Dr. James Kimuyu said that the country had made strides in dealing with cyber threats.
He said that NC4 had developed a draft national cyber-security policy and reviewed the national cybersecurity strategy which was awaiting policy adoption.
“The other regulations in terms of issues of virtual assets are one of our partners in the Central Bank of Kenya so that we’re able to have a digital space that is in order,” he said.
The director of Standards Development and Trade in KEBS Eng. Zachariah Lukorito said that the country was in an era defined by rapid digital transformation, artificial intelligence, cloud computing, big data, and interconnected systems.
“However, as these technologies evolve, so do the complexity, scale, and simplification of the cyber threats and in this environment, information security management systems are no longer optional,” he said.
The three-day conference, organised jointly by NC4 and the Kenya Bureau of Standards (KEBS), brought together regulators, private sector players and development partners to shape recommendations on information security standards.
By Erastus Gichohi
