KSh 2.1 Billion. That’s the estimated annual cost of cybercrime to Kenyan organisations (Source: Communications Authority, 2024). It’s not a statistic from a far-off jurisdiction — it’s happening right here, right now, to businesses like those we recently sat with as Patricia Wanjama facilitated a board training session on technology risk.

So, what exactly is cybersecurity? Simply put, it is the practice of defending computers, servers, mobile devices, networks and data from malicious attacks — also known as information or electronic security.

The threats are varied and evolving: Malware (viruses, trojans, spyware, ransomware) infiltrates systems quietly or aggressively. SQL Injection exploits vulnerable entry points to steal sensitive data — financial records, intellectual property, client information. Phishing uses convincing fake emails to trick employees into handing over credentials or authorising fraudulent payments. Man-in-the-middle attacks intercept communications meant for you, while Denial of Service attacks flood systems with traffic, locking out legitimate users.

So how do Heads of Technology fight back? By layering defences across the organisation’s digital estate — securing networks, applications and information systems, tightening operational controls around data access, and building robust disaster recovery and business continuity plans so the organisation can bounce back quickly if and unfortunately, when incidents occur.

But here’s the thing — cybersecurity isn’t just an IT problem. It’s a governance one. Boards must provide strategic oversight: understanding how technology underpins the organisation’s mission, defining risk appetite, allocating adequate resources, and demanding regular cybersecurity dashboards. Boards should also build technology expertise into their ranks, stress-test resilience, approve key policies annually, and champion a cyber-aware culture where everyone — from the boardroom to the front desk — knows their role in protection.

And individually? Update your software regularly, install reputable antivirus protection, use strong passwords, avoid opening attachments or clicking links from unknown senders, and steer clear of unsecured public Wi-Fi.
Cybersecurity is everyone’s responsibility — but it starts with leadership.

🔹 Akira Consult Limited is ready to walk alongside organisations on their Technology Governance journey — from board training to policy frameworks and resilience planning.

So….Is your board truly governing technology — or hoping nothing goes wrong?
Let’s talk. 👇
hashtagTechnologyGovernance hashtagCyberSecurity hashtagBoardGovernance