Home / Blog / GRC & Compliance

Aligning to the CBK Guidance on Cybersecurity: A Practical Compliance Roadmap

The Central Bank of Kenya has made its position clear: cybersecurity is a board-level obligation, not an IT project. Between the CBK Guidance Note on Cybersecurity for the Banking Sector, the parallel guidance issued to Payment Service Providers, and SASRA's expectations for deposit-taking SACCOs, every regulated financial institution in Kenya now operates under scrutiny that assumes a mature security program is already in place.

The problem? Many institutions are still treating CBK cybersecurity compliance as a document exercise. Auditors and CBK inspectors are increasingly asking for evidence of *operating* controls — not just policies filed in a shared drive. If you are a CISO, Head of Risk, or Compliance Officer at a Kenyan bank, SACCO, or PSP, this is the practical roadmap you need.

What the CBK Guidance Actually Requires

The CBK Guidance Note builds around five core expectations that map closely to internationally recognised frameworks like NIST CSF and ISO 27001. Reading them literally, the regulator expects:

  • A board-approved cybersecurity strategy and policy, reviewed at least annually
  • A designated Chief Information Security Officer (CISO) with direct reporting lines to senior management
  • A documented cybersecurity risk management framework covering identification, protection, detection, response, and recovery
  • Incident reporting to CBK within 24 hours of detection of a material cyber incident
  • Independent assurance — internal audit and external testing — of the control environment

For PSPs regulated under the National Payment System Act, similar obligations apply, with added emphasis on transaction integrity and customer fund protection. SACCOs supervised by SASRA face parallel expectations proportionate to their size and deposit base.

Expert tip: CBK examiners are less interested in the elegance of your policy document than in whether your CISO can produce evidence that controls operated effectively across the review period. Build for evidence from day one.

The Five-Phase Compliance Roadmap

Phase 1: Gap Assessment Against CBK and ISO 27001

Start by mapping your current state against both the CBK Guidance and ISO 27001:2022 Annex A controls. The overlap is significant — roughly 70% — and treating them as one exercise avoids duplicated work. A structured gap assessment identifies missing controls, weak evidence, and unclear ownership. ISO 27001 Gap Assessment Service

Phase 2: Governance and the CISO Function

CBK expects a dedicated CISO. For tier-1 banks, this is a full-time executive. For SACCOs and smaller PSPs, a virtual CISO arrangement is both compliant and cost-effective — provided the individual has documented authority, board access, and reporting cadence. Do not bury the function under the Head of IT; the regulator sees that structure as a conflict of interest.

Phase 3: Risk Management and Third-Party Oversight

Build a cybersecurity risk register linked to your enterprise risk framework. Pay particular attention to third parties — core banking vendors, mobile money integrators, cloud providers, and fintech partners. CBK expects due diligence, contractual security clauses, and ongoing monitoring of critical suppliers. Given how many Kenyan institutions rely on shared core banking platforms and regional payment rails, third-party risk is where most examiners find gaps.

Phase 4: Detection, Response, and the 24-Hour Reporting Clock

You cannot report an incident to CBK within 24 hours if you cannot detect one. This phase demands investment in monitoring — whether through an in-house SOC, a co-managed arrangement, or an MSSP. Pair this with a tested incident response plan covering ransomware, business email compromise, and mobile banking fraud — the three threat categories most consistently reported across East African financial services.

Phase 5: Assurance, Testing, and Awareness

Annual penetration testing, red team exercises for larger banks, and phishing simulations for all staff are now baseline expectations. Human error remains the entry point for most incidents affecting Kenyan financial institutions. Regular, contextualised security awareness training — using scenarios relevant to M-PESA fraud, SIM swap attacks, and local BEC patterns — moves the needle far more than generic global content. Security Awareness Training Services

Common Pitfalls Kenyan Institutions Keep Repeating

  • Treating the CISO role as a title, not a function. A CISO with no budget and no board access will not satisfy CBK.
  • Policies without evidence. If you cannot show sampled evidence that a control operated for the past 12 months, it does not exist in the eyes of an examiner.
  • Ignoring cloud misconfigurations. As more Kenyan banks and PSPs migrate workloads to AWS and Azure, misconfigured storage buckets and identity permissions are creating exposures the Guidance explicitly addresses under "protection."
  • No incident response testing. A plan that has never been rehearsed will fail under pressure. Table-top exercises should run at least twice a year.

Where to Start This Quarter

If you are behind on CBK alignment, do not attempt to fix everything at once. Prioritise: complete a gap assessment, formalise the CISO function, and operationalise incident reporting. Those three moves close the majority of examination findings we see across the sector.

SecureZaidi helps East African enterprises achieve and maintain compliance. Get in touch.