
A cyberattack is never just a technical event, the moment systems are compromised, data is exposed, or a network is breached, legal obligations activate immediately, reporting deadlines, regulatory exposure, potential criminal liability, and the risk of civil claims from affected parties. At Kathurima N Advocates, our cybersecurity law practice helps businesses build legally sound defenses before an incident occurs, and provides immediate, decisive legal support the moment one does, so that a cyber incident is managed as the serious legal matter it actually is, not just an IT problem.
Cybersecurity in Kenya is governed primarily by the Computer Misuse and Cybercrimes Act, 2018, which criminalizes offences including unauthorized access and interference, cyber espionage, computer forgery, identity theft and impersonation, phishing, cyber harassment, and cyberterrorism. The Act also establishes the National Computer and Cybercrimes Coordination Committee and requires any person operating a computer system or network, public or private, to report attacks, intrusions, or disruptions to another system within twenty four hours of occurrence. This sits alongside the Data Protection Act, 2019, which governs the personal data dimension of most cyber incidents, and the Computer Misuse and Cybercrime Regulations on Critical Information Infrastructure, which impose specific security governance obligations on organizations operating systems considered critical to Kenya's national infrastructure, including telecommunications, finance, and energy.
For most businesses, a genuine cyber incident triggers obligations under both statutes simultaneously, the Computer Misuse and Cybercrimes Act's twenty four hour reporting requirement to relevant authorities, and, where personal data is involved, the Data Protection Act's separate seventy two hour breach notification duty to the Office of the Data Protection Commissioner. Understanding how these two timelines and obligations interact is central to managing a cyber incident correctly.
Incident Response. When a breach, intrusion, or attack occurs, we provide immediate legal triage, assessing your reporting obligations under both the Computer Misuse and Cybercrimes Act and the Data Protection Act, coordinating with your technical team, and preparing the required regulatory disclosures within the applicable deadlines.
Cybercrime Compliance Assessments. We review your organization's practices against the Computer Misuse and Cybercrimes Act's requirements, identifying gaps in reporting protocols, security governance, and staff awareness before they become the subject of a regulatory inquiry or an actual incident.
Critical Information Infrastructure Compliance. For organizations operating systems classified as critical information infrastructure, telecommunications, financial services, energy, and similar sectors, we advise on the specific governance, risk assessment, and security obligations these regulations impose.
Cybersecurity Governance Frameworks. We help boards and management build legally coherent cybersecurity governance, covering board level oversight, staff training obligations, vendor and third party security requirements, and incident response planning, so your organization is prepared before an incident occurs rather than scrambling during one.
Cybercrime Defense. Where an individual or organization faces allegations under the Computer Misuse and Cybercrimes Act, or is the subject of a cybercrime related regulatory investigation, we provide defense representation grounded in a detailed understanding of the Act's specific offences and evidentiary requirements.
Contracts and Vendor Risk. We draft and review technology contracts, data processing agreements, and vendor security clauses, ensuring your organization's exposure to a third party's cybersecurity failure is properly limited and clearly allocated.
Cyber Insurance and Risk Advisory. We advise businesses on the legal dimensions of cyber risk, helping align insurance coverage, contractual protections, and internal governance with the actual threat landscape your organization faces.
One of the most important, and most commonly misunderstood, aspects of Kenyan cybersecurity law is that a single incident can trigger two separate, overlapping legal deadlines. The Computer Misuse and Cybercrimes Act requires notifying the relevant authorities of an attack, intrusion, or disruption within twenty four hours of it occurring. Where the incident also involves personal data, which most breaches affecting customer or employee information do, the Data Protection Act separately requires notifying the Office of the Data Protection Commissioner within seventy two hours of becoming aware of the breach. These are not interchangeable obligations, meeting one does not satisfy the other, and organizations that focus only on the more widely known seventy two hour data breach clock can miss the tighter twenty four hour cybercrime reporting window entirely. We help clients navigate both simultaneously from the moment an incident is discovered.
Cybersecurity law genuinely operates on two levels, and we work across both. On the prevention side, we help businesses build the legal and governance infrastructure, policies, contracts, board level oversight, staff training obligations, that reduces both the likelihood of an incident and the legal exposure if one occurs despite those precautions. On the response side, when an incident does happen, we move immediately, every hour matters once a breach is discovered, both for containing legal exposure and for meeting the tight statutory deadlines involved. Businesses that have never engaged legal counsel on cybersecurity until the moment of a crisis are at a genuine disadvantage compared to those with an existing governance framework and a legal team already familiar with their systems and risk profile.
Our cybersecurity law practice supports technology companies and software platforms managing sensitive user data, financial institutions and fintech companies operating under heightened regulatory scrutiny, telecommunications and critical infrastructure operators subject to specific security governance requirements, healthcare providers handling sensitive patient data, and any business, across any sector, that has experienced or wants to prepare for a cyber incident before it happens.
What should I do immediately after discovering a cyberattack? Secure your systems to prevent further exposure, preserve evidence and logs before making changes, and contact legal counsel immediately, given how quickly the twenty four hour cybercrime reporting clock and, where personal data is involved, the seventy two hour data breach clock begin running.
Is reporting a cyber incident legally required in Kenya? Yes. The Computer Misuse and Cybercrimes Act, 2018 requires any person operating a computer system or network to report attacks, intrusions, or disruptions within twenty four hours of occurrence. Where personal data is affected, a separate notification to the ODPC is also required within seventy two hours.
What penalties apply under the Computer Misuse and Cybercrimes Act? Penalties vary by offence and can include substantial fines and imprisonment, with severity generally scaled to the nature of the offence and its impact, ranging from unauthorized access to more serious offences like cyber espionage or cyberterrorism.
Does my business need a formal cybersecurity governance framework? Any business handling sensitive customer, financial, or health data benefits significantly from a documented framework, and organizations operating what qualifies as critical information infrastructure are specifically required to meet defined governance and risk assessment standards.
Can I be held personally liable for my company's cybersecurity failures? Depending on the role and the specific circumstances, directors and senior management can face exposure where governance failures contributed to a breach or where statutory reporting obligations were not met, which is part of why board level oversight is a genuine legal, not just technical, priority.
How is a cybersecurity incident different from a data breach for legal purposes? They frequently overlap, but are legally distinct. A cybersecurity incident under the Computer Misuse and Cybercrimes Act concerns unauthorized access to or interference with a computer system. A data breach under the Data Protection Act specifically concerns unauthorized access to or exposure of personal data. Many incidents trigger both sets of obligations at once.
Cyber incidents do not wait for business hours, and neither do the legal deadlines they trigger. Our cybersecurity law team is available around the clock to help you respond decisively when it matters most, and to build the governance frameworks that reduce your risk before an incident ever occurs.