Cybersecurity & Tech

Crucial Steps to Protect Your Business from Cyber Threats featuring BrianLee Maingi

BrianLee Maingi

BrianLee Maingi

Managing Partner · May 2026 · 7 min read

Crucial Steps to Protect Your Business from Cyber Threats featuring BrianLee Maingi

Cyber incidents are no longer a remote risk category for Kenyan businesses; they are a routine operational hazard with direct legal consequences under the Data Protection Act, 2019. Managing Partner BrianLee Maingi outlines the compliance steps we most often recommend to corporate clients building, or repairing, their cyber risk posture.

The direct cost of a cyber incident is frequently smaller than the downstream legal cost: regulatory notification, contractual liability, and reputational damage.

The Rising Cost of Cyber Incidents for Kenyan Businesses

The direct cost of a cyber incident, forensic investigation, system restoration, and business interruption, is frequently smaller than the downstream legal cost: regulatory notification obligations, potential enforcement action by the Office of the Data Protection Commissioner (ODPC), contractual liability to business customers whose data was exposed, and reputational damage that outlasts the technical remediation.

Data Protection Act Obligations You Cannot Ignore

Any organisation that determines the purpose and means of processing personal data qualifies as a data controller, or a data processor if it processes on another's behalf, and both categories carry registration and compliance obligations to the ODPC. Where a breach is likely to result in risk to the rights of the data subjects concerned, the Act requires notification to the Commissioner without unreasonable delay, and in certain circumstances, notification to the affected individuals themselves.

Businesses transferring personal data outside Kenya, common for companies using cloud infrastructure or regional shared services, must additionally satisfy the Act's cross-border transfer conditions, which is an area we see frequently overlooked until a transaction or an audit brings it to light.

Practical Safeguards We Recommend to Clients

Beyond the technical controls that IT teams already prioritise, we advise clients to maintain a documented incident response plan naming specific decision-makers and legal counsel in advance, to run a data mapping exercise identifying exactly what personal data is held and why, to put data processing agreements in place with every third-party vendor that touches customer or employee data, and to rehearse the notification timeline before an incident, not during one.

Key Takeaways

  • A cyber incident's legal cost, regulatory, contractual, and reputational, usually exceeds the technical remediation cost.
  • Data controllers and processors both carry registration and compliance obligations to the ODPC under the Data Protection Act, 2019.
  • Breaches likely to risk data subjects' rights must be notified to the Commissioner without unreasonable delay.
  • Cross-border data transfers (including to cloud infrastructure) require separate compliance conditions under the Act.
  • Have a named incident response plan, vendor data processing agreements, and a rehearsed notification timeline in place before an incident occurs.

Have a question on this topic?

Speak with our attorneys about how this affects your business.

Free Consultation
Consultation Request

Get in Touch with Us

Fill out the form below detailing your legal inquiry. A representative from our firm will review your request and get back to you within 24 hours.

Contact Info

Reach Our Offices

General enquiries: info@moadvocatesllp.com

Nairobi OfficeHead Office

Hurlingham Plaza, Suite C2, 2nd Floor, Argwings Kodhek Road
P.O. Box 17011-00100, Nairobi, Kenya

Kisumu Office

Tumaina Mall, Suite 204, 2nd Floor, Awuor Otiende Road, Milimani Estate
P.O. Box 775-40100, Kisumu, Kenya

Office Hours

Monday – Friday: 8:00 AM – 5:00 PM
Saturday & Sunday: Closed (By Appointment Only)

Nairobi Office· Head Office Location