Sector 01
Financial services
Banks, microfinance institutions, SACCOs and payment providers, where a control failure is a regulatory event before it is an IT event.
What makes this sector different
- Central Bank of Kenya cybersecurity guidance carries board-level accountability, not an IT action item.
- Core banking replacements run for years and consume the risk appetite of the whole organisation.
- Card and mobile money rails bring PCI DSS obligations into a business that did not previously have them.
- Agency and branch networks push controls out to people the head office never meets.