Skip to content

Sectors

Four sectors where the team already knows what breaks.

Technology risk is not generic. A control that is proportionate in an NGO is negligent in a bank, and a recovery time that is fine for a parastatal loses a telco money by the minute.

Sector × practiceWhich of the five practices each sector most often engages. Every marked cell links to that practice.
01Business system reviews02Information security assurance03Technology governance04Business continuity management05Project risk management
Financial services Not typically engaged
Telecommunications Not typically engagedNot typically engaged
International development & NGOs Not typically engagedNot typically engaged
Public sector & parastatals Not typically engagedNot typically engaged

A marked cell is a practice that sector engages most often, not a restriction. Every engagement is scoped against what you actually need.

Sector 01

Financial services

Banks, microfinance institutions, SACCOs and payment providers, where a control failure is a regulatory event before it is an IT event.

What makes this sector different

  • Central Bank of Kenya cybersecurity guidance carries board-level accountability, not an IT action item.
  • Core banking replacements run for years and consume the risk appetite of the whole organisation.
  • Card and mobile money rails bring PCI DSS obligations into a business that did not previously have them.
  • Agency and branch networks push controls out to people the head office never meets.

Sector 02

Telecommunications

Operators and mobile money businesses where availability is the product and subscriber data is the liability.

What makes this sector different

  • Mobile money makes a telco a financial institution in everything but name — and in some obligations, in name too.
  • Subscriber data volumes make Data Protection Act obligations material rather than procedural.
  • Network and IT change at different speeds, and the seam between them is where incidents live.
  • Downtime is measured in lost transactions per minute, which makes recovery time a commercial number.

Sector 03

International development & NGOs

Development agencies and non-governmental organisations answering to donors, beneficiaries and several jurisdictions at once.

What makes this sector different

  • Donor assurance requirements arrive with their own frameworks and their own deadlines.
  • Beneficiary data is among the most sensitive any organisation holds, and often the least protected.
  • Programmes run across borders, so one control environment has to satisfy several regulators.
  • Grant-funded IT is bought project by project, which leaves an estate nobody owns end to end.

Sector 04

Public sector & parastatals

Government agencies and state corporations under audit scrutiny, digitising services faster than they are governing them.

What makes this sector different

  • Auditor-General findings repeat year to year until somebody addresses the underlying control.
  • Citizen-facing digital services raise the cost of an outage from inconvenience to headline.
  • Procurement rules constrain how technology risk can be transferred to a supplier.
  • Legacy systems remain in service long past the point where anyone supports them.

Your sector

Not on this list?

These four are where the team’s depth sits, not a restriction on who we work with. Tell us what you do and we will say honestly whether we bring an advantage to it.

Send an enquiry

+254 721 687846 taarifa@techrisk.co.ke