FEATURED STORY

Banks required to report critical cyber attacks within 2 hours

Share
Central Bank of Kenya Governor Dr. Patrick Njoroge during a past event. CBK has frozen its base lending rate.
Share

With increasing fears that cyber attacks pose a huge threat to Kenya’s economy, The Central Bank of Kenya (CBK) has published new cyber security regulations that will require Payment Service Providers (PSPs) that move large value and high volume transactions like banks to report critical cyber attacks within 2 hours from October this year.

The new regulations also require retail payment service providers used by many Kenyans such as M-Pesa to report these attacks within two hours of occurrence while all other PSPs will be required to report attacks within 24 hours.

PSPs will also be required to furnish CBK with a report of these attacks detailing occurrence and their handling of cyber security incidents.

Further, PSPs will also be required to submit their Cyber security Policy, Strategies and Frameworks to CBK by December 31, 2019.

Banks will not be required to submit their documents on this date as they are licensed under the Banking Act.

“CBK is well aware of the fact that cyber risk will keep morphing due to the evolution of cyber threats in Kenya and across the globe. Therefore all PSPs are required to review their cyber security strategy, policy, and framework annually based on each PSP’s threat and vulnerability assessment,” read the guidelines.

Conversely, external auditors will also be required to report threats and cyber security strategies to CBK annually.

{Read: Postbank, Xpress Money sign money transfer deal}

PSPs will also be required to notify CBK of the intention to outsource functions, services and infrastructures at least thirty days before such outsourcing agreements are executed.

This comes in the backdrop of the release of a report by Microsoft which states that the Kenyan economy lost Ksh29.5 billion to cyber crime in 2018.

{See also: Sugar industry faces extinction thanks to proposed new rules}

The Microsoft Security Intelligence 2018 warns that as authorities adjust to the recent wave of cyber crime, hackers are becoming more sophisticated and hurting Kenyan businesses as a result.

Another report authored by Pan African cyber security firm Serianu states that Kenya lost Ksh29.8 billion to cyber crime in 2018.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Follow Us

Related Articles
Milka Moraa with Affordable Housing Board officials
FEATURED STORY

Milkah Moraa, Woman Humiliated By City Pastor, To Get Affordable Housing Unit

Milka Moraa Tegisi,  a woman from Mukuru kwa Njenga slums who was...

Kenya Airways repair accreditation
FEATURED STORY

Kenya Airways to Service European Planes After Key Certification

Kenya Airways (KQ) has attained another milestone with the European Union Aviation...

Affordable Housing Project in Bomet
FEATURED STORY

How Affordable Housing Project In My Town Transformed My Life: Beneficiaries Tell Their Stories

The story of John Kipkorir, a 39-year-old renowned welder in Bomet town,...

KCB Platinum Multi-Currency Card
FEATURED STORY

KCB, Mastercard Unveil Kenya’s First Prepaid Card Supporting 11 Currencies

KCB Bank Kenya, in collaboration with Mastercard, has launched Kenya's only multi-currency...