FEATURED STORY

Banks required to report critical cyber attacks within 2 hours

Share
Central Bank of Kenya Governor Dr. Patrick Njoroge during a past event. CBK has frozen its base lending rate.
Share

With increasing fears that cyber attacks pose a huge threat to Kenya’s economy, The Central Bank of Kenya (CBK) has published new cyber security regulations that will require Payment Service Providers (PSPs) that move large value and high volume transactions like banks to report critical cyber attacks within 2 hours from October this year.

The new regulations also require retail payment service providers used by many Kenyans such as M-Pesa to report these attacks within two hours of occurrence while all other PSPs will be required to report attacks within 24 hours.

PSPs will also be required to furnish CBK with a report of these attacks detailing occurrence and their handling of cyber security incidents.

Further, PSPs will also be required to submit their Cyber security Policy, Strategies and Frameworks to CBK by December 31, 2019.

Banks will not be required to submit their documents on this date as they are licensed under the Banking Act.

“CBK is well aware of the fact that cyber risk will keep morphing due to the evolution of cyber threats in Kenya and across the globe. Therefore all PSPs are required to review their cyber security strategy, policy, and framework annually based on each PSP’s threat and vulnerability assessment,” read the guidelines.

Conversely, external auditors will also be required to report threats and cyber security strategies to CBK annually.

{Read: Postbank, Xpress Money sign money transfer deal}

PSPs will also be required to notify CBK of the intention to outsource functions, services and infrastructures at least thirty days before such outsourcing agreements are executed.

This comes in the backdrop of the release of a report by Microsoft which states that the Kenyan economy lost Ksh29.5 billion to cyber crime in 2018.

{See also: Sugar industry faces extinction thanks to proposed new rules}

The Microsoft Security Intelligence 2018 warns that as authorities adjust to the recent wave of cyber crime, hackers are becoming more sophisticated and hurting Kenyan businesses as a result.

Another report authored by Pan African cyber security firm Serianu states that Kenya lost Ksh29.8 billion to cyber crime in 2018.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

WHAT YOU NEED TO KNOW IN POLITICS

FOLLOW US ON SOCIAL MEDIA

Related Articles
Online Betting in Kenya
FEATURED STORY

The Financial Impact of the Online Betting Industry in Kenya

Online betting is hugely popular in Kenya and this means that it...

challenges of AI in business
FEATURED STORY

Executives Struggle to Balance AI With Accountability and Ethics

A new report by NTT DATA Inc., a global leader in digital...

President William Ruto
FEATURED STORY

List Of Projects Govt Is Doing For Nyanza Region

The Kenya Kwanza government, in the recent few months, has been engaged...