CBK Cybersecurity Guidance
Market regime · Central Bank of Kenya Guidance Note on Cybersecurity
Central Bank of Kenya
Kenya
2017, with sector guidelines extending it
Central Bank of Kenya
CBK-supervised institutions
Curated, versioned & cross-mapped
The obligation, plainly.
The CBK's Guidance Note makes cybersecurity a supervised discipline for Kenyan banking: board ownership of strategy and posture, a designated CISO, risk assessment driving controls, workforce awareness, and cyber incidents reported to the CBK within 24 hours.
Its shape is the regional pattern, the same governance-to-reporting arc as the CBN's framework and the BoG directive, and it cross-maps onto the ISO 27001 and NIST CSF control set an institution should already be running.
Where programmes are tested.
Board and CISO governance
The board owns the strategy and reviews posture; a CISO carries it with standing and independence.
Risk-driven controls
Assessments that select the controls, and a technical estate evidenced against them.
24-hour incident reporting
Cyber incidents reported to the CBK within 24 hours, with the response documented.
Curated once, evidenced continuously.
- The Guidance Note is cross-walked to the same technical and governance controls as CBN's framework and ISO 27001, so one control set answers every supervisor in the portfolio.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
CBK Cybersecurity Guidance, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who does the CBK guidance apply to?
Institutions the Central Bank of Kenya supervises, beginning with banks and mortgage finance companies, with payment service providers brought under parallel guidelines. If the CBK licenses you, a version of the same expectations reaches you.
What is the incident reporting window?
24 hours to the CBK for cyber incidents, one of the shortest clocks in the portfolio, which is why detection-to-report needs to be a workflow with a timer rather than a judgement call made during the incident.
Does the CBK require a CISO?
Yes: a designated senior officer responsible for the cybersecurity programme, with the independence and board access to run it. The supervisor tests whether the role is real, budget, reporting line, board papers, not whether the title exists.
How does it relate to ISO 27001?
The guidance expects the substance ISO 27001 systematises: governance, risk assessment, controls, awareness and response. Institutions certified against 27001 mostly evidence the CBK note from the same programme, with the 24-hour reporting duty layered on top.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.