2024 was a turning point for cybersecurity in Kenya. Ransomware incidents against local businesses roughly tripled compared to the prior year, and attackers increasingly targeted mid-sized organisations that assumed they were too small to be worth the effort.
What changed
Attackers shifted from opportunistic phishing toward more targeted intrusions β researching a company's suppliers and staff before striking, often through compromised M-PESA-adjacent payment workflows and unpatched remote access tools.
The most common entry points
In the incidents DollarEdge's digital forensics team reviewed, three patterns stood out: reused passwords across systems, unpatched VPN or remote desktop software, and staff clicking through convincing invoice-themed phishing emails.
What actually reduces risk
Multi-factor authentication on every privileged account, regular offline backups tested for restore (not just taken), and a written incident response plan consistently made the difference between a contained incident and a business-ending one.
Looking ahead to 2025β2026
Expect continued growth in AI-assisted phishing (more convincing, harder to spot) and increased regulatory attention as Kenya's Data Protection Act enforcement matures. Organisations that haven't run a security audit in the past 12 months should treat that as the first priority.
Need help with this in your organisation?
Talk to the DollarEdge team about a free, no-obligation consultation.
Request a Quote β
Loading comments...
Leave a Comment