Skip to article sections
Purpose

This study examines how the advisory role of the Information and Communications Technology Authority (ICTA) influences cybersecurity and records management practices, and how these contribute to enhanced governance in Kenya's public sector.

Design/methodology/approach

A qualitative case study design was adopted to explore the integration of cybersecurity and records management practices within Kenya's public-sector digital governance framework. Data were collected through semi-structured interviews administered to 18 purposively selected participants, including top management, records management, ICT and information security personnel at ICTA. The data were analysed thematically to identify institutional practices, governance challenges and the extent to which cybersecurity principles are embedded in records management practices.

Findings

The findings reveal that integrated cybersecurity and records management practices play a critical role in strengthening good governance in Kenya's public sector. ICTA supports this integration through policies promoting role-based access control, secure audit trails, digital signatures and disaster recovery mechanisms. However, challenges persist, including inconsistent implementation across public institutions, unclear records security classification protocols, limited resources and infrequent policy updates.

Practical implications

The study highlights the need for harmonized implementation of cybersecurity and records management policies across public institutions. Strengthening institutional capacity, clarifying classification frameworks and regularly updating policies would enhance information management and improve governance outcomes.

Originality/value

This study provides original insights into cybersecurity and records management as interdependent components of digital governance within the public sector. Situated in Kenya's digital landscape, it offers evidence from a Global South perspective, contributing to debates on secure digital governance, institutional accountability and records management in emerging economies.

The digital revolution has transformed economies and societies globally, driven by rapidly evolving emerging technologies. This pace of change compels professionals in the public sector to continuously learn, unlearn and relearn in order to remain effective. These innovations operate within an interconnected digital ecosystem-cyberspace-where physical and digital realities increasingly converge, reshaping how records are generated, processed, shared and utilized. In this context, effective electronic records management and robust cybersecurity have become critical pillars of good governance. Globally, governments face the dual challenge of leveraging the benefits of cyberspace while ensuring its security. Cybersecurity and records management are now deeply interdependent: sound recordkeeping enhances transparency and accountability, while cybersecurity protects the integrity, confidentiality and availability of information assets. Effective records management further ensures the authenticity, reliability, integrity and accessibility of government information, while cybersecurity safeguards records against unauthorised access, manipulation, breaches and loss throughout their lifecycle. Together, these complementary practices support trustworthy digital governance and informed decision making in the public sector (ISO 15489–1, 2016)

Electronic records encompass a wide range of information formats; emails, reports, databases, letters, photographs, policies and more. Managing these records through a continuum approach; from creation, capture, organization, access use, preservation and ongoing accountability is not merely an administrative function but a strategic process that underpins efficient operations, transparency and informed decision-making (Upward, 1996; ISO 15589–1, 2016). Across the records continuum, distinct security concerns emerge, including risks related to unauthorised access, data breaches, manipulation loss and long-term digital preservation. As a result, cybersecurity plays a crucial role in safeguarding these information assets, together with the systems and networks that support them against evolving digital threats through mechanisms such as access controls, risk management, information integrity protection and secure information governance frameworks (ISO/IEC 27001, 2022, Greaves, 2020a, b; Musembe and Mutula, 2020). As Stevens (2018a, b) observes, cybersecurity also functions as a tool for advancing national and international policy agendas.

However, the increasing reliance on digital systems introduces new vulnerabilities. Cyberspace, comprising not only e-records but also the infrastructures and users that interact with them, is inherently fragile (Christen et al., 2020). This fragility is increasingly evident in Kenya's public sector, where rapid digital transformation has expanded exposure to cyber risks such as phishing attacks, system intrusions and unauthorised access to government digital platforms. Reports from the Communications Authority of Kenya (CAK) through the National KE-CIRT/CC indicate a sharp increase in cyber threat incidents, with billions of detected events recorded in recent reporting cycles, reflecting escalating exposure within both public and private sector systems (Communications Authority of Kenya, 2025; National KE-CIRT/CC, 2026).

Further, Kenya's accelerated e-government agenda, coordinated through the Kenya information and communications Technology Authority (ICTA), continues to expand the scale and sensitivity of digital records, thereby increasing systemic vulnerability if cybersecurity controls are not consistently enforced (ICTA, 2025). This reality elevates cybersecurity to a top priority for governments, businesses and civil society, with implications for critical infrastructure, public safety, economic resilience and international stability (Kenya ICT Action Network, 2019a, b).

Despite this interdependence, many organizations continue to treat records management and information security as separate domains. Records management is often perceived as a technical or administrative function, while cybersecurity is frequently confined to ICT or information security units, limiting integration into broader governance processes (Greaves, 2020a, b; ISO 15489–1, 2016). Similarly, cybersecurity functions are often isolated from records management practices, resulting in fragmented operational structures that weaken digital governance coherence (Musembe, 2019). This separation is further compounded by the fact that both domains are frequently implemented in parallel rather than in collaboration, despite their shared responsibility for ensuring information integrity, confidentiality, accessibility and accountability (ISO/IEC 27001, 2022). Consequently, the lack of integration undermines the effectiveness of both cybersecurity and records management in supporting public-sector decision making and service delivery. Existing studies have often addressed cybersecurity and records management within separate disciplinary traditions, with records management grounded inn records continuum perspectives while cybersecurity is primarily situated within information systems, risk management and data governance literature (Upward, 1996; Sanderson, 2019; Alhassan et al., 2016; Knight, 2016), As a result, limited scholarly attention has been given to their integration within public-sector governance frameworks, particularly in developing country contexts.

Existing literature has highlighted that, fragmented operations hinder the integration of cybersecurity principles into records practices and vice versa (Knight, 2016). This study explores how ICTA's practices align information security principles with records management, determines legal structures enhancing the cybersecurity ecosystem and proposes strategies to address gaps, fostering secure and efficient governance in Kenya's digital age.

The ongoing digital transformation in Kenya is significantly reshaping records management practices, creating an increased demand for robust cybersecurity mechanisms to support good governance within the public sector. As government services continue to transition to digital platforms, the integrity, security and management of electronic records have become central to effective service delivery and evidence-based decision making. This study explores how practices align information security principles with records management, examines legal structures that enhance the cybersecurity ecosystem and proposes strategies to address existing gaps in order to strengthen secure and efficient governance in Kenya's digital age.

Despite these efforts, Kenya continues to experience a rapid increase in cyber threats, with reports indicating a 200% rise in cyber incidents in the first quarter of 2025 alone, as documented by the (National KE-CIRT/CC (Communications Authority of Kenya, 2025). These threats pose significant risks to the confidentiality, integrity and availability of public-sector information systems, thereby affecting service delivery and institutional accountability.

Established in 2013, ICTA plays a central role in enforcing ICT standards, developing secure infrastructure and promoting digital literacy across Ministries, Counties, Departments and Agencies (MCDAs). Within this mandate, ICTA is strategically positioned to support the alignment of cybersecurity and records management practices as part of Kenya's broader digital governance agenda (ICTA, 2025).

Effective records management is central to good governance, as it promotes transparency, accountability and evidence-based decision-making (International Council of Archives, 2016). Within public sector institutions records constitute critical governance assets that support public service delivery, institutional reforms and policy implementation (ISO 15489–1, 2016). These records underpin administrative processes and safeguard public entitlements by ensuring that government actions remain traceable and verifiable.

In the digital era, the governance value of records has been reshaped by the integration of emerging technologies, which has introduced both operational efficiencies and heightened cybersecurity risks, as public institutions increasingly rely on electronic records systems, the protection of these assets has become essential to safeguarding information integrity and institutional trust. Cybersecurity threats now represent a significant global concern, with increasing financial and operational impacts on digital systems and data infrastructure (Serianu, 2023).

Digital transformation has therefore expanded both the opportunities and vulnerabilities associated with public sector information systems. While technologies such cloud computing, mobile platforms and interconnected databases improve efficiency and accessibility, they also significantly broaden the cyber-attack surface (Mizrak, 2023; Lee et al., 2021). As Goel et al. (2018) observe, cyber risk is inherent wherever data are created, processed or stored, making it a persistent governance concern across all digital environments.

International evidence further illustrates the scale and evolution of these threats. A United Nations (2021) report confirms that even highly secure institutions are vulnerable to cyberattacks ranging from phishing and identity theft to malware and denial of service attacks. Increasingly, cyber threats are shifting from system-based attacks to human-targeted social engineering strategies. Despite this global nature, responses remain largely fragmented and nationally constrained, creating governance gaps in coordination, capacity and oversight (Sabillon et al., 2016).

Within this context, cybersecurity has evolved from a technical Information Technology function to a strategic governance concern, it is widely recognized as essential for organizational resilience, continuity and institutional trust (Mizrak, 2023). However, despite this recognition ambiguity persists regarding responsibility for protecting electronic records. For instance, studies in public sector environments have shown that records protection is often incorrectly perceived solely as an ICT function, leading to unclear accountability structures and weak compliance with cybersecurity standards such as ISO/IEC 27001 (British Standards Institute (2018).

This ambiguity contributes to persistent structural silos between cybersecurity and records management functions, Knight (2016) observes that these two professional domains often operate independently due to differences in terminology, institutional priorities and limited interdisciplinary communication. Additional contributing factors include resource constraints, fragmented governance structure and outsourcing of ICT services all of which weaken coordination and information governance effectiveness.

In the Kenyan context, similar challenges have been observed. Ambira (2016a, b) notes that electronic records management systems across government ministries have historically been fragmented, with institutions adopting inconsistent approaches to records governance. Although the government of Kenya introduced the integrated management system (IRMS) to improve standardisation, implementation gaps remain, particularly in relation to electronic records security and system interoperability (Ambira, 2016a, b; Serianu Limited, 2015). These weaknesses continue to expose public sector systems to cyber vulnerabilities and data quality risks.

Empirical evidence further shows that Kenya faces evolving cybersecurity threats, including data breaches, third-party misuse of information, malware attacks and infrastructure vulnerabilities (Kenya ICT Action Network, 2019a, b). These challenges are compounded by limited institutional coordination, outdated regulatory enforcement mechanisms and insufficient technical capacity across public institutions.

From a governance perspective, this situation highlights a broader challenge; the separation of records management and cybersecurity undermines integrated digital governance. While records management ensures the structured capture, organization and preservation of information, cybersecurity ensures its protection across systems and networks. Without integration, both functions operate sub-optimally, resulting in weakened accountability, reduced trust and inefficiencies in public service delivery.

Despite the growing global recognition of this interdependence, existing literature continues to treat cybersecurity and records management largely as separate fields of inquiry, with limited attention to their integration within public sector governance systems, particularly in developing country contexts (Upward, 1996; Sanderson, 2019; Alhassan et al., 2016; Knight, 2016). This fragmented scholarly attention highlights the need for more context specific studies that examine how these two domains interact in practice within public institutions.

Building on the established interdependence between cyberspace and records management in public governance, legal and institutional frameworks play a critical role in translating cybersecurity principles into enforceable governance practice. These frameworks define responsibilities, establish compliance mechanisms and provide structured approaches for managing digital risks within increasingly complex information environments.

Globally, cybersecurity governance has evolved through structured frameworks that integrate risk management, system protection and organizational accountability. One of the most widely adopted models is the National Institute of Standards and Technology (NIST) Cybersecurity Framework that integrate risk-based approach organized around five core functions: identify, protect, detect, respond and recover (NIST, 2018). Although widely recognized for its flexibility and applicability across sectors, its effectiveness depends on institutional maturity and the ability to integrate it into existing governance systems, including records management strictures (Akitra, 2024).

In the European context, the original Network and Information Systems Directive (NIS2, 2023) represents a more regulatory driven approach, requiring member states to establish national cybersecurity strategies, incident response mechanisms and enforcement frameworks. This directive strengthens accountability across critical sectors, including public administration, healthcare and finance (European Union, 2023). However, its effectiveness remains dependent on national level implementation capacity and institutional coordination.

In Africa, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) provides a continental framework aimed at harmonising cybersecurity, data protection and electronic transaction governance (African Union, 2014). Despite its comprehensive scope, limited ratification across member states has constrained its operational impact, thereby weakening regional coherence in cybersecurity governance (Ifeanyi-Ajufo, 2024). Complementing this, the African Union Digital Transformation Strategy (2020–2030) emphasizes the need for secure digital ecosystems, interoperable systems and strengthened cybersecurity capacity as foundational enablers of digital development (African Union, 2020).

Within the Kenyan context, cybersecurity governance is shaped by a combination of legislative instruments, institutional mandates and national strategies. Key legal frameworks include the Computer Misuse and Cybercrimes Act (2018), which criminalises cyber offences; the Data Protection Act (2019), which regulates the processing of personal data and established the Office of the Data Protection Commissioner and the Kenya Information and Communications (Amendment) Act (2013), which provides the legal basis for the establishment and mandate of the CAK. The National Kenya Computer Incident Response Team Coordination Centre (National KE-CIRT/CC) operates under the Communications Authority as the country's national cyber incident response centre.

In addition, the National Cybersecurity Strategy 2022–2027 provides a coordinated policy direction aimed at strengthening Kenya's resilience against cyber threats through multi-agency collaboration, capacity building and proactive risk management (Government of Kenya, 2022). However, despite these frameworks, implementation challenges persist due to overlapping institutional mandates, fragmented governance structures and limited inter-agency coordination. For example, cybersecurity responsibilities are distributed across multiple institutions, creating challenges in coordination and implementation (KICTANet, 2019).

Additionally, institutional capacity constraints continue to hinder effective cybersecurity governance in Kenya. Prior studies highlight weaknesses in technical expertise, limited awareness among public officials and inadequate incident reporting mechanisms across government institutions (KICTANet and Global Partners Digital, 2019). These challenges are compounded by legacy systems and inconsistent integration of cybersecurity considerations into the design and management of electronic records systems.

From a governance perspective, these structural and institutional gaps directly affect the integration of cybersecurity and records management practices. While legal frameworks provide the normative foundation for secure information governance, their effectiveness depends on how well they are operationalized within records systems and administrative processes. The persistence of fragmented implementation therefore reinforces the separation between cybersecurity and records management identified in Section 2.1.

Comparative analysis of global, regional and national frameworks demonstrates a common pattern; although cybersecurity governance structures are increasingly well- developed in policy form, their effectiveness is constrained by implementation gaps, institutional silos and limited integration with records management systems. This reinforces the need for context-specific studies that examine how governance frameworks are operationalized within public institutions to support integrated information management.

Despite the growing body of literature on cybersecurity governance and records management, the two domains continue to evolve along largely parallel but disconnected scholarly and institutional trajectories. Existing studies have predominantly focused on cybersecurity as a technical and risk management concern, while records management has largely been situated within archival science, compliance and information governance traditions. As demonstrated in the preceding discussion, this disciplinary separation has resulted in limited empirical attention to how cybersecurity and records management interact as integrated components of public sector governance systems, particularly within developing country contexts. Furthermore, there remains insufficient context-specific evidence on how public institutions operationalize this integration in practice, especially within regulatory and advisory bodies such as the ICTA in Kenya.

This study addresses this gap by examining the intersection between cybersecurity and records management within Kenya's public sector governance environment, focusing on how ICTA facilitates their integration to enhance secure and accountable digital governance. The study is anchored on the records continuum perspective, which conceptualizes records as dynamic entities management across time, space and institutional contexts rather than discrete lifecycle stages (Upward, 1996). This perspective is complemented by information security governance principles, particularly ISO/IEC 27001 and ISO 15489–1 which provide structured frameworks for ensuring the integrity, confidentiality and accessibility of information assets. Together these perspectives provide an integrated analytical lens for understanding how records management and cybersecurity function as mutually reinforcing components of digital era governance.

A qualitative research approach using a case study design to examine how cybersecurity and records management practices are integrated within Kenya's public sector digital governance framework. The case study focused on the ICTA, which plays a central advisory and regulatory role in guiding ICT standards, cybersecurity practices and digital transformation initiatives within the Kenyan public sector.

Study participants were purposively selected based on their roles and involvement in records management, information communication technology and information security functions within ICTA. The study targeted top management representatives (R1 and R2), Information security heads and deputies (R3 to R6) Records manager and officers (R7 to R 14), Information Communication Technology manager and officers (R 15 to R18). The categorization of respondents enabled the study to capture diverse institutional perspectives and support analytical differentiation during data analysis.

Data were collected through semi-structured key informant interviews. The use of interviews enabled the researchers to obtain in-depth insights into institutional practices, governance challenges, cybersecurity implementation and the integration of information security principles within records management processes.

Sampling was guided by the principle of data saturation, whereby interviews continued until no significant new themes and insights emerged from the participants. A total of 18 participants were interviewed, which falls within recommended qualitative case study ranges for generating rich and meaningful data (Yin, 2018).

The collected qualitative data were analysed thematically and presented through narrative descriptions to highlight emerging themes, institutional experiences and governance related implications associated with cybersecurity and records management in the public sector.

The study targeted 20 respondents to be interviewed including four top management representatives seven heads of departments and their seven deputies. However, those reached were 18 representing a 90% response rate. In particular, top management achieved 50% (2) while the heads of departments and their deputies achieved 100% (16).

The study sought to examine how cybersecurity principles are integrated with records management practices within ICTA and across the wider public sector. Findings indicate a strong institutional recognition that cybersecurity and records management are interdependent components of digital governance. However, while this integration is conceptually well understood, its implementation remains uneven across departments and agencies.

Respondents across all the categories consistently affirmed that ICTA operationalises key information security principles: (confidentiality, integrity, availability, authenticity, possession and utility) through structured policies and technical controls. These principles are imbedded within records management systems using role-based access controls (RBACs), secure audit trails, version control mechanisms, digital signatures and structured classification frameworks. For example, confidentiality is enforced through least-privilege access rights, while integrity is maintained through audit logs and controlled modification privileges. Availability is supported through backup systems and disaster recovery protocols, whereas authenticity is ensured through metadata standards and digital verification mechanisms, possession is ensured by clear custodianship protocols; and utility is supported by classifying and organizing records for timely access.

Despite these formal structures, respondents noted that implementation varies significantly across MCDAs, largely due to differences in capacity, awareness and resource availability. Top management respondents particularly emphasized the implementation gap between ICTA frameworks and operational execution at institutional level. This weakens system-wide consistency in secure records governance.

An Information Security respondent explained that ICTA plays both a proactive and a reactive role in strengthening cybersecurity compliance across government systems:

ICTA develops of policies and standards and conducts audits, system reviews and awareness training across agencies. We also respond to incidents when called upon, which helps influence both implementation and governance thinking around cybersecurity (R3)

This highlights ICTA's dual role as both a regulatory and capacity-building institution shaping not only compliance structures but also organizational behaviour in digital governance as emphasized particularly by ICT and security respondents. Overall, the findings demonstrate that while integration mechanisms exist in policy and system design, their effectiveness is constrained by inconsistent implementation across public institutions, which remains a critical challenge to achieving coherent cybersecurity and records management integration.

The study further examined how access controls mechanisms are implemented to safeguard electronic records and ensure that only authorized personnel access sensitive records. ICT and information security responds indicated that ICTA and other public sector institutions predominantly rely on RBAC systems as the primary framework for managing digital permissions under this model, access rights are assigned according to job functions, ensuring that users interact only with records relevant to their responsibilities. Complementary mechanisms such as multifactor authentication secure login credentials, system audit logs and intrusion detection systems are used to enhance monitoring and accountability. These controls collectively strengthen the security posture of records management systems by reducing the risk of unauthorised access and data manipulation.

However, records management and ICT officers noted that while these controls are well-established in formal systems, their effectiveness varies depending on system maturity, infrastructure capacity and institutional compliance levels, in some cases, older systems experience performance challenges, which may affect accessibility and efficiency of records retrieval. As records management respondent explained that:

Access is granted strictly based on the principle of least privilege. However, system performance and capacity sometimes affect how effectively these controls' function, especially where infrastructure has not been upgraded (R8).

Thus, the findings suggest that access control mechanisms are well-developed at the policy and systems level but require continuous technical upgrading and institutional compliance to ensure consistent effectiveness across government entities.

The study further examined the role that security classification plays in strengthening records management and cybersecurity practices within ICTA and the wider public sector. Records management respondents particularly emphasized classification functions as a foundational governance mechanism for determining how records are accessed, stored, protected and shared according to their sensitivity levels. Participants explained that ICTA applies structured classification frameworks that categorise records into levels such as public, confidential, secret private and top secret. These classification guide access permissions, handling procedures, storage requirements and protection controls across digital records systems. Respondents further noted that classification practices are closely aligned with legal and regulatory requirements, particularly Computer Misuse and Cyber Crimes Act, as well as the Data Privacy Act, which shape institutional obligations relating to information security and data privacy.

Findings from both ICT and records management respondents also revealed that although overarching government classification guidelines exist, institutions are often required to contextualize and customize classification procedures based on their operational mandates and the sensitivity of the information they manage. This reflects the varying nature of government records across sectors and highlights the complexity of implementing uniform cybersecurity controls within diverse public institutions. One respondent observed:

What may be classified as top secret in one institution may not necessarily be top secret in another institution. Each organization must interpret classification requirements based on its functions and the nature of the data it handles (R10)

The findings further suggest that security classification extends beyond technical data protection and functions as a broader governance tool that supports regulatory compliance, accountability and risk management within digital records environments. However, variations in institutional interpretation and implementation may create inconsistencies in classification practices across the public sector, potentially weakening standardization efforts in secure records governance.

The study further examined the information security controls implemented within ICTA to protect the integrity and confidentiality of records and how these controls influence records management efficiency and governance processes. Information security and ICT respondents revealed that ICTA employs multiple layered security controls, including encryption technologies, role based access controls, firewalls, intrusion detection and prevention systems (IDS/IPS), secure audit trails and regular data backup mechanisms to safeguard digital records and information systems.

Participants indicated that these controls are designed to ensure that only authorized personnel cab access, modify or retrieve sensitive records, thereby reducing the risks associated with unauthorised access, data breaches, manipulation and information loss. The findings suggest that the integration of these controls strengthens trust in digital records systems by supporting accountability, regulatory compliance and transparency within public-sector operations.

Top management, ICT and information security respondents further emphasized that cybersecurity controls are embedded across different technological layers, including networks, databases and applications, reflecting a multi-layered institutional approach to information security governance. However, the findings also revealed that while these controls enhance security, they may simultaneously introduce operational challenges affecting service delivery and records accessibility. For instance, aging systems, increased system demand and infrastructure limitations may contribute to slower system performance and delayed access to critical records. One respondent explained that:

These controls can have both positive and negative impacts on records management and governance. While they enhance security by controlling access and detecting malicious activity, some systems may experience performance degradation, especially when user demands increase or when systems become outdated (R2)

The information security respondents additionally demonstrate that ICTA evaluates the effectiveness of information security controls through continuous monitoring mechanisms such as audits, risk assessments, compliance reviews and automated reporting systems. Key performance indicators include the number of attempted or blocked cyberattacks, incident response time, user access violations, audit trail completeness and the frequency of successful security breaches.

Participants noted that Security Information and Event Management (SIEM) systems, compliance dashboards and access logs are among the primary tools used to monitor institutional security performance and support governance objectives. These tools enable ICTA to proactively identify vulnerabilities, assess emerging threats and strengthen institutional resilience within digital governance environments.

As highlighted by an information security respondent;

Some of the tools such as Security Information and Event Management (SIEM) systems, access logs, and compliance dashboards help us monitor performance and ensure that controls are effectively supporting transparency, accountability and data integrity within the departments (R5)

Collectively, the findings demonstrate that information security controls play a critical role not only in protecting digital records but also in supporting broader governance objectives within Kenya's public sector. Nevertheless, the study highlights the continuing challenges of balancing robust cybersecurity protection with operational efficiency, infrastructure sustainability and timely access to government information.

The study further explored the institutional legal structures that supports ICTA's cybersecurity ecosystem within Kenya's public sector. It examines the key regulations, directives and policies guiding information security practices, as well as how these instruments are implemented and enforced across government systems.

Findings across top management, ICT and records management functions indicated that ICTA relies on key cybersecurity regulations and policies such as the Computer Misuse and Cybercrimes Act (2018), the Data Protection Act (2019), ICT Authority guidelines and internal information security standards. Collectively, these frameworks regulate records handling, access control. Incident response and user accountability, thereby strengthening the overall governance of digital information systems.

ICT, security and records management respondents indicated that these frameworks guide records handling, access controls, incidence response and user accountability. Implementation is achieved through staff training, integration of security policies into day to day operational procedures and secure system configurations across MCDAs and agencies. Enforcement is achieved through internal audits, compliance monitoring and disciplinary actions for violations. However, the findings also reveal variations in compliance and enforcement across institutions, indicating that implementation is not always uniform. A top management respondent noted the overarching legal framework:

These are the overarching regulations that we have, including Computer Misuse and Cybercrimes Act (2018), the Data Protection Act (2019), including international commitments such as the Malabo Convention (R1)

An information Security respond added that while frameworks exist implementation varies across institutions. In some cases, even basic directives; such as restrictions on the use of public WI-FI by government employees are not consistently followed exposing systems to avoidable security risk (R4)

The study further examined the institutional structures and operational frameworks in place to support and enhance the cybersecurity ecosystem within ICTA and across its affiliated departments. It also explored how these structures contribute to overall security posture of the organisation.

Findings from the top management, ICT and information security respondents indicate that ICTA has implemented a multi layered cybersecurity structure that includes dedicated ICT security unit, a cybersecurity policy aligned with national standards, incident response protocols and supporting technical controls. The ICT and Information security respondents further highlighted the use of firewalls, intrusion detection systems and vulnerability assessments to strengthen institution security posture.

The respondents indicated that these structures strengthen the organisations security posture by enabling proactive threat detection, supporting regulatory compliance and fostering a culture of cybersecurity awareness across all institutional levels. Rather than functioning as isolated technical tools, these mechanisms operate as an integrated governance system that links policy, people and technology.

Further findings highlight that ICTA's cybersecurity governance is also reinforced through structures inter-agency coordination frameworks. These include formal support mechanisms for MCDAs as well as collaboration with both public and private sector actors. Of particular importance is the close working relationship with the National KE-CIRT/CC, which facilitates information sharing, coordinated incident response and collective threat mitigation.

An ICT explained the institutional structure supporting cybersecurity governance:

ICTA’s security posture is strengthened not only through internal organizational structures but also through external collaboration networks that enable coordinated cyber defense across government systems. Through these arrangements, information is shared, incidents are jointly managed and institutional capacity is enhanced, thereby contributing to a more resilient national cybersecurity ecosystem (R15)

The study further examined the frequency with which ICTA reviews and update cybersecurity and records policies and procedures as well as the triggers and prioritization mechanisms guiding these updates. Findings across top management, ICT, records management information security respondents indicated that ICTA undertakes policy reviews on a periodic basis, typically at least after three years, or immediately in response to emerging cyber threats, compliance requirements or security incidents. A records management respondent explained that policy review cycles are complex and resource intensive, which sometimes affects the speed and regularity of updates.

The top management respondents explained that policy revisions are primarily triggered by threat intelligence reports, audit findings, internal policy evaluations and technological advancements. Prioritisation of updates is guided by structured risk assessment processes, where critical vulnerabilities are addressed first to ensure continuous protection of sensitive information assets and uninterrupted service delivery.

These findings suggest that ICTA adopts a risk responsive and compliance driven approach to policy governance, balancing regulatory obligations with operational capacity constraints. As a records management responded noted:

While policy updates are ideally undertaken within a three-year circle, the process is inherently dependent on institutional capacity, stakeholder engagement and approval structures. Unlike agile operational adjustments, policy revision is a structured and resource-intensive process requiring consultation, validation and board-level approval. Consequently, although some updates may occur annually or biennially in response to urgent needs, the minimum standard remains a three year review cycle within ICTA. Policy development and review is not an easy process; it requires resources and stakeholder engagement (R11)

The study further examined the processes established within ICTA and the broader public sector to ensure compliance with cybersecurity regulations and directives including the mechanisms used to monitor and enforce compliance as well as the challenges encountered in implementation. Findings indicate that compliance is supported through structured cybersecurity governance mechanisms, including internal and external audits, continuous staff training and alignment with national ICT policies, standards and regulatory frameworks. Monitoring processes are rein forced through automated security tools, audit logs, incident reporting systems and compliance checklists, while enforcement is undertaken through policy enforcement procedures and disciplinary measures for non-compliance.

The findings further reveal the fact that regular audits and reporting mechanism play a central role in evaluating institutional security posture and maintaining accountability across departments. However, despite the existence of these governance mechanisms, respondents acknowledge persistent implementation challenges, including limited financial and technical resources, rapidly evolving cyber threats, varying levels of cybersecurity awareness among staff and inconstant compliance practices across institutions.

These findings suggest that while Kenya's public sector has established important cybersecurity compliance structures, institutional capacity limitations continue to affect the effectiveness and uniformity of implementation. One respondent explained that;

Compliance monitoring is strengthened through annual and quarterly audits, as well as mandatory reporting requirements that require institutions to regularly submit security incident reports and institutional security assessments. Automated monitoring tools further support this process by generating reports that help institutions evaluate and demonstrate their security status (R18)

The study further explored additional structures, resources and institutional support mechanisms perceived as necessary for strengthening the cybersecurity ecosystem within ICTA and the wider public sector. Findings indicate that respondents considered the establishment of a centralised Security Operations Center (SOC), adoption of advanced threat intelligence systems, continuous professional training and modernization of digital infrastructure as critical priorities for enhancing cybersecurity resilience. Respondents also emphasized the importance of increasing financial investment and expanding the pool of skilled cybersecurity personnel to address emerging digital threats effectively.

The findings further demonstrate that capacity building remains a major concern within the cybersecurity ecosystem. Participants noted that limited technical expertise, insufficient staffing and constrained budgets continue to affect the implementation, maintenance and renewal of cybersecurity systems and tools. As a result, prioritization of cybersecurity improvements is often guided by risk exposure, available resources and institutional capacity. As one respondent observed that;

Cybersecurity implementation is heavily dependent on adequate funding adequate funding, specialized technical skills and continuous hands-on training. The respondent further noted that the field still lacks clearly regulated professional progression frameworks defining the competencies and qualifications required for cybersecurity practitioners, thereby affecting institutional capacity development and long-term sustainability (R6).

Another responded emphasized that;

Prioritization of cybersecurity improvements depends largely on the availability of financial resources, institutional capacity and awareness, noting that cybersecurity awareness remains a significant concern even at the national level (R16).

Lastly the study explored how ICTA collaborates with other departments, particularly records management and ICT units to enforce information security principles, access control and security classification procedures to support a holistic cybersecurity approach. Findings from all the 18(100%) indicated that the cybersecurity governance within ICTA is implemented through collaboration and cross sectional-functional approaches involving joint policy development, cross-departmental committees regular coordination meetings and shared operational responsibilities. Respondents emphasized that records management and ICT departments work closely to align access controls will varying levels of data sensitivity and ensure consistent application of security classification protocols across systems and institutional processes.

The findings further reveal that collaboration extends beyond policy coordination to include joint audits, staff training, implementation of secure systems and continuous information sharing between departments. Together, these practices contribute to the development of a unified cybersecurity culture in which information security responsibilities are distributed across institutional functions rather than confined to a single department.

Significantly, the findings demonstrate a growing recognition within ICTA that cybersecurity is inherently cross-cutting and cannot be effectively addressed through isolated technical structures alone. Instead, the protection of digital records and information assets increasingly depends on coordinated institutional governance involving records managers, ICT personnel, information security teams and organizational leadership.

An information security respondent emphasized the importance of integration collaboration by stating that:

Cybersecurity is cross-cutting in nature and cannot be left to one function alone. It requires cohesive collaboration because records constitute critical evidential assets that must be protected through both appropriate technologies and coordinated institutional practices. The respondent further emphasized the importance of developing departmental champions capable of promoting cybersecurity awareness and supporting implementation across organizational functions, thereby strengthening institutional resilience and collective responsibility for information security (R3).

Provision to access to information in support of evidence-based decision making, citizen empowerment and participation in government activities is fundamentally dependent on sound electronic management practices. The International Council on Archives (ICA) emphasises that effective records and archives management is an essential precondition for good governance, the rule of law, administrative transparency and access to information by citizens (International Council on Archives (ICA), 2016). In digital era, however, these governance objectives can only be effectively achieved when records management practices are aligned with robust cybersecurity measures, As noted by Kenya ICT Action Network and Global Partners Digital (2019) cybersecurity has emerged as a major concern within Kenya's ICT sector due to the rapid adoption of digital technologies across public and private institutions. Despite increased digitization, many institutions continue to underprioritize cybersecurity risks, exposing critical information assets to growing vulnerabilities.

The findings of this study demonstrate that cybersecurity and records management become increasingly interdependent within contemporary digital governance environments. The study revealed that ICTA integrates information security principles into records management through established policies governance frameworks and technical controls. Measures such as RBACs audit trails, version control systems, digital signatures, metadata standards reliable backup systems and disaster recovery mechanism collectively support the confidentiality integrity, authenticity availability, possession and utility of records. These findings reinforce the argument that effective records governance in the digital age extends beyond information access and preservation and include continuous protection of digital assets against evolving cyberthreats. These further reflects the records continuum perspective, which emphasizes ongoing accountability, accessibility, security and governance throughout the existence of records.

However, despite the existence of these institutional mechanisms, the findings further indicate that implementation remains uneven across public -sector institutions. Variations in institutional capacity, technological infrastructure, cybersecurity awareness and resource allocation continue to affect the consistency of cybersecurity enforcement and records protection practices across MCDAs and agencies. This observation aligns with findings from the Communication Authority of Kenya cybersecurity report (2024–2025) which noted increasingly cyber incidents involving malware attacks, system intrusions, data breaches, operational disruptions and data loss across sectors such as government, health, insurance and education. The report further attributes these vulnerabilities to inadequate investment in technical infrastructure, reliance on legacy systems, system configurations, weak authentication practices and low levels of cybersecurity awareness. Consequently, the study suggests that while Kenya has made considerable progress in integrating cybersecurity within records management frameworks, persistent implementation gaps continue to expose critical information infrastructure and public sector records system to cyber threats.

The findings further demonstrate that access controls and security classification mechanisms remain central components in strengthening records security and cybersecurity governance within the public sector. The study revealed that ICTA implements and advocates for RBAC mechanisms that allocate system permissions according to institutional responsibilities and operational needs. Additional controls such as, secure login credentials, two-factor authentication and audit trails, system logs and periodic access reviews are utilised to monitor access to sensitive records. These measures reflect a growing institutional recognition that access governance is essential for safeguarding the confidentiality, integrity and accountability of electronic records within digital governance environments.

The findings align with recommendations from the National KE-CIRT/CC 2024–25 which emphasizes the importance of implementing firewalls, intrusion detection systems, strong authentication protocols, secure password practices and continuous system upgrades to mitigate cyber threats. The increasing adoption of these controls within public institutions demonstrates a shift from traditional records protection approaches toward more integrated and technology-driven information governance practices. This further reinforces the argument that cybersecurity controls are no longer supplementary technical mechanisms but fundamental components of records management and digital governance frameworks.

The study further revealed that security classification plays a significant role in determining how records are accessed, protected and managed across public institutions. Respondents identified various classification categories including top secret, secrete, confidential, public, private records. However, the findings also suggest the existence of inconsistencies in the operationalization of these classifications across MCDAs. While classification practices appear to be guided by institutional mandates and business functions, respondents did not clearly identify standardized national instruments governing classification approaches and varying institutional interpretations regarding records sensitivity and information protection requirements.

The findings further highlight an important governance gap concerning the legal and operational clarity of information classification practices in Kenya. Although the Official Secrets Act (Cap 187) provides a legal basis for protecting sensitive state information, the legislation does not comprehensively define classification categories such top secret, secrete or confidential in operational terms comparable to some international jurisdictions. Instead, the Act broadly focuses on the protection of state secrets and national security information. The lack of standardized classification guidance may contribute to inconstancies in records handling, access management and information protection practices across public institutions. Consequently, the study suggests the need for clearer national classification frameworks and harmonized implementation guidelines to strengthen information governance, records security and institutional accountability within Kenya's evolving digital environment.

The findings additionally demonstrate that Kenya has established various legal and institutional structures aimed at strengthening the national cybersecurity ecosystem, Key frameworks identified by respondents include Computer Misuse and Cyber Crimes Act (2018), Data Protection Act (2019), ICTA cybersecurity standards and directives, sectorial policies and internationally recognised standards such as ISO/IEC 2700 series. Collectively, these frameworks provide mechanisms for regulating records security, cybersecurity governance access management and digital accountability within public institutions.

However, the findings also reveal persistent implementation challenges within the public sector. Although Kenya has developed and expanded cybersecurity policy and legislative environment, institutional implementation remains uneven across MCDAs. This observation supports concerns raised by Kenya ICT Action Network and Global Partners Digital (2019) and global Partners Digital (2019) which noted that several national ICT and cybersecurity strategies have experienced limited operationalization despite their policy significance. The findings therefore reinforce broader concerns within African cybersecurity governance formulation and scholarship regarding the gap between policy formulation and practical implementation.

At the continental level, the findings further reflect wider African cybersecurity governance challenges associated with harmonization, ratification and enforcement of reginal legal instruments. Respondents referenced the African Union Malabo Convention as an important continental framework for cybersecurity and data protection. However, as observed by Ifeanyi-Ajufo (2024) the Convention experienced prolonged ratification delays before entering into force in 2023, with relatively few African states having formal ratified it. The continued absence of ratification by several major African economies, including Kenya, highlight s ongoing regional challenges in achieving coordinated cybersecurity governance and harmonized digital policy implementation across the continent, These findings therefore suggest that while legal and policy structures continue to expand both nationally and regionally, stronger institutional coordination, enforcement mechanisms and implementation capacity remain necessary to achieve effective cybersecurity and records governance within the public sector.

The findings further revealed that ICTA reviews and updates cybersecurity and records policies and procedures periodically, particularly in response to emerging threats, compliance requirements, technological changes and security incidents. Although respondents indicated that policy reviews are ideally conducted after every 3 years, they acknowledged that urgent threats and audit findings may necessitate immediate revisions. However, the findings also demonstrate that policy development and review processes within the public sector are often lengthy and resource-intensive due to stakeholder consultations, institutional approvals and capacity limitations. This suggests that while policy responsiveness is recognized as essential, operational realities may delay timely adaptation to rapidly evolving cyber threats. The findings therefore reinforce the argument that cyber governance is not a one-time institutional exercise bother rather a continuous and adaptive process requiring sustained investment, technical expertise and organisational commitment.

These findings correspond with existing policy and scholarly literature emphasising the importance of continuous policy renewal and institutional adaptability in addressing cybersecurity challenges. In Kenya, policy instruments such as the National Cybersecurity Strategy 2025–2029 (under review) and the Kenya National ICT Policy Guidelines (2020) provide direction for strengthening and periodically adapting national digital governance frameworks, while KICTANet's Data Protection Policy Brief highlights the need for continued review and improvement of Kenya's data-protection framework (Government of Kenya, 2022; Kenya ICT Action Network [KICTANet], 2024). Similarly, international resources such as the International Telecommunication Union's (ITU) National Cybersecurity Strategies Repository provide a reference point for national cybersecurity strategy development and review, while the African Union Convention on Cyber Security and Personal Data Protection provides a continental legal framework for cybersecurity and data protection (International Telecommunication Union (ITU), 2022; African Union, 2014). The findings therefore demonstrate that effective cybersecurity and records management governance depends not only on the existence of policies but also on the institutional capacity to review implement and update them consistently in response to evolving digital threats.

Lastly, the findings established that collaboration between cybersecurity and records management and ICT departments is central to strengthening secure digital governance within ICTA and across the public sector. Respondents indicated that collaboration is achieved through joint policy development, cross-departmental committees, coordinated audits, staff training and regular interdepartmental engagements. The findings further revealed that records management and ICT teams work together to align access controls, security classifications and information protection mechanisms with institutional responsibilities and data sensitivity requirements. This demonstrates that cybersecurity is increasingly being approached as a shared organizational responsibility rather than a function confined solely to ICT departments.

The findings support broader scholarly and policy arguments emphasizing multistakeholder and cross-functional collaboration in cybersecurity governance. The report by Carnegie Endowment titled “When the Rubber Meets the Road: Cybersecurity and Kenya’s Digital Superhighway” (2023) argues that effective national cybersecurity resilience requires coordinated collaboration among government agencies, regulatory bodies and private sector actors. Similarly, Kenya's National cybersecurity strategy, ICT policy frameworks and communications Authority cybersecurity reports emphasize the need for institutional coordination, information sharing and integrated governance mechanisms. The findings therefore suggest that sustainable cybersecurity and records management practices cannot operate in isolation. Instead, coordinated institutional approaches that integrate records management, ICT and cybersecurity functions are necessary to safeguard digital records, strengthen accountability and enhance public trust in digital governance systems.

This study examined the integration of cybersecurity and records management practices within the ICTA and their contribution to good governance in Kenya's public sector digital environment. The findings demonstrate that cybersecurity and records management are increasingly interdepend functions that collectively support transparency, accountability, evidence-based decision making and secure service delivery in the digital age. Through policies, access controls, audit trails, digital signatures, disaster recovery mechanisms and institutional governance structures, ICTA has made significant progress in embedding information security principles within records management practices.

The study further established that legal and institutional frameworks such as the Computer Misuse and Cybercrimes Act (2018), the Data Protection Act (2019), ICTA standards and international information security standards provide an important foundation for strengthening Kenya's cybersecurity ecosystem. In addition, collaborative approaches involving records management, ICT and information security departments were found to enhance institutional coordination and promote a shared culture of information governance.

Despite the achievements, the study identified several persistent challenges affecting the effective integration of cybersecurity and records management practices across the public sector. These include inconsistent implementation of cybersecurity controls among MCDAs, limited technical and financial resources, inadequate staff capacity, fragmented operational structures, policy implementation gaps and ambiguities surrounding information classification frameworks. The findings also reveal that although policy review mechanisms exist, lengthy review processes and resource constraints may limit institutional responsiveness to rapidly evolving cyber threats.

The study contributes to existing scholarship by addressing the limited empirical attention given to the intersection between cybersecurity and records management within public sector governance frameworks, particularly in developing country contexts, By situating the study within Kenya's rapidly evolving digital governance landscape, the research provides context-specific insights into how integrated information governance practices can strengthen institutional resilience and secure digital transformation efforts in the Global South.

Thus, the study concludes that effective digital governance cannot be achieved through isolated cybersecurity or records management initiatives. Rather through sustainable governance in the digital era requires integrated adaptive and collaborative approaches that align cybersecurity, records management legal frameworks, institutional capacity building and continuous policy renewal. Strengthening these interconnections will be essential in enhancing public trust, protecting critical information assets and supporting secure, transparent and efficient government operations in Kenya and beyond.

To address the identified gaps and strengthen governance within Kenya's public sector, this study proposes an integrated cybersecurity and records management improvement framework. The framework is anchored on five interrelated pillars: Institutional coordination, policy harmonization, human capacity development, Inter-Agency collaboration and stakeholder inclusivity and technology modernization. It positions ICTA as a central coordinating authority working in collaboration with MCDAs, regulatory bodies, academia and private sector actors.

A core component of the framework is the establishment of a centralized governance structure supported by real time threat intelligence. ICTA should lead the development of a national SOC enhanced with advanced analytics and AI-driven tools to enable continuous monitoring, predictive threat detection and coordinated incident responses across MCDAs. Integration with the National KE-CIRT/CC and collaboration with the national innovation ecosystems such as Konza Technopolis would further enhance situational awareness and response efficiency.

The framework emphasizes the need for a unified and standardized approach to records classification and cybersecurity policy management across government institutions. ICTA should champion the development of a Kenya-specific security classification framework to ensure consistency in categorizing and protecting records. In parallel, policy review cycles should be institutionalized on an annual basis, supported by multistakeholder committees comprising ICTA Communications Authority (CA), Office of the Data Protection Commissioner (ODPC) and private sector representatives. Policy updates should be informed by threat intelligence, audit outcomes and emerging technological developments to ensure regulatory agility and alignment with global standards.

The framework recognizes human capacity as a critical determinant of cybersecurity effectiveness. ICTA should institutionalize mandatory annual cybersecurity and records management training for all MCDA personnel, delivered through accessible digital platforms, including mobile-based learning systems. This should be complemented by structured collaboration with universities and training institutions to integrate cybersecurity and records management competencies into academic curricula and professional certification pathways, thereby ensuring sustainable skills development within the sector.

ICTA should facilitate the establishment of a national cybersecurity and records management Taskforce to enhance coordination and shared responsibility across government and non-state actors. The taskforce should include regulatory agencies, academic institutions, professional associations, private sector actors and citizen representatives. This collaborative structure would strengthen information sharing, policy coherence and public trust while reinforcing cybersecurity as a collective governance responsibility rather than an isolated technical function.

The framework further underscores the need for the modernization of digital infrastructure to support secure and efficient records management. ICTA should advocate for secure cloud-based systems and hybrid architectures supported by public-private partnerships. Parallel investment in cybersecurity workforce development and certification programmes should be pursued in collaboration with local universities. Emerging technologies such AI-driven threat detection and mobile-based intrusion monitoring systems should be piloted within national innovation hubs, including Konza Technopolis to enhance scalability, adaptability and contextual relevance.

Together, these pillars constitute an integrated national framework that aligns cybersecurity and records management with Kenya's digital transformation agenda. The framework enhances institutional coordination, strengthens policy coherence, improves operational efficiency and reinforces compliance with legal and regulatory instruments. Ultimately, it supports the development of a resilient, transparent and trusted digital governance ecosystem, positioning ICTA as a central enabler of secure public sector information management.

This study focused on the information and communication Technology Authority as a single institutional case study within Kenya's public sector. Although the qualitative approach provided a rich and context specific insights into the integration of cybersecurity and records management practices, the findings may not be fully generalizable to all public sector institutions in Kenya or other developing country contexts. Additionally, the study relied primarily on perspectives from top management representatives, Records management professionals, ICT personnel and security officers within ICTA. The exclusion of frontline staff, citizens and external stakeholders may have limited broader perspectives on operational implementation and public experiences related to cybersecurity and records governance.

The rapidly evolving nature of digital technologies and cyber threats also presents a limitation as cybersecurity environments, policies and institutional practices continue to change overtime. As a result, some findings may require continuous review to remain relevant within dynamic digital governance environments. Furthermore, although the study explored institutional integration between cybersecurity and records management, it did not quantitatively measure the effectiveness of specific cybersecurity controls or governance outcomes.

Future research may therefore adopt mixed methods approaches involving multiple public institutions to enable broader comparative analysis and greater generalizability. Additional, studies may also examine citizen perspectives, frontline implementation experiences, emerging technologies such as artificial intelligence and blockchain in records security and the effectiveness of integrated cybersecurity governance frameworks within developing country contexts.

African Union
(
2014
), “
African union convention on cyber security and personal data protection
”.
African Union
(
2020
), “
The digital transformation strategy for Africa (2020-2030)
”,
available at:
 Link to the website
Akitra
(
2024
), “
Future-proofing your business: mastering cybersecurity in 2024
”,
available at:
 Link to the website
Alhassan
,
I.
,
Sammon
,
D.
and
Daly
,
M.
(
2016
), “
Data governance activities: an analysis of the literature
”,
Journal of Decision Systems
, Vol. 
25
No. 
1
, pp. 
64
-
75
, doi: .
Ambira
,
C.M.
(
2016a
), “
A framework for management of electronic records in support of e-government in Kenya
”,
Doctoral Dissertation, University of South Africa, University of South Africa, College of Human Sciences, Department of Information Science, available at:
 Link to the website
Ambira
,
C.M.
(
2016b
), “
A framework for management of electronic records in support of e-government in Kenya
”,
Doctoral Dissertation, University of South Africa
.
British Standards Institute
(
2018
), “
Information and cyber challenges in the public sector
”,
available at:
 Link to the website
Christen
,
M.
,
Gordijn
,
B.
and
Loi
,
M.
(
2020
),
The Ethics of Cybersecurity
,
Springer
.
[PubMed]
.
Communications Authority of Kenya
(
2025
),
National KE-CIRT/CC Cyber Threat Landscape Report
,
Communications Authority of Kenya
,
Nairobi
.
Computer Misuse and Cybercrimes Act
(
2018
),
No. 5 of
,
(Kenya)
.
Data Protection Act
(
2019
),
No. 24 of
,
(Kenya)
.
Goel
,
R.
,
Haddow
,
J.
and
Kumar
,
A.
(
2018
), “
Managing cybersecurity risk in government: an implementation model
”,
available at:
 Link to the website
Government of Kenya
(
2022
), “
National cybersecurity strategy 2022-2027
”.
Greaves
,
R.
(
2020a
), “
Intersection between records management and security management
”,
available at:
 Link to the website
Greaves
,
R.
(
2020b
),
Records Management, Governance and Cybersecurity in the Digital Era
,
Routledge
,
London
.
ICT Authority
(
2025
),
Digital Government and ICT Governance Report
,
Government of Kenya
,
Nairobi
.
Ifeanyi-Ajufo
(
2024
), “
The AU took important action on cybersecurity at its 2024 summit – but more is needed
”,
Chatham House, available at:
 Link to the website
International Council on Archives
(
2016
), “
IAAF hosts sports archive bureau meeting of international council on archives
”.
International Telecommunication Union
(
2022
), “
National cybersecurity strategies repository
”.
Kenya ICT Action Network
(
2019a
),
Cybersecurity and Digital Resilience in Kenya: Policy and Practice Insights
,
KICTANet
,
Nairobi
.
Kenya ICT Action Network
(
2019b
), “
Cybersecurity in Kenya: priorities for 2019
”.
Kenya ICT Action Network
(
2024
), “
Five years of Kenya's data protection act: reflections and considerations for the future (policy Brief No. 19)
”.
Kenya ICT Action NetworkGlobal Partners Digital
(
2019
), “
Cybersecurity in Kenya: priorities for 2019
”,
available at:
 Link to the website
Kenya Information and Communications (Amendment) Act
(
2013
),
No. 41A of
,
(Kenya)
.
Knight
,
J.
(
2016
), “
ICT attitude to recordkeeping: survey report now available
”,
available at:
 Link to the website
Lee
,
J.
,
Morduch
,
J.
,
Ravindran
,
S.
,
Shonchoy
,
A.
and
Zaman
,
H.
(
2021
), “
Poverty and migration in the digital age: experimental evidence on mobile banking in Bangladesh
”,
American Economic Journal: Applied Economics
, Vol. 
13
No. 
1
, pp. 
38
-
71
.
Mizrak
,
F.
(
2023
), “
Integrating cybersecurity risk management into strategic management: a comprehensive literature review
”,
Research Journal of Business Management
, Vol. 
10
No. 
3
, pp. 
98
-
108
.
Musembe
,
C.
(
2019
), “
E-records security management at Moi University, Kenya
”,
(PhD Thesis), University of KwaZulu-Natal, Pietermaritzburg, available at:
 Link to the website
Musembe
,
C.N.
and
Mutula
,
S.
(
2020
), “Cyberspace security threats and attacks on e-records management at Moi University, Eldoret, Kenya”, in
Chisita
,
C.T.
,
Drodolu
,
O.O.
,
Tsabedze
,
V.W.
and
Ngoakesti
,
M.J.
(Eds),
Handbook of Research on Records and Information Management Strategies for Enhanced Knowledge Coordination
,
IGI Global
, pp. 
333
-
353
,
[PubMed]
.
National Institute of Standards and Technology (NIST)
(
2018
), “
Framework for improving critical infrastructure cybersecurity
”,
available at:
 Link to the website
National KE-CIRT/CC
(
2026
),
Cyber Security Report: 2025-2026 Q2
,
Communications Authority of Kenya
.
Sabillon
,
R.
,
Cavaller
,
V.
and
Cano
,
J.
(
2016
), “
National cyber security strategies: global trends in cyberspace
”,
International Journal of Computer Science and Software Engineering
, Vol. 
5
No. 
5
, pp.
67
-
81
.
Sanderson
,
N.
(
2019
), “
Records management by stealth: an Australian practitioner's view
”,
Business Information Review
, Vol. 
36
No. 
1
, pp. 
23
-
29
, doi: .
Serianu
(
2023
), “
Reimagining the African cybersecurity landscape: Africa cybersecurity strategy
”,
available at:
 Link to the website
Serianu Limited
(
2015
), “
Kenya cyber security report 2015: achieving enterprise cyber resilience through situational awareness
”.
Stevens
,
T.
(
2018a
),
Cyber Security and the Politics of Time
,
Cambridge University Press
,
Cambridge
.
Stevens
,
T.
(
2018b
), “
Global cybersecurity: new directions in theory and methods
”,
Politics and Governance
, Vol. 
6
No. 
2
, pp. 
1
-
4
, doi: ,
[PubMed]
.
United Nations
(
2021
), “
Joint inspection unit report on cybersecurity in the United Nations system organizations
”,
available at:
 Link to the website
Upward
,
F.
(
1996
), “
Structuring the records continuum—part one: postcustodial principles and properties
”,
Archives and Manuscripts
, Vol. 
24
No. 
2
, pp. 
268
-
285
.
Yin
,
R.K.
(
2018
),
Case Study Research and Applications: Design and Methods
, (6th ed.) ,
Sage Publications
.
Federal Trade Commission
(
2016
), “
Privacy and data security update
”,
available at:
 Link to the website
International Organization for Standardization (ISO)
(
2016
),
Information and Documentation - Records Management Standard. Part 1: General
, (2nd ed.) ,
International Organization for Standardization
,
Geneva
.
Kshetri
,
N.
(
2019
), “
Cybercrime and cybersecurity in Africa
”,
Journal of Global Information Technology Management
, Vol. 
22
No. 
2
, pp. 
89
-
93
, doi: .
The International Council on Archives (ICA)
(
2016
), “
What are archives?
”,
available at:
 Link to the website
Published in Organizational Cybersecurity Journal: Practice, Process and People. Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) license. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this license may be seen at Link to the terms of the CC BY 4.0 licence.

Data & Figures

Supplements

References

African Union
(
2014
), “
African union convention on cyber security and personal data protection
”.
African Union
(
2020
), “
The digital transformation strategy for Africa (2020-2030)
”,
available at:
 Link to the website
Akitra
(
2024
), “
Future-proofing your business: mastering cybersecurity in 2024
”,
available at:
 Link to the website
Alhassan
,
I.
,
Sammon
,
D.
and
Daly
,
M.
(
2016
), “
Data governance activities: an analysis of the literature
”,
Journal of Decision Systems
, Vol. 
25
No. 
1
, pp. 
64
-
75
, doi: .
Ambira
,
C.M.
(
2016a
), “
A framework for management of electronic records in support of e-government in Kenya
”,
Doctoral Dissertation, University of South Africa, University of South Africa, College of Human Sciences, Department of Information Science, available at:
 Link to the website
Ambira
,
C.M.
(
2016b
), “
A framework for management of electronic records in support of e-government in Kenya
”,
Doctoral Dissertation, University of South Africa
.
British Standards Institute
(
2018
), “
Information and cyber challenges in the public sector
”,
available at:
 Link to the website
Christen
,
M.
,
Gordijn
,
B.
and
Loi
,
M.
(
2020
),
The Ethics of Cybersecurity
,
Springer
.
[PubMed]
.
Communications Authority of Kenya
(
2025
),
National KE-CIRT/CC Cyber Threat Landscape Report
,
Communications Authority of Kenya
,
Nairobi
.
Computer Misuse and Cybercrimes Act
(
2018
),
No. 5 of
,
(Kenya)
.
Data Protection Act
(
2019
),
No. 24 of
,
(Kenya)
.
Goel
,
R.
,
Haddow
,
J.
and
Kumar
,
A.
(
2018
), “
Managing cybersecurity risk in government: an implementation model
”,
available at:
 Link to the website
Government of Kenya
(
2022
), “
National cybersecurity strategy 2022-2027
”.
Greaves
,
R.
(
2020a
), “
Intersection between records management and security management
”,
available at:
 Link to the website
Greaves
,
R.
(
2020b
),
Records Management, Governance and Cybersecurity in the Digital Era
,
Routledge
,
London
.
ICT Authority
(
2025
),
Digital Government and ICT Governance Report
,
Government of Kenya
,
Nairobi
.
Ifeanyi-Ajufo
(
2024
), “
The AU took important action on cybersecurity at its 2024 summit – but more is needed
”,
Chatham House, available at:
 Link to the website
International Council on Archives
(
2016
), “
IAAF hosts sports archive bureau meeting of international council on archives
”.
International Telecommunication Union
(
2022
), “
National cybersecurity strategies repository
”.
Kenya ICT Action Network
(
2019a
),
Cybersecurity and Digital Resilience in Kenya: Policy and Practice Insights
,
KICTANet
,
Nairobi
.
Kenya ICT Action Network
(
2019b
), “
Cybersecurity in Kenya: priorities for 2019
”.
Kenya ICT Action Network
(
2024
), “
Five years of Kenya's data protection act: reflections and considerations for the future (policy Brief No. 19)
”.
Kenya ICT Action NetworkGlobal Partners Digital
(
2019
), “
Cybersecurity in Kenya: priorities for 2019
”,
available at:
 Link to the website
Kenya Information and Communications (Amendment) Act
(
2013
),
No. 41A of
,
(Kenya)
.
Knight
,
J.
(
2016
), “
ICT attitude to recordkeeping: survey report now available
”,
available at:
 Link to the website
Lee
,
J.
,
Morduch
,
J.
,
Ravindran
,
S.
,
Shonchoy
,
A.
and
Zaman
,
H.
(
2021
), “
Poverty and migration in the digital age: experimental evidence on mobile banking in Bangladesh
”,
American Economic Journal: Applied Economics
, Vol. 
13
No. 
1
, pp. 
38
-
71
.
Mizrak
,
F.
(
2023
), “
Integrating cybersecurity risk management into strategic management: a comprehensive literature review
”,
Research Journal of Business Management
, Vol. 
10
No. 
3
, pp. 
98
-
108
.
Musembe
,
C.
(
2019
), “
E-records security management at Moi University, Kenya
”,
(PhD Thesis), University of KwaZulu-Natal, Pietermaritzburg, available at:
 Link to the website
Musembe
,
C.N.
and
Mutula
,
S.
(
2020
), “Cyberspace security threats and attacks on e-records management at Moi University, Eldoret, Kenya”, in
Chisita
,
C.T.
,
Drodolu
,
O.O.
,
Tsabedze
,
V.W.
and
Ngoakesti
,
M.J.
(Eds),
Handbook of Research on Records and Information Management Strategies for Enhanced Knowledge Coordination
,
IGI Global
, pp. 
333
-
353
,
[PubMed]
.
National Institute of Standards and Technology (NIST)
(
2018
), “
Framework for improving critical infrastructure cybersecurity
”,
available at:
 Link to the website
National KE-CIRT/CC
(
2026
),
Cyber Security Report: 2025-2026 Q2
,
Communications Authority of Kenya
.
Sabillon
,
R.
,
Cavaller
,
V.
and
Cano
,
J.
(
2016
), “
National cyber security strategies: global trends in cyberspace
”,
International Journal of Computer Science and Software Engineering
, Vol. 
5
No. 
5
, pp.
67
-
81
.
Sanderson
,
N.
(
2019
), “
Records management by stealth: an Australian practitioner's view
”,
Business Information Review
, Vol. 
36
No. 
1
, pp. 
23
-
29
, doi: .
Serianu
(
2023
), “
Reimagining the African cybersecurity landscape: Africa cybersecurity strategy
”,
available at:
 Link to the website
Serianu Limited
(
2015
), “
Kenya cyber security report 2015: achieving enterprise cyber resilience through situational awareness
”.
Stevens
,
T.
(
2018a
),
Cyber Security and the Politics of Time
,
Cambridge University Press
,
Cambridge
.
Stevens
,
T.
(
2018b
), “
Global cybersecurity: new directions in theory and methods
”,
Politics and Governance
, Vol. 
6
No. 
2
, pp. 
1
-
4
, doi: ,
[PubMed]
.
United Nations
(
2021
), “
Joint inspection unit report on cybersecurity in the United Nations system organizations
”,
available at:
 Link to the website
Upward
,
F.
(
1996
), “
Structuring the records continuum—part one: postcustodial principles and properties
”,
Archives and Manuscripts
, Vol. 
24
No. 
2
, pp. 
268
-
285
.
Yin
,
R.K.
(
2018
),
Case Study Research and Applications: Design and Methods
, (6th ed.) ,
Sage Publications
.
Federal Trade Commission
(
2016
), “
Privacy and data security update
”,
available at:
 Link to the website
International Organization for Standardization (ISO)
(
2016
),
Information and Documentation - Records Management Standard. Part 1: General
, (2nd ed.) ,
International Organization for Standardization
,
Geneva
.
Kshetri
,
N.
(
2019
), “
Cybercrime and cybersecurity in Africa
”,
Journal of Global Information Technology Management
, Vol. 
22
No. 
2
, pp. 
89
-
93
, doi: .
The International Council on Archives (ICA)
(
2016
), “
What are archives?
”,
available at:
 Link to the website

Languages

or Create an Account

Close subscription notice
Close access options