Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat
Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 May 2018.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds any person who operates a computer system or a computer network in Kenya, whether public or private; the duty is not limited to a critical-infrastructure operator, a licensed entity, or a business of any minimum size, and it binds a government body as well as a private one.
- Immediately inform the National Computer and Cybercrimes Co-ordination Committee, established under section 4 of the Act, of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption.
- Include in the report a summary of how the breach occurred, an estimate of the number of people affected, an assessment of the risk of harm to them, and an explanation of any circumstance that would delay or prevent telling them.
- Failing to make this report is itself an offence: a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both; the Committee may separately propose isolating a suspected system pending resolution.
- This duty is in effect now and has applied since the Act commenced on 30 May 2018; the Computer Misuse and Cybercrimes (Amendment) Act, 2025 left this section unchanged.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A person who fails to report an attack, intrusion, or disruption under section 40(1) commits an offence and is liable, on conviction, to a fine not exceeding two hundred thousand shillings, imprisonment not exceeding two years, or both.
Penalty structure
Section 40(4)'s fine cap of two hundred thousand shillings; the same subsection separately authorises imprisonment for up to two years, either alone or in addition to the fine.
- Rule
- Fixed only
- As of
- 14 September 2026
- Currency
- KES
- Fixed cap
- 200,000
Who enforces it
Enforcement body
The National Computer and Cybercrimes Co-ordination Committee, established under section 4 of the Computer Misuse and Cybercrimes Act, 2018, is the body section 40(1) directs a report to.
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Any person who operates a computer system or a computer network in Kenya, whether public or private, must immediately inform the National Computer and Cybercrimes Co-ordination Committee of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption.
The report must include a summary of how the breach occurred, an estimate of the number of people affected, an assessment of the risk of harm to them, and an explanation of any circumstance delaying their notification. The Committee may propose isolating a suspected system pending resolution. Failing to report under this duty is itself an offence, punishable by a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official consolidated Act text, National Council for Law Reporting (Kenya Law)