Kenya's Computer Misuse and Cybercrimes Act, 2018 (Act No. 5 of 2018, Cap. 79C) sets a general cyber-incident reporting duty, in section 40, on any person who operates a computer system or a computer network in Kenya, whether public or private: within twenty-four hours of an attack, intrusion, or other disruption to the functioning of another computer system or network, the operator must inform the National Computer and Cybercrimes Co-ordination Committee, and failing to do so is itself an offence carrying a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both.
Because that duty binds any operator of a computer system rather than a licensed or sector-specific status, it reaches an ordinary developer operating a website, app, or online service with a Kenya nexus, and the row is filed and flagged on that basis.
Separately, Part II of the same Act (sections 4 through 13) creates Kenya's critical-information-infrastructure regime: the Director of the Committee designates, by Gazette notice, which systems are "critical infrastructure", meaning a system whose disruption would interrupt a life-sustaining service, harm the economy, cause massive casualties, disrupt the money market, or severely affect national security; only the owner or operator of a system so designated carries the Act's further critical-infrastructure duties, including an annual compliance report and audit under section 13, with a penalty on conviction of a fine of up to two hundred thousand shillings or imprisonment of up to five years, or both, for an owner who fails to file or cooperate.
The Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 (Legal Notice No. 44 of 2024) operationalise that regime: an owner of designated critical information infrastructure must conduct an annual cyber-risk assessment and business impact analysis, submit a risk register to the Committee, designate a Chief Information Security Officer, and report a cybersecurity incident to the relevant Sectoral Cybersecurity Operations Centre within twenty-four hours of becoming aware of it.
Because that whole regime binds only an owner or operator the Director has individually designated by Gazette notice into one of the Regulations' named critical-infrastructure sectors, rather than a status any declared LexLint activity can express, it is recorded here rather than raised against a declared activity, the same treatment this profile gives Singapore's critical-information-infrastructure regime, Japan's designated critical-infrastructure operators, and New York's Department of Financial Services Part 500 covered entities.
The State Corporations (National Cybersecurity Agency) Order, 2026 (Legal Notice No. 89 of 2026, in effect from 15 May 2026) separately establishes a new National Cybersecurity Agency as the autonomous body coordinating national cybersecurity policy and auditing the cybersecurity resilience of designated critical information infrastructure; its own text creates no duty running to an undesignated private business, so it is named here as background rather than filed as an instrument.
No enacted Kenyan statute sets security requirements a software product or connected device must meet before or after it is placed on the market, so the product-requirements research dimension is a researched absence.
No general reasonable-security or information-security-programme statute reaches a business simply because it holds personal data; the nearest analogue is the Data Protection Act, 2019 sections 41 and 42, the technical-and-organisational-measures duty inside that comprehensive regime, an article this jurisdiction's privacy row already researches, the same architecture as General Data Protection Regulation (GDPR) Article 32, so it is not repeated here.
The same Act's breach-notification duty, section 43 (notice to the Data Commissioner within seventy-two hours and to the affected data subject), is likewise this jurisdiction's privacy-topic finding rather than restated here. No published enforcement record specific to section 40 is confirmed in the primary text.