As CIOS weighed in on topics of data access, governance, cyber security and cyber resilience at the CITO East Africa Data and Cyber Security Summit held at Villa Rosa Kempinski Nairobi, it was apparent that human actors have a bigger role to play than the tech.
The first-ever CITO East Africa Data and Cybersecurity summit, which took place at the Villa Rosa Kempinski Nairobi on 17 July, brought together CIOs and CISOs from across the region to discuss matters related to cyber security, cyber reliance and data governance. The first panel discussion moderated by Executive Communities managing director Joel Roerig featured Erick Ngwiri, director of global data and analytics at Catholic Relief Services, Faith Muricho, technical operations manager at a leading global cloud computing and digital infrastructure provider, Dennis Katusya, group technology delivery manager at Mitchell Cotts, and Uzma Qureshi, senior manager for EHR operations at Aga Khan University Hospital.
Eric set the tone early, pushing back on the instinct to hoard information simply because storage makes it possible.
"Collect as little information as you need. The more information you collect, the more you expand the possibilities for insights. When you focus on one decision and build on that, it makes it easier to focus on what you need from the data available," he said.
Less data, sharper decisions
Faith picked up the thread from the customer’s side, arguing that governance can't be bolted on after systems are built. It has to start with understanding the customer journey.
"We need to have an IT person and a standard in every customer journey. Once we understand that journey, then understand the data we have then we can build tech solutions based on that journey,” she said.
Dennis picked up from Faith’s remarks and emphasised on the importance of data governance and cyber security for business outlook.
"Data creates competitive advantage, and cybersecurity ensures that advantage is sustainable," he said.
Towards the end of the first session, Jamila Aroi from PWC who were the official sponsors to the event took the stage and began her address by distinguishing between cyber security and cyber resilience.
“Cyber security is about defense while cyber security is about survival and recovery,” she said.
In the address Jamila set the scene by sharing statistics that $11 billion was lost in cyber crime and the number is expected to rise to $19.7 trillion by 2020. As a way to address emerging cybersecurity issues, she encouraged attendees to explore the use of AI.
“If you are thinking of cyber resilience as an organisation, you must also think of how to use AI to help you in cyberdefense,” she said.
Issues surrounding data access especially in sectors like healthcare took center stage during the interactive session as attendees deliberated on how best to ensure data access without abuse. They also noted the friction between data governance regulations and sector specific governance frameworks and wondered who regulated the regulators in the different sectors. A further discussion arose on sharing accountability between CIOs and other stakeholders in organisations in cybersecurity issues with the consensus being that CIOs are left to bear the weight of responsibility alone especially when there is a cybersecurity issue.

Road markings, not roadblocks
In the final panel discussion of the day, Adili Group CISO Kiprono Rugut, KFC’s Yuki Ouchi, Mpesa Africa’s Tim Theuri and Ralph Lagillama took the stage in a short yet insight-packed session moderated by CITO East Africa’s community manager Sandra Mulluka.
During the panel, the ever changing nature of cyber security became apparent as Yuki described a recent AI generated scam in which fraudsters impersonated the KFC brand online, posting fake delivery numbers and collecting small mobile-money payments before vanishing. Interestingly, the solution was to invest in marketing to create awareness among customers as opposed to investing in more tech.
The thread was picked by Tim Theuri who confirmed that the face of cyber security has changed and attacks are no longer traditional.
“These days, we are experiencing attacks where you are not even the one being hacked. It could be a vendor, a partner of yours, an integrator or somebody who has your customer data who's attacked. Just because you have shared customers, you have to manage it like you were the one attacked. It's a constantly evolving game,” he said.
Tim further drew the room’s attention to the region's threat landscape, pointing to the geopolitics shaping cyberattacks and the professionalisation of ransomware. He noted that entire gangs are now operating with the infrastructure of legitimate enterprises.
On his part, Kiprono reframed a tension experienced by most CTOs with the assumption that controls and innovation pull in opposite directions.
Good governance, he argued, works less like a gate and more like a sandbox, where products can be tested and risk-assessed before they reach a customer, so the guardrails are already built in by launch day.
Tier I bank executive Ralph JC Ligallama picked up the same idea from the banking side, offering the line that would frame the rest of the session.
"Governance should act as road markings instead of the roadblockers," he said.

The human threat and fix
The panel also brought to light the significant risks that human actors pose to cyber security. Kiprono shared a cautionary story of a serious breach that came from trusted staff in an organisation.
“It’s very inviting because you really don’t know who’s who. It actually reinforces the need for controls. Things like segregation of duties, closing the toxic concentration of power and role based access,” he said.
Ralph agreed that the inside-outside distinction is increasingly meaningless.
From a banking perspective, intruder prevention is from inside and outside. We have to ask ourselves how to protect our staff, for instance the Gen Z employees using AI tools to experiment but later it becomes an attack,” he said.
Nevertheless, Kiprono insisted that humans still remain an organisation’s best bet at cyber resilience.
"As tech professionals, your best assets are your people. Empower your people and make them the best. That’s where innovation, culture and business transformation come from," he said.
The event was sponsored by associate partners Absa and GardaWorld Security and principal partner PwC Kenya.





