CIOs tackle governance and cyber resilience at CITO Summit 

post-title

As CIOS weighed in on topics of data access, governance, cyber security and cyber resilience at the CITO East Africa Data and Cyber Security Summit held at Villa Rosa Kempinski Nairobi, it was apparent that human actors have a bigger role to play than the tech. 

The first-ever CITO East Africa Data and Cybersecurity summit, which took place at the Villa Rosa Kempinski Nairobi on 17 July, brought together CIOs and CISOs from across the region to discuss matters related to cyber security, cyber reliance and data governance. The first panel discussion moderated by Executive Communities managing director Joel Roerig featured  Erick Ngwiri, director of global data and analytics at Catholic Relief Services, Faith Muricho, technical operations manager at a leading global cloud computing and digital infrastructure provider, Dennis Katusya, group technology delivery manager at Mitchell Cotts, and Uzma Qureshi, senior manager for EHR operations at Aga Khan University Hospital.

Eric set the tone early, pushing back on the instinct to hoard information simply because storage makes it possible. 

"Collect as little information as you need. The more information you collect, the more you expand the possibilities for insights.  When you focus on one decision and build on that, it makes it easier to focus on what you need from the data available," he said.

Less data, sharper decisions

Faith picked up the thread from the customer’s side, arguing that governance can't be bolted on after systems are built. It has to start with understanding the customer journey.

"We need to have an IT person and a standard in every customer journey. Once we understand that journey, then understand the data we have then we can build tech solutions based on that journey,” she said.

Dennis picked up from Faith’s remarks and emphasised on the importance of data governance and cyber security for business outlook.

"Data creates competitive advantage, and cybersecurity ensures that advantage is sustainable," he said. 

Towards the end of the first session, Jamila Aroi from PWC who were the official sponsors to the event took the stage and began her address by distinguishing between cyber security and cyber resilience.

“Cyber security is about defense while cyber security is about survival and recovery,” she said.

In the address Jamila set the scene by sharing statistics that $11 billion was lost in cyber crime and the number is expected to rise to $19.7 trillion by 2020. As a way to address emerging cybersecurity issues, she encouraged attendees to explore the use of AI.

“If you are thinking of cyber resilience as an organisation, you must also think of how to use AI to help you in cyberdefense,” she said.

Issues surrounding data access especially in sectors like healthcare took center stage during the interactive session as attendees deliberated on how best to ensure data access without abuse. They  also noted the friction between data governance regulations and sector specific governance frameworks and wondered who regulated the regulators in the different sectors. A further discussion arose on sharing accountability between CIOs and other stakeholders in organisations in cybersecurity issues with the consensus being that CIOs are left to bear the weight of responsibility alone especially when there is a cybersecurity issue.

 

Road markings, not roadblocks

In the final panel discussion of the day, Adili Group CISO Kiprono Rugut, KFC’s Yuki Ouchi, Mpesa Africa’s Tim Theuri and Ralph Lagillama took the stage in a short yet insight-packed session moderated by CITO East Africa’s community manager Sandra Mulluka.

During the panel, the ever changing nature of cyber security became apparent as Yuki described a recent AI generated scam in which fraudsters impersonated the KFC brand online, posting fake delivery numbers and collecting small mobile-money payments before vanishing. Interestingly, the solution was to invest in marketing to create awareness among customers as opposed to investing in more tech.

The thread was picked by Tim Theuri who confirmed that the face of cyber security has changed and attacks are no longer traditional. 

“These days, we are experiencing attacks where you are not even the one being hacked. It could be a vendor, a partner of yours, an integrator or somebody who has your customer data who's attacked. Just because you have shared customers, you have to manage it like you were the one attacked. It's a constantly evolving game,” he said. 

Tim further drew the room’s attention to the region's threat landscape, pointing to the geopolitics shaping cyberattacks and the professionalisation of ransomware. He noted that entire gangs are now operating with the infrastructure of legitimate enterprises. 

On his part, Kiprono reframed a tension experienced by most CTOs with the assumption that controls and innovation pull in opposite directions. 

Good governance, he argued, works less like a gate and more like a sandbox, where products can be tested and risk-assessed before they reach a customer, so the guardrails are already built in by launch day.

Tier I bank executive Ralph JC Ligallama picked up the same idea from the banking side, offering the line that would frame the rest of the session.

"Governance should act as road markings instead of the roadblockers," he said.

The human threat and fix

The panel also brought to light the significant risks that human actors pose to cyber security. Kiprono shared a cautionary story of a serious breach that came from trusted staff in an organisation. 

“It’s very inviting because you really don’t know who’s who. It actually reinforces the need for controls. Things like segregation of duties, closing the toxic concentration of power and role based access,” he said.

Ralph agreed that the inside-outside distinction is increasingly meaningless.

From a banking perspective, intruder prevention is from inside and outside. We have to ask ourselves how to protect our staff, for instance the Gen Z employees using AI tools to experiment but later it becomes an attack,” he said.

Nevertheless, Kiprono insisted that humans still remain an organisation’s best bet at cyber resilience.

"As tech professionals, your best assets are your people. Empower your people and make them the best.  That’s where innovation, culture and business transformation come from," he said.

The event was sponsored by associate partners Absa and GardaWorld Security and principal partner PwC Kenya.  

Related articles

How Uzma Qureishi oversaw Aga Khan Hospital's bold EHR leap

In 2022, Uzma Qureishi, Senior Manager of EHR Operations at Aga Khan Hospital Nairobi, led one of the boldest bets of her career, overseeing the institution's transition to a paperless system. The transition wrote the hospital into the region's history books as the first hospital in East Africa to run a full Electronic Health Record (EHR) system, namely MEDITECH Expanse.

IT heads weigh in on cybersecurity's talent problem 

A 2025 PwC report placed knowledge and skills gaps among the top challenges organisations face when implementing AI for cyber defence. Mpesa Africa’s head of cybersecurity Tim Theuri, Ecobank Uganda’s head of IT Juliet Kyomugisha and WASREB’s head of IT Brenda Anzagi weigh in on the challenge of finding talent in IT.

Fix policy gaps before scaling AI, CIO Summit panellists say

At the recent CIO of the Future Summit held in Kampala, Uganda, participants identified AI as one of their main concerns with loopholes in AI governance emerging as one of the greatest hindrances towards its effective use.

Clearer data governance frameworks dominate discussions at CITO Summit

When Ecobank Uganda's Juliet Kyomugisha, Nation Media Group's Russell Akuom and AAR Hospital's Ibrahim Juma took to the stage at the CITO East Africa Data and Cybersecurity Summit to report back from the roundtable sessions, the consistent message was that implementation is the hard part of data governance.

PwC Kenya’s Jamila Aroi urges leaders to build cyber resilience

The first-ever CITO East Africa Data and Cybersecurity Summit took place at the Villa Rosa Kempinski Nairobi on 17 July. During the event's keynote address, Jamila Aroi, partner for technology consulting at PwC Kenya, urged business and technology leaders to develop the ability to withstand, recover from and adapt to cyber incidents. 

Tanzania's tech leaders set agenda at CITO East Africa chapter launch

Over 35 CIOs and technology leaders from across Tanzania gathered on June 11 in Dar es Salaam to help shape the future of the country's technology leadership community. The inaugural CITO East Africa Tanzania Summit served as an agenda-setting forum, creating space for candid discussions on the priorities that will define the community in the months ahead.

The rise of East Africa’s CITO community

The Uganda edition of the CITO East Africa Summit began as a room full of technology leaders comparing operational challenges. By the end of the evening, the conversation had evolved into a discussion about community, collaboration and the need for CIOs across East Africa to stop working in isolation.

Rwandan CIOs bridge IT–finance gap to get technology funded

Rwanda’s technology leaders say their biggest challenge is getting risks funded before they escalate into costly failures. Critical warnings around cybersecurity, infrastructure, and system upgrades are often raised early, but not always approved in time.

Top