A visit to Nairobi for the CITO EA launch by software escrow provider ESCROWSURE has brought renewed attention to a concern raised by technology leaders across East Africa: how to maintain business continuity when critical software vendors fail.
When Anthony Watson, CEO of ESCROWSURE, touched down in Nairobi for the CITO East Africa launch in December last year, he was welcomed by the vibrant conversations East African chief information officers were having around artificial intelligence, cloud migration, and automation.
Because ESCROWSURE is a valued partner of CIO South Africa, Anthony gladly accepted the invitation from Executive Communities managing director Joël Roerig. He joined the historic launch of CITO East Africa, a unique executive community platform for technology leaders across Kenya, Rwanda, Tanzania, and Uganda.
As he engaged with senior technology leaders across the region, a recurring concern quickly emerged regarding how organisations can maintain business continuity when critical software vendors fail. According to Anthony, many organisations are accelerating digital transformation without putting in place the governance structures needed to manage vendor dependency.
“Boards are approving mission critical platforms that run core operational processes, yet in many cases there is no structured mechanism to ensure continuity if the vendor becomes insolvent, is acquired by a competitor, withdraws support, or experiences operational disruption,” Anthony said.
He noted that in sectors such as financial services and healthcare, where core systems underpin payments, policy administration, claims processing, and regulatory reporting, the failure of a software provider can have immediate consequences beyond IT operations.
“Prolonged software failure is not simply an IT issue. It creates immediate operational exposure, potential regulatory scrutiny, reputational damage, and direct accountability at board level," he said.
Anthony observed that the discussion showed that many organisations still rely on contractual safeguards within supplier agreements, such as service level commitments and termination clauses, as their primary form of protection. However, he noted that contractual rights do not automatically provide access to source code, development environments, or the technical documentation needed to rebuild or maintain a system.
“Without access to these components, organisations may find themselves unable to operate critical systems if a vendor is no longer able to provide support,” Anthony noted.
He added that the conversations reflect a broader shift in how organisations are approaching technology risk, as digital systems become central to business operations and regulators increase their focus on operational resilience and third-party risk management.
"Organisations that cannot demonstrate credible continuity arrangements for mission critical systems may face growing audit pressure," Anthony said.
To mitigate this risk, Anthony argues that organisations must ensure they can access the technical assets required to maintain, update or rebuild systems under defined conditions, moving beyond simply relying on source code to establishing legally enforceable and technically validated continuity frameworks.
“As organisations deepen their reliance on third party platforms, vendor continuity is increasingly being treated as a governance issue. Vendor continuity risk is becoming a strategic issue requiring board level attention," he said.





