The first-ever CITO East Africa Data and Cybersecurity Summit took place at the Villa Rosa Kempinski Nairobi on 17 July. During the event's keynote address, Jamila Aroi, partner for technology consulting at PwC Kenya, urged business and technology leaders to develop the ability to withstand, recover from and adapt to cyber incidents.
Speaking to almost 100 CIOs who attended the first-ever CITO East Africa Data and Cybersecurity Summit, Jamila challenged technology and business leaders to look beyond cybersecurity as a defensive measure and focus on building cyber resilience.
At the start of her keynote, she explained the difference between cybersecurity and cyber resilience for the audience.
“Cybersecurity is a defence. Cyber resilience is survival. We have to accept that in today’s world, cyber risk will happen,” she said.
She also noted that while many organisations have invested significantly in cybersecurity controls, systems and processes designed to prevent attacks, fewer have developed the ability to respond effectively, recover quickly and continue operations after an incident.
She said the growing scale and sophistication of cyber threats means organisations can no longer rely only on prevention. Instead, leaders must prepare for the possibility of disruption and ensure they have the right strategies, investments and capabilities in place to recover.
“Cyber resilience is about accepting that the risk will come and preparing ourselves to survive it,” she said.
The AI challenge
Highlighting the growing impact of cybercrime globally, Jamila pointed out that cyber threats are becoming more frequent and complex, with artificial intelligence (AI) creating new opportunities for both attackers and defenders. She explained that criminals are increasingly using AI to develop more advanced phishing attacks, malware and other cyber threats, making it harder for organisations to rely on traditional security approaches alone.
However, she added that organisations can also use AI as a powerful tool to strengthen their cyber defences, improve threat detection and respond more effectively to incidents.
“The same technology being used to create threats can also help us build stronger defences and improve our cyber resilience,” she said.
Drawing from PwC’s Digital Trust Insights survey, which captures the views of senior executives including CEOs, CIOs, CTOs and other business leaders, Jamila highlighted key challenges that organisations are facing as they work to strengthen their cyber resilience.
Among the major concerns identified in the survey was geopolitical uncertainty. She explained that global conflicts and tensions are increasingly influencing the cybersecurity landscape, with cyberattacks often becoming part of wider geopolitical disputes.
“Organisations must consider these external risks when developing their cybersecurity strategies, as threats are no longer limited to individual criminals but can also come from organised groups and state-linked actors,” she added.
Building cyber resilience
As a way to build resilience, Jamila encouraged leaders to move away from a reactive approach, where organisations only respond after an attack has occurred, towards a proactive approach that anticipates risks and prepares for potential disruption.
“Many organisations are still waiting for trouble before they act. The question leaders need to ask is whether they are preparing for a crisis or simply reacting when it happens,” she said.
She drew the attention of the room to the growing cybersecurity skills gap and the need to invest in skilled professionals.
“As cybercriminals continue to find new ways to exploit vulnerabilities, we must develop the expertise and capabilities needed to defend against these attacks,” she said.
Further, she reminded attendees that cyber resilience is a business priority that requires involvement from across the organisation, not only a technology issue. She pointed to strong governance, leadership commitment, employee awareness and continuous investment as the pillars of a resilient organisation.
"True cybersecurity is preparing for what is next, not what was last. Organisations cannot completely eliminate cyber risks, but they can build the resilience needed to respond, recover and continue moving forward when challenges arise," she said.





