Kenya has named the first chair of a dedicated national cyber agency. On 24 August 2026, ICT and Digital Economy Principal Secretary Eng. John Tanui announced that Dr Martin Koyabe, a UK-based cybersecurity expert, is the inaugural non-executive chairperson of the board of the National Cybersecurity Agency (NCSA).
Tanui said the appointment lands as Kenya tries to grow the digital economy toward 30 percent of GDP. A standalone agency, he argued, is a strategic milestone: government services, payments, AI, cloud, data centres, BPO and “digital jobs” now sit on infrastructure that is also a national-security problem. The digital economy is no longer a side bet for Nairobi. It is the growth story the government sells to investors, and it is the attack surface criminals and geopolitically motivated actors already use.
That is why a chairperson’s name, announced on a Monday in late August, is more than a personnel notice. It is the first time the Kenyan state has put a single public face on a problem that has spent 2026 leaking into headlines — Interpol rankings, SIM-swap factories, a defaced presidency website, and billions of logged threat events in a single Communications Authority quarter.
Why a new agency, and why now
Kenya has spent 2026 in Interpol’s headlights. The African Cyberthreat Assessment Report 2026 placed the country second on the continent for exploitable digital vulnerabilities detected in 2025, at 11.9 percent, behind only South Africa. SIM-swap investigations jumped 327 percent. More than 123,000 fraudulent SIMs were issued. About Ksh 500 million left mobile wallets. In July, president.go.ke was defaced with a bitcoin ransom note. The Communications Authority has previously reported 2.35 billion cyber-threat events in a single quarter. None of that is a staffing gap in one ministry. It is a systems failure across telcos, banks, counties and the centre of government.
Until NCSA, cyber policy in Kenya lived in overlapping rooms: the Ministry of ICT, the Communications Authority, the National KE-CIRT/CC, the Directorate of Criminal Investigations’ cybercrime unit, and a patchwork of bank and telco SOCs that do not share a same-day freeze protocol. When a SIM is hijacked, the bank can often see the theft in real time and still cannot kill the line without a court order. When a government portal is probed, the ticket may sit in a queue that was never designed for nation-state tempo. A board that outlasts a single circular is supposed to close that gap.
Koyabe’s brief, as Tanui framed it, is to help build an institution that can protect digital infrastructure without smothering the innovation story Nairobi sells. That tension is the job. Enough control to stop a SIM-swap factory. Not so much that every startup waits six months for a clearance. Kenya wants data-centre investment, AI talent and BPO contracts. Those buyers now ask, before they ask about tax, who is accountable when the VPN is last year’s build.
Who Martin Koyabe is — and what a non-executive chair can actually do
Koyabe is a UK-based practitioner, not a career politician. Coverage in TechAfrica News and Eastleigh Voice presents him as a cybersecurity expert appointed to a non-executive chair, which in Kenyan public bodies usually means he does not run day-to-day operations. He chairs the board. He sets tone, hires or recommends a chief executive, and is the person Parliament and the press will call when the next defacement happens. That is useful. It is also limited. A chair is not a security operations centre. A chair cannot patch a county hospital’s Fortinet box from London.
What a serious chair can do in the first 100 days is narrower and more important: lock a mandate, a budget line, and a legal channel into telcos and banks. Interpol’s Kenya chapter is not a mystery novel. The holes it names are unpatched routers, weak VPNs, misconfigured document portals, and SIM-swap social engineering of shop-floor agents. Those are operator problems. NCSA only matters if operators must answer it.
Watch three documents. First, the legal instrument that says who NCSA can compel — critical-infrastructure operators, licensees, counties. Second, the budget. An agency without analysts, incident responders and a 24-hour desk is a letterhead. Third, the interface with KE-CIRT, CA and DCI. If those three still run parallel war rooms, Kenya has added a fourth logo, not a command structure.
The economic argument Tanui is making
The 30 percent of GDP figure is a political target, not a SOC metric, but it explains the timing. eCitizen, Huduma, M-Pesa, the digital superhighway, Konza, and the push for AI and cloud jobs all assume the network is trustworthy enough for a teacher in Voi to pay school fees on a phone. Interpol’s ranking is the opposite of that assumption. Foreign partners — the UK review of 20 August is the nearest example — will not keep writing training cheques into a vacuum. They want a counterpart. NCSA is that counterpart, or it is nothing.
There is also a private-sector test. SACCOs hold on the order of a trillion shillings. Hospitals run imaging and billing on the same class of VPN appliances Gunra affiliates scan. Print estates in universities still expose PaperCut. Banks still treat SIM-swap as a customer-negligence story even after the High Court, in June 2026, held Safaricom and Diamond Trust Bank jointly liable for a Ksh 4.4 million loss. A national agency that cannot change those incentives will be ignored by the people who actually run the pipes.
What to watch between now and the next crisis
The next crisis will not wait for a board induction. PaperCut’s August zero-day, Citrix NetScaler in CISA’s KEV catalogue, and Check Point’s July ransomware spike are all live. Kenyan organisations are already in those datasets even when they are not named on the first slide. NCSA’s early usefulness is therefore boring: a public patch-priority list for operators, a same-day SIM-freeze protocol with CA and the banks, and a single number that a county CIO can call at 2 a.m.
A chair is not a SOC. The test is whether NCSA gets a budget, a mandate over critical operators, and a same-day channel with telcos and banks — the exact gaps Interpol named. Until then this is a nameplate. The appointment is still the most important Kenyan cyber story of late August, because it is the first time the state has put a single public face on the problem. The country will judge Koyabe not on the press release, but on whether the next SIM-swap ring, the next defacement, and the next ransomware note hit a desk that can act.
A 100-day checklist Kenya can hold him to
Public appointments die in the gap between the photograph and the first budget vote. A useful way to read the next three months is as a checklist, not a personality story. Day 30: a named chief executive or a dated search, and a one-page public mandate that says which operators NCSA can compel. Day 60: a written protocol with Safaricom, Airtel, the banks and KE-CIRT for same-day SIM freezes — the gap the High Court has already started to price. Day 90: a published patch-priority list for Kenyan critical operators that maps CISA’s KEV and Interpol’s boring holes (VPN, router, document portal) onto local estates. Day 100: a 24-hour desk that a county CIO can actually ring.
None of that requires Koyabe to write exploits. It requires the board to spend political capital on unglamorous plumbing. If those artefacts do not exist by year-end, Kenya will still have a chair, and Interpol will still have a ranking. Readers should keep both on the same desk.
The digital-economy target of 30 percent of GDP will be quoted again at the next conference. Quote it back with a question: what share of eCitizen, SACCO and hospital systems had an internet-facing admin plane last week, and who had the authority to order it shut. That is the chair’s real job description, whether or not it appeared in the 24 August announcement.