Call/ WhatsApp us: 0710942629 / 0736677646 Email: omaadvocates@gmail.com
Cybersecurity Law Advocates in Nairobi, Kenya
Cybersecurity law sets the rules for data privacy, punishes cybercrimes like hacking and fraud, and requires organisations handling sensitive or critical systems to keep them properly secured. As Kenyan businesses move more of their operations online, cybersecurity compliance has stopped being an IT-only concern and become a genuine legal exposure. At Ondieki & Matoke Company Advocates, we advise businesses on cybersecurity compliance, respond to incidents when they happen, and represent clients pursuing or defending cybercrime claims.
The Legal Framework
- The Computer Misuse and Cybercrimes Act, 2018 (CMCA) — The primary statute governing cybercrime in Kenya. Its objects are to protect the confidentiality, integrity, and availability of computer systems and data; prevent unlawful use of computer systems; facilitate the detection, investigation, and prosecution of cybercrimes; protect constitutional rights to privacy, freedom of expression, and access to information; and facilitate international cooperation on cybercrime matters.
- The Data Protection Act, 2019 — Governs how personal data is collected, stored, and shared, and works alongside the CMCA wherever a cyber incident involves personal data. See our Data Protection page for the full compliance picture.
- Coordinating Bodies — Kenya’s cybersecurity coordination is centred on the National Computer and Cybercrimes Co-ordination Committee, established under the CMCA, working alongside the National KE-CIRT/CC (NC4) on incident response and critical infrastructure protection.

Kenya’s Cybersecurity Regulatory Instruments
Beyond the founding Act, Kenya’s cybersecurity regime is built out through a set of specific regulations and standards:
- The Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024
- The National Cybersecurity Strategy 2022–2027
- The CII (Critical Information Infrastructure) Gazette Notice
- The Computer Misuse and Cybercrimes Act, 2018
- The Procedure for Designation of CII and Compliance
- Guidelines for Implementing Security Operations Centers (SOC)
- Cybersecurity Standards for Adoption
If your business operates in a sector that could be designated Critical Information Infrastructure power, finance, telecommunications, and similar essential services these instruments, not just the founding Act, are what actually define your compliance obligations.
Key Definitions Under the Act
- Access — Broadly defined to cover gaining entry to a computer system or data and then altering, copying, transferring, displaying, or executing it a wider definition than most people expect, capturing far more than just “hacking into” a system.
- Interference — Any impairment to the confidentiality, integrity, or availability of a computer system, program, or data the legal standard used to assess whether a cyber incident constitutes an offence.
- Cybersquatting — Registering a domain name in bad faith to profit from, mislead, damage the reputation of, or block someone else’s trademark or personal name a specific offence under the Act, and one that overlaps directly with trademark protection.
- Interception — Monitoring, modifying, viewing, or recording non-public data transmissions, or listening to or recording a computer system’s functions without authorisation.
- Critical Infrastructure — Processes, systems, facilities, and networks essential to the health, safety, security, or economic wellbeing of Kenyans and the effective functioning of government the category that determines whether the heightened CII compliance obligations apply to your organisation.
Key Parts of Cybersecurity Law
- Cybercrime Rules — Outlaws illegal access, data theft, phishing, fraud, and cyber terrorism.
- Data Protection & Privacy — Controls how personal information is gathered, stored, and shared.
- Critical Infrastructure Protection — Sets heightened safety standards for vital sectors like power, finance, and transport.
- Breach Notification — Requires organisations to report data leaks to the relevant authorities and affected individuals promptly.

Our Cybersecurity Services
- Cybercrime Incident Response & Legal Advisory — Guiding you through the legal steps required immediately after a breach or cyber incident, including engaging law enforcement and the Communications Authority where necessary.
- CII Compliance Advisory — Advising businesses on whether they fall within Critical Information Infrastructure designation, and what that means for compliance under the 2024 Regulations.
- Cybersecurity Policy & Compliance Programmes — Developing internal cybersecurity policies aligned to both the CMCA and the Data Protection Act.
- Cybercrime Litigation & Enforcement — Representing victims of hacking, fraud, or cybersquatting, and defending clients facing cybercrime allegations.
- Breach Notification Compliance — Advising on your legal obligations to notify authorities and affected individuals following a data breach.
- Technology & Vendor Contract Review — Reviewing agreements with cybersecurity vendors, cloud providers, and IT service partners to ensure your legal exposure is properly allocated.
Why Ondieki & Matoke Company Advocates
- Direct access to your advocate throughout not a call centre or a junior clerk.
- Practical, calm guidance during what is often a genuinely stressful moment for a business a breach or cybercrime incident.
- Coordinated advice across cybersecurity and data protection, since the two are rarely separable in practice.
- A transparent process and fee structure, explained clearly before work begins.

What to Expect — Our Process
- Initial consultation — you share what’s happened or the compliance question you’re facing.
- Assessment — we assess your legal exposure, notification obligations, and any CII designation considerations.
- Response or advisory — we guide your immediate response to an incident, or advise on the compliance programme you need.
- Documentation & notification — we help you meet any breach notification obligations correctly and on time.
- Follow-through — where enforcement or litigation is needed, we represent you through to resolution.
Frequently Asked Questions
Act quickly to contain the breach, assess what data or systems were affected, and determine your notification obligations under the Data Protection Act and, where relevant, sector-specific rules. Getting legal advice early helps ensure notifications are made correctly and within required timeframes, rather than compounding the incident with a compliance failure.
Yes. Unauthorised access to a computer system or data is a criminal offence under the Computer Misuse and Cybercrimes Act, 2018, alongside related offences like data interference, unauthorised interception, and cyber fraud.
The Act covers unauthorised access and interference with computer systems and data, cybercrime offences including fraud and phishing, protections for critical information infrastructure, and specific offences such as cybersquatting. It also establishes the institutional framework for investigating and prosecuting cybercrime in Kenya.
Critical Information Infrastructure refers to systems and networks essential to the health, safety, security, or economic wellbeing of Kenyans, typically in sectors like power, finance, telecommunications, and transport. Whether your business is designated CII depends on your sector and role this is worth confirming directly, since designation brings significantly heightened compliance obligations under the 2024 Regulations.
Cybersquatting is registering a domain name in bad faith to profit from, mislead, or damage the reputation associated with someone else’s trademark or name. It’s a specific offence under the Computer Misuse and Cybercrimes Act, and it also frequently overlaps with trademark infringement claims.
Call now for a Free Consultation
Contact
0710942629 / 0736677646 / omaadvocates@gmail.com / info@omaadvocates.co.ke
Office
A.C.K. Garden Annex, 1st Ngong Avenue, Ground Floor, Suite 04, Upper Hill, Nairobi, Kenya
Open Hours
Monday-Saturday 8 am – 5pm
Weekends on Appointments only.
