Treasury and the Central Bank of Kenya have unveiled draft regulations that would obligate payment service providers and payment system operators to inform the regulator of any cyber breach that materially affects their operations.
The proposals require immediate notification after a material event, defined as a significant data breach, a prolonged systemic outage, or loss or unauthorised access to customer funds.
“A payment service provider or payment system operator shall notify the Central Bank about any material event that significantly affects its business and operations immediately after the material event occurs,” says the National Payment System Bill, 2026.
“A payment service provider or a payment system operator that fails or refuses to comply, or gives false information relating to the material event, shall be liable to administrative enforcement action by the Central Bank,” the draft states, and notes that non-compliance could attract fines of up to KSh1 million or licence revocation.
The draft cites official data showing that half of the KSh1.59 billion stolen from banks by hackers in 2024 occurred through mobile-banking channels.
Central Bank figures also reveal that mobile-banking fraud rose to KSh810.68 million in 2024 from KSh182.41 million in 2023.
Interpol reported that Kenyans lost $3.8 million (KSh492.3 million) in cash and cryptocurrency in 2025 after SIM-swap fraud, with fraudulent SIM cards exceeding 123,000 and incidents rising 327 per cent.
The Communications Authority of Kenya recorded 11.1 billion cyber-threats in the year to June 2026, a 29 per cent increase on the previous year.
The draft notes that the 2011 National Payment System Act does not address cybersecurity and that the regulator believes the law no longer matches the pace of technological change.
“This creates regulatory gaps that hinder innovation while exposing the financial system to risks such as fraud, cybercrime, money laundering, and operational inefficiencies,” the apex bank and the Treasury said.
The proposals also call for stronger risk-management measures, including threat-intelligence sharing, security testing, third-party risk oversight and tighter supervisory arrangements.
“Rapid digitisation, increasing reliance on technology and growing interconnection between banks, PSPs, fintechs, payment systems and third-party technology providers, expose the payment ecosystem to cyber threats, fraud, operational disruption, data compromise and risks associated with emerging technologies and new business models,” the draft states.
Regulators point to similar frameworks in the European Union, where providers must report major incidents within four hours, and in Thailand, where disclosure is overseen by the Bank of Thailand and related authorities.