
Recently, I was involved in a discussion with an acquaintance about a home-security upgrade. The additional investment was not necessarily on the radar, except that the person told me that he had suspected someone may have breached his perimeter fence without stealing anything.
This investment, he said, was his “second wave” of home security, having completed what he considered the basics a year prior.
It reminded me of the current state of cybersecurity in Kenya, where we are clearly seeing a similar “second wave” investment in security in the digital realm.
As our data moves from on-prem servers to the cloud, many organisations are realising that while the neighbourhood may have changed, the threat has not. This is in no way alarmist; it is just an acknowledgement of the status quo.
Africa, as we know, is no longer just a participant in the digital revolution. If we look at East Africa, we are its rising star. Recent research from McKinsey suggests that Africa’s cloud growth potential exceeds that of more mature markets such as Europe.
With 40% of infrastructure already migrated as of 2024, it is safe to say this continent is bypassing legacy limitations and surging into the digital future.
The continent has clearly seen the advantages of being in the cloud: reduced total cost of ownership and an ability to level the playing field with international competitors of any size, among other benefits. However, as this reality accelerates, we are facing a critical consideration: data sovereignty.
The data sovereignty challenge
Kenya released pivotal national policies on data and the cloud. These aren’t just suggestions; they are policy mandates. Under the Data Protection Act in Kenya, there are strict conditional cross-border transfer regimes that act as de facto data localisation for certain types of data.
Certainly, from Kenya’s perspective, the environment is dynamic with local players filling the void and the country waiting for the international giants to turn soil in the country.
The data sovereignty imperative exists alongside the need to keep the data safe. This all creates a complex challenge for an organisation’s C-suite. And so, as organisations navigate this evolving landscape, how do they protect their data while leveraging the power and advantages of the cloud?
The cloud security fallacy
The biggest misconception in the market is the belief that security in the cloud is someone else’s problem. Many business leaders fall into a false sense of security, assuming that because they are using a world-class provider, their data security is automatically bulletproof. This is a dangerous misconception.
Cloud security operates on a shared responsibility matrix. Perhaps it is best to think of this in terms of an analogy.
The provider secures the building, the cables and the physical “box”, so to speak. The end user, you, is responsible for securing the doors, the windows and the locks. You are in charge of your encryption, configuration and your organisation’s digital hygiene.
Modern security does not override old-school discipline
How often have you heard the question: How much security is too much? Or worse, the refrain that cybersecurity is just another cost centre?
What began as a casual conversation among colleagues about the “second wave” of home security quickly turned into a discussion about purchasing a new car.
One shared that she had just purchased a vehicle and that smashandgrab tint and a tracker were part of the standard checklist. The first, a necessity shaped by daily realities on Kenyan roads; the second, a requirement for insurance.
What might once have been considered optional features are now viewed as nonnegotiable fundamentals of car ownership — much like how cybersecurity is evolving in our digital lives.
Now, consider that a few decades ago, gearlocks and steering locks were the standard security layer. Indeed, many people still use gearlocks and steering locks today, in addition to whatever new technologies have been brought to the table. The gearlock physically prevents the vehicle from being operated.
Related to this, we must understand that data sovereignty isn’t just a legal hurdle. It is a security architect’s blueprint.
In other words, when the law says data must stay within a country’s borders, a gearlock mindset ensures that even when data is hosted locally or in hybrid environments, it remains as protected as if it were in a physical vault on-prem. That understanding is critical to understanding modern cybersecurity.
What do we learn from this? The world has evolved, and so we need to evolve too. For the modern organisation, in addition to supporting a gearlock mindset, the second wave of security essentials for our digital world includes:
Endpoint security: Protecting the organisation’s devices that access the cloud.
Identity and access management: Ensuring that only the right people have the keys to the organisation.
Vulnerability and patch management: Keeping the software updated to avoid breakdowns and known vulnerabilities.
The bottom line
To return to the vehicle analogy: Whether you are driving a high-end, modern push-to-start, software-driven electric vehicle that requires a fob or NFC mobile phone to be present to start, or an old-school petrol-driven manual car with a mechanical gearlock installed, the goal remains the same: you want to prevent somebody else from driving off with your asset.
Securing your data needs the same pragmatic approach. As we navigate the grey areas of data regulations and the vastness of the African cloud market, security cannot be an afterthought. It must be “baked in” to the organisation’s infrastructure investments, and not “bolted on” after the fact. Organisations are innovating and building incredible infrastructure on a continent. The onus is on all of us to make sure we aren’t leaving the keys in the ignition.
By Allan Juma, Lead Cyber Security Engineer at ESET


