security

Author: samsongetengah-coderCreated May 11, 2026Updated Sep 7, 2026
Analyse "

Executive Analysis

The proposed plan focuses on five key areas:

  1. Immediate infrastructure protection
  2. Governance and control
  3. Human resource capacity
  4. Security culture
  5. Monitoring and maturity development

This is a strong stabilization framework because it addresses both technical weaknesses and management gaps.

The biggest concern is that some recommendations depend heavily on executive approval, which may delay urgent action.


1. Firewall License Renewal

Analysis

This is correctly listed as Priority 1.

An expired firewall license creates major exposure because it may affect:

  • Threat intelligence updates
  • Malware signature updates
  • IPS/IDS effectiveness
  • Web filtering controls
  • Security patch updates

This leaves the organization exposed to:

  • Malware infiltration
  • Unauthorized access
  • Command-and-control communication
  • Zero-day vulnerability exploitation

For a broadcaster like Kenya Broadcasting Corporation, this could affect:

  • Internal communication systems
  • Broadcast transmission infrastructure
  • Corporate network services
  • Digital platforms

Strength

Immediate escalation to CEO level is appropriate.


Recommendation

Add Business Impact Statement

The recommendation should include measurable business risk.

Example:

Failure to renew the firewall license exposes the organization to increased cyber threats, service interruption, possible malware compromise, and reputational damage due to weakened perimeter defense.

This creates urgency for finance approval.


Add Temporary Risk Mitigation

While waiting:

  • Restrict unnecessary inbound traffic
  • Review firewall rules manually
  • Increase log monitoring
  • Disable unused exposed services

K24 Score

24/25

Strong recommendation, but needs contingency actions.


2. Centralization of Platforms under ICT

Analysis

This is one of the most strategic recommendations.

Decentralized platform ownership creates:

  • Shadow IT
  • Inconsistent patching
  • Weak access control
  • Poor incident visibility
  • Uncontrolled third-party access

The website issue is especially serious because public-facing systems are common attack entry points.


Strength

You correctly identify:

  • Governance fragmentation
  • Security ownership gaps
  • Developer management risk

The recommendation for centralized developer management is highly relevant.


Risk

The wording may appear operationally forceful.

Executive leadership often responds better to governance language.


Recommendation

Reframe as:

Establish centralized ICT governance for all digital platforms to ensure uniform security standards, access control, vulnerability management, and incident response coordination.


Add Governance Structure

Recommend creation of:

Digital Security Governance Committee

Members:

  • ICT
  • Legal
  • Corporate Communication
  • Digital teams
  • Audit

This improves implementation.


K24 Score

23/25

Very strong but needs governance framework detail.


3. Recruitment of Cybersecurity Officer

Analysis

This is critical.

The absence of a dedicated Cybersecurity Officer creates:

  • Lack of security ownership
  • Weak policy enforcement
  • Delayed incident response
  • Poor risk oversight

The HR rejection indicates governance misalignment.


Key Concern

The recommendation should include operational risk evidence.

Executives approve positions faster when tied to business risk.


Recommendation

Add justification: