On this page

Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
A relatively small policy change within the country of Kenya could have significant implications for the future of managed services. Maybe.
The Central Bank of Kenya (CBK) has made it a requirement for its banks to disclose to regulators if there was an "attack" on the bank and how the bank handled the attack. The US banking system has a similar requirement around data security monitoring, and all 50 states now have data breach notification laws.
Now, what is unclear is whether the CBK requires reporting of data breaches or just attacks. Regardless, this policy change signals what is likely to be viewed as a global shift towards greater transparency within the cybersecurity community (which includes everyone) to disclosure breaches (something which already exists globally) and the shift towards disclosure of attempted attacks (which does not currently exist).
Disclosures of Attempted Cyber Attack
Data breach notification requirements make sense to most people (which is why it is becoming law in most developed nations around the world). But, requiring an organization to disclose an attempted attack (before a breach has occurred) presents some challenges. Even the best MSPs could have a difficult time knowing whether an attempted access to a network or system was valid or not. Understanding the intent of an impersonal IP address is practically impossible unless it is coming from a known offender or geographic location known to be hostile.