11–14 MAY 2027 MOMBASA, KENYA
7th Annual Conference · 11–14 May 2027

ISMS 2027 Information Security
Management Systems Conference

From compliance to
national resilience.

Advancing ISMS for governance, Critical Information Infrastructure resilience and sustainable development.

4-day capability & strategy conference
Exhibition · 11–13 May
MOMBASA · KENYA National cyber resilience · ISMS · CII
000DAYS
00HRS
00MIN
00SEC
Register Interest
Jointly convened byNational Computer and Cybercrimes Coordination Committee & Kenya Bureau of Standards
National Computer and Cybercrimes Coordination Committee
01 Conference progression
01ComplianceMeet the obligation
02CapabilityMake controls work
03ContinuitySustain essential functions
04ResilienceRecover, adapt and improve
Conference Direction

Compliance is the foundation. Resilience is the outcome.

The question is no longer only whether controls exist, but whether institutions and critical systems can continue delivering essential functions when disruption occurs.

Kenya’s economy, public administration and essential services increasingly depend on interconnected digital infrastructure. That dependence creates opportunity, but it also means disruption can propagate across institutions, sectors and national functions.

The 7th Annual ISMS Conference connects legal obligations, standards, institutional governance and operational capability into a practical national resilience conversation.

Official conference proposition · 2027
Conference at a Glance

A national platform built around capability.

Building on six previous editions, the 2027 conference expands the conversation from ISMS implementation and compliance into governance, continuity of critical functions, cross-sector resilience and sustainable digital development.

7thAnnual Edition
4Conference Days
6Thematic Pillars
3Exhibition Days

Designed for decision-makers and implementers

CISOs, CIOs, Directors, Heads of Departments, regulators, CII operators, risk and audit professionals, academia and industry.

Why this edition

From documented controls to demonstrable resilience.

The programme is designed to test how governance, standards and operational capability work together under real pressure.

Masterclasses, strategic plenaries, executive dialogue, practitioner sessions, case studies and a cross-sector resilience exercise replace a conventional four-day presentation format.

Why Resilience Now

Digital dependence has made resilience a shared responsibility.

Critical sectors do not operate independently. Electricity, telecommunications, finance, government platforms, logistics, health systems, cloud providers and technology suppliers depend on one another.

01 · SYSTEMIC RISK

One disruption can travel across sectors.

The conference examines cascading dependencies and what they mean for continuity of essential services.

02 · GOVERNANCE

Cyber risk is a leadership question.

Boards, executives, CISOs and institutional leaders must connect risk ownership, investment, procurement and accountability.

03 · ASSURANCE

Controls must work — not simply exist.

The focus shifts from evidence of implementation to evidence of effectiveness, recovery and adaptive capability.

Leadership

Speakers & strategic voices

The conference will convene leaders from government, standards bodies, critical sectors, industry, academia and the information-security profession. Confirmed speakers will be published as the programme is finalised.

To be announced

Government Leadership

Cybersecurity, governance and national resilience.

To be announced

Standards & Assurance

ISMS, ISO/IEC 27001 and regulatory assurance.

To be announced

Critical Infrastructure

Operators responsible for essential national services.

To be announced

Industry & Academia

Technical capability, research and professional practice.

Thematic Pillars

Six connected conversations.

The conference is organised around six connected pillars that move from legal and institutional assurance to the resilience of critical national functions and sustainable digital development.

PILLAR I

Law, Regulation & Assurance

Translating statutory and regulatory requirements into operational controls and demonstrable assurance.

PILLAR II

Standards & ISMS

ISO/IEC 27001, continual improvement, integration and evidence that controls operate effectively.

PILLAR III

Governance & Accountability

Board and executive responsibility, risk ownership, CISO authority and investment decisions.

PILLAR IV

CII Resilience

Continuity of critical functions, supplier risk, cloud concentration, OT, incident management and recovery.

PILLAR V

National Resilience

Cross-sector dependencies, situational awareness, SOC coordination, information sharing and resilience metrics.

PILLAR VI

National Security & Development

Secure digital public infrastructure, strategic technology dependencies, local capability and sustainable development.

Programme

Four days. One capability journey.

The programme progresses from law and standards to governance, Critical Information Infrastructure resilience and a final cross-sector national resilience exercise.

11 May 2027

Law, Standards, ISMS Capability & Governance

Masterclasses, implementation workshops, case studies and executive-oriented sessions. Exhibition opens.

Morning

Regulatory-to-control mapping

Connecting Kenya’s cyber and data-protection obligations to practical controls, ownership and evidence.

Midday

ISO/IEC 27001 implementation masterclasses

ISMS maturity, continual improvement, assurance and integration with continuity.

Afternoon

Governance and executive accountability

Risk ownership, reporting, investment and communicating cyber risk to decision-makers.

12 May 2027

Strategic Conference

Official opening, keynote addresses, strategic plenaries and leadership panels.

Opening

From Compliance to National Resilience

What must ISMS deliver for Kenya?

Plenary

Law, Standards and Assurance

Translating Kenya’s cybersecurity framework into institutional capability.

Leadership

Who Owns Cyber Risk?

Leadership, governance and accountability.

13 May 2027

CII & National Resilience

Parallel executive, practitioner, CII and academic tracks. Exhibition closes.

Track

From Protecting CII to Sustaining Critical National Functions

Continuity, dependencies, supplier risk and recovery.

Track

Can an Organization Be Resilient if Its Ecosystem Is Not?

Third-party concentration and cross-sector dependencies.

Roundtable

National Cyber Resilience Executive Dialogue

Senior-level discussion on systemic risk, incident lessons and priority interventions.

14 May 2027

National Resilience Exercise & Outcomes

A cross-sector scenario exercise followed by lessons, recommendations and a conference communiqué.

Scenario

Critical National Functions Resilience Exercise

A disruption begins in one critical sector and progressively exposes consequences for others.

Decisions

Continuity, coordination and recovery

Participants decide on escalation, essential-service continuity, communication and recovery priorities.

Outcomes

Lessons and Conference Communiqué

Convert the exercise and conference deliberations into priority actions.

Partnership

Exhibition & sponsorship

The exhibition runs from 11–13 May 2027. Partnership options can support visibility, technical contribution, structured engagement and practical solution demonstrations aligned to the conference pillars.

Platinum Partner
Gold Partner
Silver Partner
Exhibitor
Institutional Partner
Previous Editions

The ISMS experience

Previous editions have brought together public and private sector leaders for practical discussion, technical learning, professional exchange and cross-sector collaboration.

Your Audience

Who should attend

National resilience cannot be delivered by ICT and cybersecurity professionals alone. The conference is designed for decision-makers, budget holders, risk owners and technical implementers.

Target roles

CISOs & CIOsDirectors & HoDsISMS CoordinatorsRisk & AuditRegulatorsNational SecurityAcademiaTechnology Providers

Critical sectors

Government Digital ServicesTelecommunicationsFinancial ServicesEnergyTransportHealthWaterDigital Infrastructure
Conference Outcomes

Designed to leave behind practical outputs.

The event is structured to move beyond discussion and produce guidance, recommendations, resilience insights and agreed priorities.

OUTPUT 01

Sector ISMS Implementation Profiles

Proposed mappings between ISO/IEC 27001 controls and relevant cybersecurity and data-protection obligations.

OUTPUT 02

Governance Recommendations

Practical recommendations on institutional cyber-risk ownership and accountability.

OUTPUT 03

CII Interdependencies Paper

A discussion paper on cross-sector dependencies and national resilience.

OUTPUT 04

Resilience Maturity Measures

Recommendations for measuring organisational and sector cyber resilience.

OUTPUT 05

Exercise Report

Lessons and actions arising from the cross-sector resilience exercise.

OUTPUT 06

Conference Communiqué

Agreed institutional and national priorities emerging from the conference.

11–14 May 2027 · Mombasa

From compliance to capability. From capability to resilience.

Registration, detailed programme, confirmed speakers and booking information will be published through the official NC4 and KEBS channels.

Register Interest →
Direct Enquiries

Connect with the conference team.

For sponsorship, delegate registration and programme enquiries, the conference team will publish the designated contacts as participation opens.

Sponsorship

Sponsorship & Exhibition

Official contact details will be published when registration and partnership bookings open.

Delegates

Registration

Official contact details will be published when registration and partnership bookings open.

Programme

Speaking & Technical Contributions

Approved technical contributions will be coordinated through the programme team.

The destination · Kenya's coast

Mombasa

A coastal setting. A national conversation.

04°03′ S / 39°40′ E · INDIAN OCEAN
Meet in Mombasa

Four days.
One resilient future.

Practical capability building, strategic dialogue and national resilience planning on Kenya's Indian Ocean coast.

Explore Mombasa
LocationMombasa, KenyaConference venue to be announced
Dates11–14 May 2027
Exhibition11–13 May 2027
FormatMasterclasses · Plenaries · Tracks · Exhibition · Resilience Exercise
ConvenersNC4 & KEBS