One disruption can travel across sectors.
The conference examines cascading dependencies and what they mean for continuity of essential services.
From compliance to
national resilience.
Advancing ISMS for governance, Critical Information Infrastructure resilience and sustainable development.


The question is no longer only whether controls exist, but whether institutions and critical systems can continue delivering essential functions when disruption occurs.
Kenya’s economy, public administration and essential services increasingly depend on interconnected digital infrastructure. That dependence creates opportunity, but it also means disruption can propagate across institutions, sectors and national functions.
The 7th Annual ISMS Conference connects legal obligations, standards, institutional governance and operational capability into a practical national resilience conversation.
Building on six previous editions, the 2027 conference expands the conversation from ISMS implementation and compliance into governance, continuity of critical functions, cross-sector resilience and sustainable digital development.
CISOs, CIOs, Directors, Heads of Departments, regulators, CII operators, risk and audit professionals, academia and industry.
The programme is designed to test how governance, standards and operational capability work together under real pressure.
Masterclasses, strategic plenaries, executive dialogue, practitioner sessions, case studies and a cross-sector resilience exercise replace a conventional four-day presentation format.
Critical sectors do not operate independently. Electricity, telecommunications, finance, government platforms, logistics, health systems, cloud providers and technology suppliers depend on one another.
The conference examines cascading dependencies and what they mean for continuity of essential services.
Boards, executives, CISOs and institutional leaders must connect risk ownership, investment, procurement and accountability.
The focus shifts from evidence of implementation to evidence of effectiveness, recovery and adaptive capability.
The conference will convene leaders from government, standards bodies, critical sectors, industry, academia and the information-security profession. Confirmed speakers will be published as the programme is finalised.
Cybersecurity, governance and national resilience.
ISMS, ISO/IEC 27001 and regulatory assurance.
Operators responsible for essential national services.
Technical capability, research and professional practice.
The conference is organised around six connected pillars that move from legal and institutional assurance to the resilience of critical national functions and sustainable digital development.
Translating statutory and regulatory requirements into operational controls and demonstrable assurance.
ISO/IEC 27001, continual improvement, integration and evidence that controls operate effectively.
Board and executive responsibility, risk ownership, CISO authority and investment decisions.
Continuity of critical functions, supplier risk, cloud concentration, OT, incident management and recovery.
Cross-sector dependencies, situational awareness, SOC coordination, information sharing and resilience metrics.
Secure digital public infrastructure, strategic technology dependencies, local capability and sustainable development.
The programme progresses from law and standards to governance, Critical Information Infrastructure resilience and a final cross-sector national resilience exercise.
Masterclasses, implementation workshops, case studies and executive-oriented sessions. Exhibition opens.
Connecting Kenya’s cyber and data-protection obligations to practical controls, ownership and evidence.
ISMS maturity, continual improvement, assurance and integration with continuity.
Risk ownership, reporting, investment and communicating cyber risk to decision-makers.
Official opening, keynote addresses, strategic plenaries and leadership panels.
What must ISMS deliver for Kenya?
Translating Kenya’s cybersecurity framework into institutional capability.
Leadership, governance and accountability.
Parallel executive, practitioner, CII and academic tracks. Exhibition closes.
Continuity, dependencies, supplier risk and recovery.
Third-party concentration and cross-sector dependencies.
Senior-level discussion on systemic risk, incident lessons and priority interventions.
A cross-sector scenario exercise followed by lessons, recommendations and a conference communiqué.
A disruption begins in one critical sector and progressively exposes consequences for others.
Participants decide on escalation, essential-service continuity, communication and recovery priorities.
Convert the exercise and conference deliberations into priority actions.
The exhibition runs from 11–13 May 2027. Partnership options can support visibility, technical contribution, structured engagement and practical solution demonstrations aligned to the conference pillars.
Partner packages range from exhibition opportunities to leadership visibility, masterclass support and the cross-sector resilience exercise.
Previous editions have brought together public and private sector leaders for practical discussion, technical learning, professional exchange and cross-sector collaboration.



National resilience cannot be delivered by ICT and cybersecurity professionals alone. The conference is designed for decision-makers, budget holders, risk owners and technical implementers.
The event is structured to move beyond discussion and produce guidance, recommendations, resilience insights and agreed priorities.
Proposed mappings between ISO/IEC 27001 controls and relevant cybersecurity and data-protection obligations.
Practical recommendations on institutional cyber-risk ownership and accountability.
A discussion paper on cross-sector dependencies and national resilience.
Recommendations for measuring organisational and sector cyber resilience.
Lessons and actions arising from the cross-sector resilience exercise.
Agreed institutional and national priorities emerging from the conference.
Registration, detailed programme, confirmed speakers and booking information will be published through the official NC4 and KEBS channels.
Register Interest →For sponsorship, delegate registration and programme enquiries, the conference team will publish the designated contacts as participation opens.
Official contact details will be published when registration and partnership bookings open.
Official contact details will be published when registration and partnership bookings open.
Approved technical contributions will be coordinated through the programme team.
A coastal setting. A national conversation.
Practical capability building, strategic dialogue and national resilience planning on Kenya's Indian Ocean coast.
Explore Mombasa