Skip to content
HomeKenyaWhat 11.1 Billion Cyber Threats Mean for Data Centres

What 11.1 Billion Cyber Threats Mean for Data Centres

Edited by Kevin Jonathan Otieno7 October 20266 min

DataCentre254 · An Elmac Communications Ltd publication

Share
A network engineer connecting cables at a patch panel in a data centre
Detection at national scale is a physical process: every counted threat event crossed hardware like this, inside a building like this, before anyone wrote a report

In October 2026 the Communications Authority of Kenya announced that the country had detected 11.1 billion cyber threat events during the 2025/26 financial year, up 29.0 percent on the year before, alongside 83.1 million advisories issued to affected ICT users, up 60.8 percent. Most coverage will stop at the number, add the word alarming, and move on. The number deserves a different reading, because detection at that scale is not a software story. It is an infrastructure story, and it is one of the cleanest demand signals for Kenyan data centres published all year.

Start with what the figure actually is. The National KE-CIRT/CC, the country's 24/7 computer incident response team operating within the Authority, publishes quarterly cyber security reports, and the four quarters of FY 2025/26 add up almost exactly to the headline: 842,320,667 detected events in July to September 2025, 4,559,229,985 in October to December, 3,367,113,840 in January to March 2026, and 2,355,938,192 in April to June. That sums to 11,124,602,684, which rounds to the 11.1 billion in the announcement. The gap between the quietest quarter and the loudest is more than five times, with October to December spiking 441.27 percent before the year cooled off. None of those events is a breach; the bulletins attribute the bulk of the volume to automated attempts exploiting unpatched systems, insufficient awareness of phishing and the increasing use of AI by malicious actors.

What a billion detections actually requires

A detected threat event is the output of a chain that has to exist somewhere physically. Telemetry has to be collected on networks, exchanged between operators, correlated against known patterns, stored, and reviewed by analysts on shift. The National KE-CIRT/CC sits at the national end of that chain, and since the Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations 2024 came into force, the Authority's mandate explicitly includes establishing and operating a Cyber Security Operations Centre (CSOC) for the ICT and telecommunications sector. The 83.1 million advisories, 20,748,489 of them in the final quarter alone, are the human-readable output of all that machinery: every advisory assumed an ICT user somewhere had the connectivity to receive it and the infrastructure to act on it.

The rest of the chain looks like this: users generate traffic, carrier networks carry it, the Kenya Internet Exchange Point keeps local traffic local, data centres and cloud platforms host the services being attacked, facility teams watch their own halls, and the national team correlates what everyone sees. Kenya's version of that chain is unusually complete for the region. 89 percent of Kenyan networks are either IXP members themselves or customers of IXP members (ISOC Pulse, October 2026), which means the exchange fabric, now at 144 member networks and about 2,985 Gbps of connected capacity, is a genuine national vantage point rather than a boutique facility. Detection capacity and peering capacity are, in practice, the same investment.

Networking equipment and cabling inside a data centre
Networks are the first rung of the detection ladder: the national response team can only see what the networks and facilities feeding it are able to see

Where the detection infrastructure sits

The DC254 map answers the where question directly. Nairobi holds 19 of Kenya's 27 tracked facilities, 13 of them operational, and that cluster is where the halls, NOCs and interconnection fabric concentrate. Mombasa is the other half of the story: all four of its tracked facilities are operational, and it is the coast where 7 in-service submarine cable systems come ashore (of 10 tracked, with Africa-1 landed and still awaiting RFS, plus Daraja announced and LuLu planned). The market's published live IT load is 10.5 MW, with 8 of the 20 operational facilities publishing figures, live designed capacity stands at 42.9 MW, and the announced pipeline adds 230 MW more. Every megawatt of that build-out is also detection capacity, because the telemetry has to be collected, stored and analysed on hardware that sits in a room like anyone else's.

The equipment hall of a Nairobi data centre with rows of racks
Threat detection runs on the same ingredients as everything else in a data centre: racks, power, cooling and staffed shifts

The bulletins make the security relevance of that geography explicit. In the final quarter of FY 2025/26 the national team counted 17,406,495 web application attack attempts, a 43.68 percent increase on the quarter before, targeted at the critical information infrastructure sector, with government systems and internet service providers the primary targets. Kenya's documented breach history says the same thing from the incident side: the 2023 eCitizen DDoS degraded the gateway to more than 5,000 public services (BBC, 28 July 2023), and in July 2026 the president's own website was defaced with a Bitcoin ransom note (The Record, 21 July 2026). The attack types are the ones catalogued in our threat guide; what is growing is the volume behind them, and the critical information infrastructure rules now formally assume operators are wired into the national detection effort.

Why the number is a demand signal

Every one of those 11.1 billion events consumed something real: bandwidth on a carrier network, packets across an exchange switch, log storage on a rack, minutes of an analyst's shift. Every one of the 83.1 million advisories travelled over Kenyan networks to someone who then had to patch, reconfigure or at least read. That work cannot usefully be offshore, because response latency is a function of distance and the 2024 regulations assume the systems watching Kenya's infrastructure are reachable, accountable and themselves secure. Facilities that can demonstrate layered controls, from the network edge down to the physical layer, are the ones that win the regulated workloads, the banks and government tenants, whose telemetry the CSOC exists to watch in the first place.

That is why this statistic belongs in the infrastructure conversation rather than the fear conversation. Kenya's digital economy is adding load from AI, cloud computing, financial services and digital public platforms at the same time as the threat volume grows, and both curves land on the same racks. The 230 MW pipeline is the country building the capacity to absorb both curves at once. Read the number as a national systems-health reading: hostile traffic is rising, and so is the country's ability to see it, count it and answer it.

Cybersecurity is not separate from digital infrastructure. It is one of the reasons digital infrastructure exists. The 11.1 billion is worth knowing, but the more useful question sits behind it: what does a country need to have built, powered, connected and staffed to see that number at all? Kenya's current answer, visible on the DC254 map, is 27 tracked facilities, 20 operational, an exchange point that touches nearly every network in the country, and a pipeline that keeps growing. The threat data and the construction data are the same story told twice.

Frequently Asked Questions