Main Article Content
Empirical Study of Cyber Incident Management Systems in Higher Education Institutions (HEIs) in Kenya
Abstract
Kenyan universities are increasingly integrating digital technologies into their academic and administrative operations. However, this digital transformation has exposed institutions to escalating cybersecurity threats, including data breaches, ransomware attacks, and unauthorized access to critical information. This study evaluates the effectiveness of existing cybersecurity measures and incident management systems in Kenyan universities, aiming to identify key vulnerabilities and areas for improvement. A structured survey was conducted among IT personnel from four major Kenyan universities, gathering data on cybersecurity preparedness, existing frameworks, and incident response strategies. The sampling process ensured proportional representation across public and private universities, considering factors such as infrastructure and regional diversity. Additionally, this group was vital for the research as they possess first-hand experience and knowledge about the existing cybersecurity infrastructure, threat detection capabilities, and incident response mechanisms within their respective institutions. The study utilized descriptive statistical analysis, correlation analysis, and regression modelling to assess the effectiveness of cybersecurity frameworks such as NIST Cybersecurity Framework, MITRE ATT&CK, and the Cyber Kill Chain Framework in the university context. The findings indicate that although universities have implemented basic cybersecurity measures such as firewall protections and access controls, there are significant gaps in real-time threat detection, incident response preparedness, and cybersecurity training programs. Many institutions lack dedicated cybersecurity teams, and incident response mechanisms are largely reactive rather than proactive. Additionally, limited financial and technical resources hinder effective implementation of cybersecurity policies. This paper highlights critical deficiencies in cybersecurity frameworks currently in use and emphasizes the need for real-time monitoring systems, improved staff training, and the adoption of automated threat detection tools. The study recommends a multi-stakeholder approach involving universities, government agencies, and cybersecurity experts to enhance resilience against evolving cyber threats. Addressing these gaps will allow Kenyan universities to strengthen their cybersecurity posture, protect academic assets, and safeguard the privacy of students, staff and faculty members.


