advertisement
AfricaHackon Cybersecurity Summit 2026 Held In Nairobi
Kenya’s digital infrastructure has more than 2,000 critical security holes and over 4.8 million leaked credentials sitting exposed online, findings from what is called a first-of-its-kind national threat landscape study, unveiled by Dr. Bright Gameli Mawudor, CEO of Cyber Guard Africa and founder of AfricaHackon, at the opening of the AfricaHackon Cybersecurity Summit in Nairobi on August 27.
The research was a passive scan, of email systems, firewalls, cloud servers, developer APIs, IoT devices and WiFi networks across more than 13 ASNs( autonomous system networks), the blocks of internet address space assigned to individual service providers, universities and large organisations. It was carried out jointly by Cyber Guard Africa and the AfricaHackon team. Speaking to CIO Africa about the state of the country’s cyber exposure, Mawudor put it plainly: “We are not ready.”
That finding is what the AfricaHackon Cybersecurity Summit 2026 was all about. Held from August 27 to 29 at Hackhouse Africa in Nairobi, the summit is put on by AfricaHackon, now in its second decade as one of East Africa’s longest-running practitioner-led security communities. This year’s theme, “From Skills to Securing Systems,” was aimed squarely at security analysts, CISOs, developers, policymakers and regulators, the people who have to turn individual technical skill into protection for entire organisations, not just their own machines. The premise is that threats are now moving faster than most organisations can respond to them, and that technical skill on its own is no longer enough to keep up.
advertisement
This year’s programme was built around workshops and live demonstrations.”We want to make sure there’s that real impact and we want people to actually have a feel of what they can practically take back to the organizations.”Mawudor said.
The agenda followed that logic across the three days – cyber operations and threat intelligence on day one, offensive security and AI-related risks on day two, then defence, cloud and governance on day three. Individual sessions ranged from the technical to the procedural: pentest reporting, privacy engineering, rebuilding threat intelligence with open-source tools, supporting law enforcement in cyber operations, cloud misconfigurations, third-party vendor risk, ISO 27001 governance, smart contract audits, DevSecOps failure points, free threat intelligence sharing through ShadowServer, data protection law, the security risks of AI agents and AI-driven databases, digital forensics, and a session bluntly titled “The Darkest Side of Bug Bounty.”
That “not ready” feedback isn’t an isolated case. It’s a trend the whole industry has been reporting all year. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 63 percent of organisations in sub-Saharan Africa say they lack adequate cybersecurity staff, the sharpest such shortage of any region it tracks. In Kenya specifically, the Cyber Shujaa Industry Report 2025 counted more than 45,000 unfilled cybersecurity roles, even as the Communications Authority of Kenya’s own quarterly monitoring recorded billions of cyber threat events hitting the country’s systems in the first half of this year alone, most of them attacks on infrastructure that hadn’t been properly patched.
advertisement
Finding 2,000 critical security vulnerabilities across just 13 large networks might sound shocking, until you realize there are only about 20,000 certified cyber experts in all of Africa. The severe talent shortage explains why so much infrastructure is left completely unprotected.
That gap between threat volume and available skill shows up just as sharply in how companies are governed as in how their systems are built. In the session “Get Your GRC Right: ISO 27001,” presenters Lena Ndanu, cybersecurity consultant, cyberguard and Fiona Msha, senior argued that most breaches trace back to how a company is run, not just what software it uses. As Ndanu put it: “If the leadership mechanism is wrong, the company is at risk.” Patch the servers all you like, if nobody at the top is accountable for security decisions, the underlying exposure doesn’t go away.
Mawudor connects that skills shortfall directly to how Kenyan employers hire. Job postings routinely ask for four years of experience for roles someone with six to twelve months in the field could reasonably fill, he argues, pointing out that this habit keeps out the fresh talent that industry reports say is so badly needed.
advertisement
“We need to understand exactly what role we are hiring for, what is the purpose of what they’re hiring this person for,” he said. “And how long do we need to take to be able to actually make sure that the person they’re hiring actually fills that role and solves the problem that the organisation has?”
Zooming out from Kenya, the reality across the rest of the continent is just as stark. Despite having over 220 million people, Nigeria only has about 8,352 certified cybersecurity professionals according to data compiled by CompTIA. Even South Africa, the continent’s most advanced digital economy, fields just 57,269, a fraction of the nearly 483,000 experts working in the US alone.
The International Information System Security Certification Consortium, known globally as ISC2, currently tracks the worldwide workforce shortfall at close to 4.8 million people, a shortage that hits sub-Saharan Africa disproportionately hard.
Mawudor started the organisation in 2013 after he couldn’t afford to attend DEF CON or Black Hat in the United States. “I wanted to go to Defcon and Black Hat in the US, I didn’t have the money to. So what did I do? I said let me just start Africa Hackon, so a few friends of mine, we came together,” he said.
He’s since built it around what he calls a “ripple effect,” deliberately pulling in people from outside conventional security career paths, lawyers, chefs, cleaners, face painters, policy professionals, alongside the technical crowd the field expects.
Whether any of this changes how Kenyan companies actually invest in security is a separate question, and one Mawudor closed the summit without pretending to have a clean answer to. His last words, “You have to be open to learning new things. If you’re not open to learn from somebody else, you’re never going to move anywhere.”