65
2018

Computer Misuse and Cybercrimes

No. 5

electronic instructions as they relate to sending of
electronic debit and credit messages or confirmation of
electronic fund transfer, issues false electronic instructions,
commits an offence and is liable, on conviction, a fine not
exceeding two hundred thousand shillings or imprisonment
for a term not exceeding two years, or to both.
40. (1) A person who operates a computer system or a
computer network, whether public or private, shall
immediately inform the Committee of any attacks,
intrusions and other disruptions to the functioning of
another computer system or network within twenty four
hours of such attack, intrusion or disruption.

Reporting of
cyber threat.

(2) A report made under subsection (1) shall include—
(a) information about the breach, including a
summary of any information that the agency
knows on how the breach occurred;
(b) an estimate of the number of people affected by
the breach;
(c) an assessment of the risk of harm to the affected
individuals; and
(d) an explanation of any circumstances that would
delay or prevent the affected persons from being
informed of the breach.
(3) The Committee may propose the isolation of any
computer systems or network suspected to have been
attacked or disrupted pending the resolution of the issues.
(4) A person who contravenes the provisions of
subsection (1) commits an offence and is liable upon
conviction a fine not exceeding two hundred thousand
shillings or imprisonment for a term not exceeding two
years, or to both.
41. (1) An employee shall, subject to any contractual
agreement between the employer and the employee,
relinquish all codes and access rights to their employer's
computer network or system immediately upon termination
of employment.
(2) A person who contravenes the provision of this
subsection (1) commits an offence and shall be, liable on
conviction, to a fine not exceeding two hundred thousand

Employee
responsibility to
relinquish access
codes.

Select target paragraph3