Key Takeaways

  • Weekly cyberattack volumes increased 4% month on month, indicating growing pressure on enterprise networks.
  • Kenya has recorded volatile threat activity, including 4.6 billion threats during October to December 2025.
  • Weak patching, phishing exposure and criminal use of AI are increasing pressure on security teams.

The latest findings from the threat intelligence arm of Check Point Software Technologies Ltd add another warning signal for businesses already contending with ransomware, phishing and attacks against unpatched systems. Weekly attack volumes rose 4% month on month, indicating that the underlying pressure on enterprise networks continues to build rather than settle.

For Kenyan organisations, that increase lands against a particularly difficult backdrop. National KE-CIRT/CC data published through the Communications Authority of Kenya showed cyber threats rising 146% year on year to 8.6 billion in the year to June 2025, up from 3.5 billion. System vulnerabilities were the dominant vector, placing patch management and asset visibility near the centre of the country’s security challenge.

The quarterly numbers have been even more volatile. The Communications Authority of Kenya’s 2025-26 Q3 Cyber Security Report followed a period in which detected threats jumped to about 4.6 billion during October to December 2025. That represented a 441% increase from 842 million in the preceding quarter. Weak patching, limited phishing awareness and greater criminal use of AI were identified as contributing factors.

Those figures should be interpreted carefully. Threat detections and attempted attacks are not the same as successful breaches, and one automated campaign can produce an enormous number of events. Still, the direction matters. High volumes consume monitoring capacity, produce alert fatigue and make genuinely dangerous activity harder to distinguish from routine internet noise.

Ransomware operators do not need every intrusion to succeed; a single exposed account, forgotten server or convincing phishing message can provide the foothold they need. Global reporting from ENISA and ransomware advisories from CISA during 2024 and 2025 documented rising ransomware activity and greater use of double extortion, where criminals encrypt systems while also threatening to publish stolen information.

Africa’s expanding digital economy presents an attractive target. INTERPOL’s African Cyberthreat Assessment identifies Kenya as a regional cybercrime hotspot, citing increases in phishing, mobile money fraud and ransomware. More than 46,000 distributed denial-of-service attacks targeted telecommunications operators during the first half of 2025. For banks, telecoms and public agencies, disruption can quickly extend beyond IT into payments, customer access and essential services.

What should security leaders do when attack counts are measured in billions? A practical response starts with reducing preventable exposure. Risk-based patching can prioritise internet-facing systems, identity infrastructure and vulnerabilities known to be actively exploited. Multifactor authentication, tested offline backups, network segmentation and rehearsed incident-response procedures can help limit the effect of a compromised account or endpoint.

Email remains another obvious pressure point. Wider use of DMARC can reduce domain impersonation, while targeted phishing exercises can help employees recognise messages shaped by generative AI. Zero-trust patterns described in NIST SP 800-207 can also support tighter access decisions, particularly for remote users, contractors and cloud workloads. The approach is less about buying one product and more about repeatedly verifying identity, device posture and access context.

Check Point Software Technologies Ltd, Palo Alto Networks and regional managed security service providers are expanding managed detection and response and ransomware-containment offerings for Kenyan banks, telecommunications operators and government agencies. That said, outsourced monitoring works better when organisations retain clear ownership of assets, escalation paths and recovery decisions. Alignment with NIST Cybersecurity Framework 2.0, 2024 and ISO/IEC 27001:2022 can provide a structured route from threat data to governance, investment priorities and measurable operational improvements. The latest 4% rise is modest beside Kenya’s quarterly spikes, but it reinforces the same message: exposure is persistent, and disciplined security operations increasingly shape business resilience.