August 2, 2026 · Education · 5 min read
We open with a clear aim: to map the current landscape and offer an actionable analysis that leaders can use now. Our article blends major report findings with field observations to give a practical view for decision makers.
Recent data shows rising threat levels and talent shortfalls. For example, a major report notes many financial institutions see cybercrime as a top risk, and skills gaps add real exposure. We focus on what this means for resilience and growth.

We explain how mobile money growth and wider digital footprints increase both risk and opportunity. By centering a skills-first approach, leaders can align governance, budgets, and capability-building to reduce risk and support innovation.
We see the present mix of fast-growing attacks and thin talent pools forcing banks to rethink how they protect customers and platforms. New channels and mobile-first services expand reach, but they also open fresh threat paths that demand faster detection and clear ownership.

Kenya recorded 2.5 billion cyber threats in Q1 2025, a 202% quarter-on-quarter rise. That spike shows how quickly exposure can escalate for banks operating in a connected digital economy.
The BCG/GCF report notes a 2.8 million global shortfall and roughly 68,000 roles missing regionally. Fewer than 300,000 pros work in the field across the continent, creating a clear gap leaders must address.
In south africa and nigeria, skilled tech professionals face intense demand from fintechs and global firms. That competition raises hiring costs and stretches time-to-fill for critical roles.
Surveys show many employees lack basic security awareness. Limited staff training amplifies risk for institutions, making simple controls and continuous learning urgent priorities.
Operational strain is widening as legacy systems and manual controls bump against modern threat vectors. We draw on regulator and industry data to show how this affects day-to-day resilience.

The Central Bank of Kenya survey shows patchy rollout of 2017 standards. Many banks still run manual monitoring and miss real-time visibility.
Budgets range from Sh19 million to Sh600 million, yet hiring remains hard. With roughly 1,700–2,000 pros versus a 40,000–50,000 need, the shortage cybersecurity creates an execution gap.
BCG/GCF data finds 60% of leaders flag AI as a major threat vector. Human failures cause about 77% of attacks, so tech must pair with strengthened processes.
| Area | Current State | Action |
|---|---|---|
| Monitoring | Manual tools, delayed alerts | Invest in real-time telemetry |
| People | Severe talent gap | Targeted hiring and partnerships |
| Governance | Uneven standards adoption | Board-level reporting and tests |
| AI Risk | Adversary automation rise | Harden playbooks and detection |
We turn strategy into action by focusing on practical steps that scale talent and raise control effectiveness. The approach blends hiring, education, and tech so banks can reduce risk while supporting digital growth.

Hire for skills, not just titles. Define role-specific tests and certification pathways that prove hands-on ability. That shortens time-to-fill and raises quality.
We recommend government-industry-academia partnerships to keep training current and credentialed. Align curricula to real systems, risk scenarios, and measurable competencies.
Make inclusion actionable. Boost outreach, mentorship, and flexible routes to help women and diverse professionals enter and grow in security roles.
South Africa and Kenya offer models where apprentices convert theory into practice through rotations and supervised tasks. Track competencies and link apprentices to hiring panels.
Use responsible AI to automate triage and routine response. This frees professionals to investigate complex incidents and improves time-to-detect and time-to-respond.
Align standards with AU frameworks like Malabo and bring board-level reporting into the loop. Strong governance raises investor confidence and cross-border resilience.
Matsh delivers practical professional and youth development training across the GCC, Africa, Asia and internationally.
Closing the gap requires steady investments in people, controls, and governance that match today’s fast-moving threat landscape. We must fund small pilots, measure results, and scale what works so leaders can act now.
Our review of reports and country data shows the challenge is real: a workforce shortage, rising threats, and gaps in basic standards. Customers benefit when institutions link training, automation, and clear board oversight to reduce operational risk.
We encourage cross-market collaboration — from South Africa to Kenya — so lessons convert into practice. For more on regional trust and inclusion, see the security and trust report.
If we align tech, talent, and governance today, we can shrink the gap, retain professionals, and build a more trusted future for the sector.
We run all our courses as private programmes for organisations across the GCC and Africa.
Request In-House →