Kenya has launched a new manual meant to help police officers and prosecutors handle cybercrime cases from the moment they are reported until they reach court.
The Rapid Reference Guide on the Investigation and Prosecution of Offenses under the Computer Misuse and Cybercrimes Act was unveiled on September 3, 2026.
It is the product of a joint effort between the National Computer and Cybercrimes Coordination Committee (NC4), the Office of the Director of Public Prosecutions (ODPP), and the National Police Service (NPS).
Communications Authority of Kenya Director General David Mugonyi attended the launch alongside other stakeholders from the criminal justice sector.
Why the Guide Exists
Cybercrime in Kenya has grown more complex and harder to pin down. Criminals now hide behind borders, switch tactics quickly, and increasingly move stolen money into virtual assets like cryptocurrency to avoid detection.
According to the guide’s authors, digital security threats cost the country roughly KES 29 billion a year.
A nationwide cyber-exposure check that fed into the launch found more than 2,000 critical security vulnerabilities and over 4.8 million leaked credentials across Kenyan systems, a sign of how exposed public and private institutions have become.
Interior Principal Secretary Raymond Omollo, who chairs the NC4, said the guide is meant to be used, not just read. He described it as a practical tool for strengthening investigations, supporting prosecutions, and keeping Kenya’s cyberspace secure.
He also pointed to mobile money fraud as one of the fastest-changing threats, since stolen funds can be shifted into virtual assets almost instantly, making them harder to trace and recover.
What’s Inside the Guide?
The guide runs 140 pages and covers 76 distinct cyber offenses under the Computer Misuse and Cybercrimes Act, Cap 79C. For each offense, it breaks down the legal elements a prosecutor must prove and the type of evidence investigators need to collect.
The offenses range from unauthorized access to computer systems and cyber espionage to phishing, cyberstalking, identity theft, computer forgery, and child sexual abuse material.
It also includes sample criminal charges, templates for court applications such as search and seizure warrants, production orders, and orders for real-time collection of data, plus guidance on preserving digital evidence so it holds up in court.
A separate chapter addresses international cooperation, since cybercrime cases often involve evidence or suspects located outside Kenya.
Where the CA Fits In
The guide sets out clear roles for the different agencies involved in fighting cybercrime. The Communications Authority of Kenya is named as the principal regulator overseeing telecommunications, broadcasting, electronic transactions, and the country’s numbering and frequency resources.
It also houses the National Kenya Computer Incident Response Team Coordination Center (National KE-CIRT/CC), which acts as the country’s operational contact point for cybersecurity incidents.
For investigators, the CA acts as the link between law enforcement and telecom operators, mobile network providers, domain registries, and international tech platforms, helping police obtain subscriber details, call records, and IP address logs needed to build a case.
The launch comes as Kenya moves toward joining the Budapest Convention on Cybercrime, the first binding international treaty on computer-related crime, which aims to align cybercrime laws across countries and improve cross-border cooperation on investigations.
By giving investigators and prosecutors a shared reference point, the guide is designed to reduce inconsistency between how different officers handle cybercrime cases, and to help Kenya turn digital evidence, wherever it originates, into cases strong enough to survive scrutiny in court.


























