Uncategorized

[New Podcast] A Conversation on AI, Cyber Risk & Digital Trust in Kenya & East Africa with Smartcomply’s Founder & CEO Gbemisola Osunrinde

As Kenya’s digital economy has taken off, so have the risks. Between April and June 2025 alone, more than 4.5 billion cyber threat events were recorded in Kenya, and over the year the country is estimated to have lost nearly KES 29.9 Billion (US$230 Million) to cybercrime. These aren’t abstract IT problems. They are real economic shocks for businesses, consumers and public institutions.​

Against this backdrop, I sat down in Nairobi earlier this week with Gbemisola Osunrinde, CEO of Smartcomply, for a new episode of the Pure Digital Passion podcast — recorded just hours before their Secure Horizon executive breakfast at Radisson Blu and the launch of their “AI & the Cyber Frontier: Securing East Africa’s Digital Future” report with TechCabal.

This is an African-built digital trust and cybersecurity story, entering Kenya at exactly the moment when AI, cyber risk and digital trust are converging at scale.

From hardware engineering to building an African cyber platform

Gbemisola’s journey into cybersecurity didn’t start in a boardroom — it started in the trenches. She began on the hardware engineering side at Inlux Computers, fixing servers, deploying antivirus software and keeping infrastructure running. That’s where she realized that information security was much bigger than boxes and cables; it was also about software, policy and human behaviour.​

A master’s degree in cybersecurity and management opened the floodgates. Consulting for big banks in Nigeria and beyond exposed her to the messy reality of cyber risk: gaps in controls, fragmented processes, and organizations that only really paid attention after something went wrong.​

One pivotal moment came at Main One in Nigeria. There, she lived through the pain of manual, spreadsheet-driven compliance — endless documents, scattered ownership, and the scramble every time auditors came calling. That experience became the seed for what would become SmartComply: instead of treating compliance as a once-a-year fire drill, why not automate the entire workflow and build real-time visibility into risk?​

It’s a classic founder story: see the problem up close, get tired of the pain, then build the product you wish you’d had.

What SmartComply actually does (Simply put)

One of my favourite parts of the conversation was forcing us to strip away jargon and explain SmartComply like you would to a non-technical board.

As Gbemisola put it, SmartComply is an automated, AI-powered digital trust and cybersecurity platform designed with African realities in mind. Under that umbrella, there are a few key building blocks:​

  • SecureSE (GRC) — The governance, risk and compliance backbone, where organizations manage controls, map risks, assign tasks, store evidence and give executives a real-time view of where they stand. No more “Where is that spreadsheet?” moments.​
  • SmartGuard — Endpoint protection that plugs into the same picture, so device-level risk and policy-level risk live in one view.​
  • Adhere — An anti-fraud and AML/KYC engine built for Africa’s financial realities. It monitors behaviour, flags anomalies and stops suspicious transactions before money leaves the account — critical in markets where fraud and social engineering have become rampant.
  • Oculus — A threat intelligence and dark web monitoring layer that tracks brand abuse, leaked credentials and malicious activity, and can even trigger takedown services when sensitive content appears online.​
  • Academy — A talent engine that trains and pipelines the next generation of cybersecurity and fraud analysts, not just for SmartComply but for clients across the continent.​

In other words, this is not “just” another tool. It’s an ecosystem that tries to cover policy, people, devices, fraud and intelligence in one integrated way.

Why an African-built platform matters

We spent some time on a question I hear a lot from African founders: “Is our homegrown solution good enough versus a big-name vendor from North America or Europe?”

Gbemisola’s answer was clear. Most global platforms were architected for European or US regulatory regimes and threat patterns. They can be powerful, but they aren’t tuned to things like:​

  • The speed and scale of mobile money, where in Kenya transactions now represent over 53% of GDP.​
  • The specific fraud patterns hitting African fintechs — SIM swaps, social engineering, and fast-moving insider threats.
  • The regulatory patchwork across African markets and the “manual compliance” culture many organisations still operate in.​

That’s why SmartComply deliberately bakes African scenarios into its code and data models — from detection rules for local fraud schemes to workflows that reflect how compliance is actually done in banks, fintechs and telcos across the continent.​

Of course, building in Africa comes with its own hurdle: credibility. Early on, they had to run proof-of-concept deployments with all features unlocked, then sit with customers through real-world pilots until results started to speak louder than the logo on the box. As users saw value and asked for more features to be switched on, SmartComply built trust the slow way — through outcomes, not brochures.​

Why Nairobi, why now?

So why choose Nairobi as a hub for East Africa — and why now?

Kenya is one of Africa’s most digitally integrated economies. It sits in Tier 1 on the ITU Global Cybersecurity Index, alongside Ghana, Rwanda, Tanzania, Egypt and Morocco, reflecting years of regulatory work and ecosystem building. At the same time, our digital exposure is massive: Kenya accounts for 68% of East Africa’s total attack surface, with more than 200,000 exposed systems.​

Between April and June 2025, Kenya recorded over 4.5 billion cyber threat events, and in a later period (July–September 2025), over 842 million threats were detected in just three months, driven largely by automated system attacks. The result? An estimated KES 29.9 billion (US$230M) lost to cybercrime in 2025, with mobile banking fraud alone rising by 87% in the most recent period.​

In short: we’re advanced, but exposed.

For SmartComply, that combination is exactly the point. Nairobi is the Silicon Savannah where fintechs, banks, telcos, regulators and startups are all pushing digital innovation. The question now is whether we can match that innovation with embedded security and digital trust, by design.

AI has changed the game — for attackers and defenders

A big chunk of our conversation, and of the AI & the Cyber Frontier report, sits on one uncomfortable truth: AI has structurally changed the economics of cyber risk.

On the offensive side, global research shows that around 60% of organizations believe they’ve already been targeted by AI-enabled attacks, yet only 7% have successfully deployed AI-driven defences. In East Africa, you see this in:​

  • A 27% document fraud rejection rate — bots hammering identity verification APIs at scale.​
  • A sharp rise in deepfake-driven fraud attempts, with Tanzania seeing a 317% surge in high-fidelity impersonation attacks during the last review period.​
  • Attackers shifting from “breaking in” to “logging in”, using stolen or spoofed identities to operate inside systems as if they were legitimate users.

Gbemisola shared a chilling example from their work: a CEO “voice note” that sounded exactly like the real thing — intonation, style, wording — authorising a large cross-border transfer. The invoice looked right, signatories checked out, the bank account matched the known vendor name. The only clue? A tiny dot inserted into an email address. The transaction was only stopped because of a final, human phone call.​

This is where AI meets the human trust layer.

On the defensive side, SmartComply is embedding AI into its own stack — from anomaly detection in transactions, to pattern recognition in threat intelligence — but always with a human-in-the-loop to verify what the machines are flagging. As Gbemisola put it, you need both automation and human judgement: one for scale, the other for context.​

The “execution gap”: awareness without readiness

One of the most important ideas in the report — and in our conversation — is what the authors call the “execution gap.”

Here’s the paradox:

  • 74% of organizations in East Africa now rank cyber risk as a top strategic concern, versus a global average of 57%.​
  • Yet only 29% of those organizations actually conduct regular tabletop exercises to simulate real incidents and rehearse their response.​

On paper, we care a lot. In practice, we mostly haven’t rehearsed what failure looks like.

The report also notes that even where budgets are rising, most spending remains compliance-driven rather than risk-driven. Many organizations still treat cybersecurity and privacy as separate track activities run for regulators, rather than an integrated, operational discipline designed to protect trust in real time.​

Gbemisola and I talked about what this looks like in the Kenyan context:

  • Incidents that only get reported when regulators or media are watching.
  • Policies that exist on paper, but fall apart under pressure because ownership and escalation paths aren’t clear.
  • Boardrooms that see cyber as an IT cost centre, not a core business and trust risk.

Her message to Kenyan CEOs and boards was blunt: don’t make cybersecurity a checkbox; make it a culture. And if you’re afraid of AI and haven’t started using it in your defenses, you’re handing the advantage to attackers who already have.​

Culture, boards and the human firewall

If there’s a phrase that stuck with me from this episode, it’s “human firewall.”

SmartComply’s academy isn’t an add-on; it’s a recognition that Africa faces the highest global shortage of AI and cybersecurity talent, with 82% of organisations on the continent reporting challenges in these skills. You can’t automate your way out of that deficit. You have to train people.​

Their approach is twofold:

  • Train and certify new entrants — especially young Africans — to build a pipeline of analysts, engineers, investigators and compliance specialists.
  • Help organizations embed security-by-design, policy-by-design and compliance-by-design into products and processes, so the human firewall is backed by solid systems.​

As we discussed, cyber is no longer just technical. There’s space for coders, policy thinkers, compliance professionals, risk analysts, product people — the whole spectrum. For young professionals across Nairobi and Lagos who are “cyber curious” but unsure where to start, Gbemisola’s advice was simple: start with broad foundations, then specialize in the track — technical, coding or policy — that fits you best.​

So, what should Kenyan leaders do in the next 90 days?

I closed the episode by asking Gbemisola for one concrete action Kenyan CEOs, boards and regulators should take in the next 90 days to materially improve cyber resilience.

Her answer:

  • Stop treating cybersecurity as an IT problem; treat it as a board problem.
  • Stop treating it as a checkbox; make it a culture.
  • Adopt AI in your defenses, because AI is already in play on the attacker side.
  • Bake security, policy and compliance by design into every new product, process or integration, rather than retrofitting controls after the fact.

If we can do that — while leveraging African-built platforms like SmartComply, grounded in our own realities — we stand a much better chance of turning digital growth into durable digital trust.

Listen to the full conversation

We covered a lot more in the episode: SmartComply’s customer stories, the Secure Horizon conversations with Kenyan regulators and C-suites, and what success in East Africa could look like in the next 2–3 years if we get this right.

You can listen to the full Pure Digital Passion episode with Gbemisola Osunrinde here:

If you’re a CEO, CISO, regulator, fintech founder — or a young professional looking to build a career in cyber — this one is worth your time.

Previous post

As An Investor Or Startup, Why Missing Sankalp Africa Summit 2026 Could Be Your Biggest Mistake This Year

Next post

Unpacking Smartcomply's & TechCabal's AI & the Cyber Frontier 2026 Report: Kenya's & East Africa's 4.5B Threat Surge & the Execution Gap Crisis

No Comment

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.