BSI Certifies Co-operative Bank of Kenya Under ISO/IEC 27001:2022

Co-operative Bank of Kenya has earned the ISO/IEC 27001:2022 certification from BSI, signaling a renewed commitment to safeguarding customer data amid rapid digital transformation.

The certification ceremony, conducted by BSI, underscores the bank’s position as a regional leader in information security and risk management as it adopts the updated standard.

What the certification entails is a holistic, risk-based approach that reflects the realities of cloud adoption, remote work, and increasingly interconnected systems. The 2022 revision expands the focus beyond static controls to ensure the confidentiality, integrity, and availability of information across its lifecycle.

An external audit assessed critical security domains, including physical security controls, robust access management, risk assessment and treatment processes, change management, business continuity planning, and secure software development practices. The certification also confirms that Co-operative Bank’s Information Security Management System (ISMS) aligns with global best practices and regulatory expectations, reinforcing stakeholder confidence.

Leadership perspectives anchor the achievement. Charles Washika, the bank’s Director of ICT & Innovations, described the milestone as a clear demonstration of its dedication to protecting customer data.

He emphasized that the certification strengthens risk management, standardizes information security policies across the organization, and enhances incident response capabilities.

“The controls we’ve implemented ensure regulatory compliance while reinforcing the trust our customers, partners, and regulators place in Co-operative Bank,” he said.

Ilias Karampoikis, IMETA Sales and Commercial Director, highlighted the broader significance in today’s cloud-driven environment. He noted that ISO/IEC 27001 certification shows the bank has taken essential steps to defend against cyber threats and keep information security aligned with global best practices.

“This focus on digital trust is crucial amid ongoing technological transformation,” Karampoikis added.

Co-operative Bank’s security leadership is part of a longer arc in East Africa. The bank first attained ISO/IEC 27001:2013 in 2014, becoming a regional pioneer. The 2022 revision expands controls to address contemporary threats while safeguarding data confidentiality, integrity, and availability, reinforcing the bank’s role as a benchmark for information security in the region.

For customers, the certification offers reassurance that personal and financial data is processed and stored according to internationally recognized security standards, supporting secure digital banking services. Regionally, the updated standard strengthens confidence in East Africa’s financial sector and supports broader expansion plans.

Looking ahead, Co-operative Bank emphasizes continued investment in security tools, cybersecurity talent, and robust processes to address all relevant controls. The bank envisions strengthening Kenya’s digital economy and expanding its regional footprint across East Africa, with security serving as a growth driver and trust anchor.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *