Sector · factories and manufacturers

The question here is downtime, not paperwork.

Manufacturing is not named in the Third Schedule, so your data-protection overlay is lighter than a hospital's or a hotel's, and we are not going to pretend otherwise to sell you something. The reason to look at this is simpler: a plant that cannot schedule, track or invoice has stopped, and the way in is usually an email.

Registration
Turns on size, not sector — see below
Primary risk
Downtime and business continuity
National context
KE-CIRT: 4.56bn threat events, Q4 2025
Snapshot
Free · one to two business days

01 The legal position

We would rather write this paragraph accurately and lose the sale than tell a factory owner the regulator is coming for them. It probably is not. Something else might.

Manufacturing is not one of the Third Schedule sectors, so registration with the ODPC is not automatic for you the way it is for a hospital or a guest house. What decides it is size: a business is exempt only if its annual turnover is below KES 5,000,000 and it has fewer than ten employees. Both, not either. Most plants fail that test on the employee count alone and are required to register like anybody else.

What you do not carry is a second sector-specific statute on top. There is no manufacturing equivalent of the Digital Health Act. If somebody tells you a factory faces the same regulatory exposure as a hospital, they are selling you fear rather than reading the Schedule.

You do still hold personal data — staff records, payroll, customer contacts, CCTV — and the Act's duties attach to it: security safeguards, audit trails, regularly reviewing and testing your software for weaknesses, and notification of a breach within 72 hours. An infringement can cost up to KES 5,000,000 or 1% of annual turnover, whichever is lower, per infringement.

02 The real driver

What those numbers are not: a forecast about your plant. They describe national volume. We quote them because they are sourced, and we will not dress them up as a prediction about you.

Background: what a stranger can already see about your business.

Ransomware does not care what you make

It encrypts the systems that schedule your production, track your inventory and issue your invoices, and then the plant stops. The cost is not the ransom, which you should not pay. It is the days of lost output, the orders you miss, the penalty clauses in your supply contracts, and the customers who go elsewhere while you rebuild.

For scale: KE-CIRT, Kenya's national cyber response team, detected 4.56 billion cyber threat events in the fourth quarter of 2025 — a 441% rise on the previous quarter — and 3.37 billion in the first quarter of 2026. Serianu puts Kenyan cybercrime losses at about USD 230 million, roughly KES 29.9 billion, across 2024 and 2025. Those are counts published by the national response team and by a Kenyan research firm; they are not our estimates and not projections.

03 The way in

Almost always mundane, and almost always through the office

  • A convincing email to finance or procurement

    Appearing to come from a supplier, or from you. Whether it can be sent convincingly in your name depends on three public settings on your domain — SPF, DKIM and DMARC — and they are readable by anyone, you included.

  • An account that outlived the person

    Credentials from a staff member who left, or reused on a site that was breached, still valid on something that faces the internet.

  • Something exposed that nobody meant to expose

    An old management interface, a supplier's remote-access box, a staging system whose hostname was published in a certificate log years ago and never taken down.

  • A domain that quietly lapses

    Registration expiry and transfer locks are public record. A domain that moves or expires without your knowing takes your website and your email with it — and with them your ability to invoice.

04 Where to start

Honest qualification: reading DNS means asking whichever name servers answer for your domain, which may be yours or your provider's. That single lookup is the only contact a free snapshot involves.

Start with what is already visible from outside the fence

The free snapshot reads public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. Nothing goes near your plant network, your control systems or your ERP.

A person reads what those records show, ranks the three issues that matter most, and writes it for a managing director rather than an engineer. It arrives by email in one to two business days, and it says plainly what we could not see — which for a factory is most of the interesting part, because the machines are behind the fence and we are deliberately outside it.

If continuity is your real concern, the snapshot is a starting point rather than an answer. It tells you what a stranger can reach and impersonate today. What it cannot tell you is whether your backups restore, and that question is worth asking your IT provider this week regardless of whether you ever talk to us.

The fixes that follow are fixed price and published. Ongoing managed cover for a plant is quoted after a scoping conversation, with no figure published here, because what it costs depends entirely on how many sites, systems and staff identities are actually in scope.

One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.

See what your plant looks like from outside

One domain, read from public records, written up by a person and emailed to you in one to two business days. Free, and nothing connects to your systems.

See what our plant looks like from outside Read a sample report first