NAIROBI, Kenya – People’s Renaissance Movement (PM Party) leader Caleb Amisi has taken issue with the government over a recent directive on domain and email security.

Addressing the press on Tuesday, September 1, 2026, at the party’s headquarters in Nairobi, Amisi linked the directive issued by the head of public service, Felix Koskei, to a major scandal within government.
“I want to inform members of the public of a looming scandal overseen by the highest office in the land. It regards a scandal worth over KSh 1.89 billion on cybersecurity maintenance,” said Amisi.
The Saboti MP claimed that he has reliable information to believe that the mystery surrounding the hacking of the State House website in July 2026 was a hoax meant to pave the way for the cybersecurity maintenance scandal.
“The government has since issued a directive to government institutions to each pay KSh 4.7 million, totalling over KSh 1.89 billion, ostensibly for maintenance of the government’s domain and email security. This is blatant theft of public money,” said the youthful MP.
July 2026 scare at State House, Kenya
According to the lawmaker, for market comparison, the ordinary rate of maintaining a domain is no more than KSh 5,000.
“We condemn this budgeted corruption in totality. Kenya needs a renaissance!” he added.
In mid-July 2026, there was a scare at State House, Kenya, that the official email of the president had been hacked, with the hackers demanding a ransom of KSh 41.3 million.
“This is an ongoing matter that is likely to have a significant financial impact on our public institutions, particularly at a time when many of them are already facing severe financial constraints,” said Amisi.
On January 13, 2025, the head of public service issued a circular to all ministries, to all departments, to all agencies, and to state corporations to deploy approved domain and email protection measures under what is called the Whole of Government Domain and Email Security Initiative.
The timeline for the circular by Felix Koskey
The circular designated the Communications Authority of Kenya (CA) as the central government entity responsible for coordinating and overseeing the initiative.
Subsequent reminders were issued on November 11, 2025. Another one was issued on January 26, 2026, and the most recent one was issued in July 2026.
Amisi states that the implementation process is currently ongoing, with public institutions being required to make payments to the Communications Authority.
“Our concern as a party is not cybersecurity. Our concern is the costs. How did we arrive at a figure of KSh 4.7 million per institution? Remember, we have more than 400 parastatals in the country, including universities and colleges. How did we arrive at the figure of KSh 4.7 million per institution? Which, if you sum up with the 400 institutions we have, adds up to around KSh 1.89 billion, approximately KSh 2 billion from the targeted institutions, given the economic difficulties facing the country and the serious financial challenges confronting many of our public institutions,” Amisi said.
The go.ke domain, according to the MP, is regulated and reserved for Kenyan government institutions.
“Yet, registration and annual maintenance of such domains are considerably cheaper than the figures currently being demanded from these institutions. Ordinarily, a .ke domain can cost as little as KSh 1,350, or say KSh 1,500, depending on the provider and the package,” the lawmaker further said.
Parastatal and state corporation CEOs under scrutiny
The PM party boss disclosed that his party recently designed a website as required by the Registrar of Political Parties.
“We did not spend more than KSh 5,000 on securing the domain. How can government spend something that is worth merely KSh 1,500? They are requiring all parastatals to spend KSh 4.7 million on a service that attracts a very small fee,” the outspoken MP said.
Governments worldwide and in Kenya enforce strict domain and email security directives to prevent spoofing, phishing, and cyberattacks against public infrastructure.
Over 100 parastatal and state corporation CEOs faced disciplinary action for failing to implement mandatory website domain and email protection measures via the Communications Authority of Kenya.
Public institutions register and manage compliance through the Domain & Email Protection Programme portal. Directives by bodies like the National Computer and Cybercrimes Coordination Committee (NC4) require critical systems to strictly utilise secure .ke domains and digital certificates.











Discussion about this post