Michael Kamande
PCI QSA and information security professional working across payment security, AI governance and digital transformation in African markets.

I work where consequential digital systems meet security, governance and assurance.
My primary professional focus is payment security and PCI DSS. As a Qualified Security Assessor, I assess the controls that protect cardholder data and the organisations responsible for keeping those controls effective.
My work also covers AI governance and digital transformation. I am interested in how organisations move from technology adoption to useful, controlled change: clear accountability, sound data, secure implementation and value that can be measured.
I have worked across East Africa and wider African markets, including digital financial services and mobile money environments. That experience has shaped how I read standards: globally consistent, but always applied within a real operating context.
Academic
MSc Advanced Cyber Security Management
MSc Computer Science with Cyber Security
BSc Information Technology Security
Assurance
PCI Qualified Security Assessor
GSMA Mobile Money Certification Lead Assessor
ISO/IEC 27001 Lead Auditor and Implementer
ISO/IEC 42001 Lead Auditor
ISO 9001, ISO/IEC 20000-1 and ISO 22301 Lead Auditor
Additional practice
Privacy and data protection
SOC 2 implementation
Business continuity and resilience
Digital financial services