CCTV footage has a strange reputation in Kenya right now. For years, it was treated as the gold standard of proof, the thing that finally settled arguments about who broke into a shop, who caused an accident, or what really happened during a dispute. Lately, though, a different kind of question has entered the public conversation: what happens when the footage itself cannot be trusted, either because it was never recorded properly or because someone with access to the system deleted it before anyone else could see it?

That question has taken on real weight in Kenya over the past year, partly because of an ongoing court case that has drawn national attention to exactly this issue. Without wading into the details of that case, since it remains before the courts and it would be wrong to treat contested allegations as settled fact, it is worth explaining why the underlying question — how CCTV storage can be interfered with, and what stops that from happening — matters far beyond that single case. It is a question that any Kenyan business, school, hospital, or institution relying on CCTV for security should be asking about its own system.

What the Ongoing Public Conversation Has Highlighted

Kenyans have been following an active murder trial connected to the death in police custody of Albert Ojwang, a teacher and blogger, in June 2025. As part of that trial, prosecutors and investigators from the Independent Policing Oversight Authority have presented testimony alleging that the CCTV recording system at the police station involved was interfered with in the hours after his death, including claims that a hard drive was formatted and that footage was later partially recovered through digital forensic work. It is important to be clear that this case is still ongoing, the individuals charged are entitled to a fair trial and the presumption of innocence, and the specific allegations about what happened have not yet been finally determined by the court.

What this case has done, regardless of its eventual outcome, is put a spotlight on a technical and practical question that applies well beyond any single institution: how vulnerable is a typical CCTV system to being tampered with by someone who has physical or administrative access to it, and what can actually be done to prevent that. This is a genuinely useful question for any business owner in Kenya to sit with, because the same basic vulnerability — a DVR that can be reformatted, footage that can be deleted, or a hard drive that can simply be removed — exists in a huge number of ordinary commercial CCTV setups across the country.

A Kenyan Case That Shows the Same Vulnerability in a Business Setting

The Ojwang case is not the only example of this problem playing out in Kenya, and it is worth looking at one that involved an ordinary commercial CCTV system rather than a police station. In 2018, two Kenya Commercial Bank employees at the Wundanyi branch, along with a security guard, were charged over the theft of more than Sh21 million from the branch vault. During the trial, the branch manager testified that the bank's surveillance cameras had gone dark for several hours on the day of the theft, and that footage from just before the outage showed one of the accused employees, who had access to the vault keys, disconnecting the CCTV system himself.

This case is a fairly clean illustration of the exact vulnerability described above. The system worked as intended right up until the moment someone with legitimate access decided it was inconvenient, at which point it simply stopped protecting anyone. Cases like this are also a reminder that tampering does not always mean sophisticated hacking or deleting files after the fact. Sometimes it is as simple as switching off a device that anyone on site could physically reach, which is precisely the kind of gap that off-site cloud backup and access logging are designed to close.

Why Ordinary CCTV Systems Are More Vulnerable Than People Assume

Most CCTV systems installed in Kenyan shops, offices, warehouses, and residential estates rely on a single physical recording device, usually a DVR or NVR box situated somewhere on the premises, often in a back office or store room. Footage is stored locally on a hard drive inside that device, and if the device is damaged, stolen, or deliberately tampered with, the footage is gone, sometimes permanently. This setup was reasonable when CCTV was primarily used as a casual deterrent, but it becomes a serious problem the moment that footage needs to hold up as evidence, whether in a criminal case, an insurance claim, a labour dispute, or a civil lawsuit.

The core vulnerability is straightforward. Whoever has physical or administrative access to the recording device, whether that is a business owner, a manager, an IT technician, or in some cases an employee with more access than they should have, can potentially delete, overwrite, or destroy footage if they have a reason to. This is not a hypothetical concern specific to any one type of institution. It applies to a retail shop where an employee is suspected of theft and happens to also manage the CCTV system, a landlord disputing a tenant's account of an incident, or any situation where the person with access to the footage also has an interest in what it shows.

What Tamper-Resistant Storage Actually Involves

Addressing this vulnerability does not require exotic technology, but it does require moving beyond the assumption that a single local hard drive is good enough. A few concrete measures make a meaningful difference.

Redundant cloud backup

Redundant cloud backup means footage is copied automatically to a remote server as it is recorded, rather than existing only on a local device that can be physically accessed or destroyed. Even if someone tampers with or removes the on-site DVR, a copy of the footage already exists elsewhere and cannot be altered by anyone at the physical location. This is arguably the single most effective safeguard available to ordinary businesses, since it removes the single point of failure that local-only storage represents.

Access logging and audit trails

Access logging and audit trails record every instance of someone viewing, exporting, or deleting footage, along with who did it and when. Without this kind of log, there is no way to prove after the fact whether footage was tampered with or simply never existed in the first place, which is often exactly the kind of ambiguity that becomes contested in legal proceedings. A proper audit trail turns a vague dispute over what happened into something that can actually be verified.

Restricted administrative access

Restricted administrative access limits who can delete or reformat footage in the first place. In many small businesses, one person, often a manager or the business owner, has full administrative rights over the entire system, which means there is effectively no separation between the person recording the footage and the person capable of destroying it. Splitting these responsibilities, or at minimum requiring a second authorisation for permanent deletion, closes an obvious gap.

Tamper-evident hardware and firmware

Tamper-evident hardware and firmware can flag or log unusual activity such as a device being powered off unexpectedly, a storage drive being physically removed, or settings being changed outside of normal maintenance windows. This does not prevent tampering outright, but it creates a record that tampering was attempted, which itself becomes useful evidence.

Why This Matters Beyond Criminal Cases

It is easy to assume that tamper-proof CCTV mainly matters for high-stakes criminal investigations, but the more common, everyday relevance for Kenyan businesses is in insurance claims, employment disputes, and civil liability cases. An insurer investigating a burglary claim may want to review footage from the days leading up to an incident, and gaps or inconsistencies in that footage can complicate or delay a legitimate payout. An employer defending against a wrongful dismissal claim involving alleged theft or misconduct needs footage that will actually hold up if challenged in court. A landlord or property manager facing a liability claim after an accident on their premises benefits enormously from footage that cannot later be dismissed as unreliable or incomplete.

In each of these situations, footage that cannot be verified as untampered is often treated with real scepticism, sometimes reasonably so, which can undermine an otherwise strong case even when nothing improper actually happened.

Choosing a CCTV Provider With Evidence Integrity in Mind

When evaluating CCTV providers in Kenya, it is worth asking specifically about backup arrangements, access controls, and whether the system produces any kind of audit trail, rather than focusing purely on camera resolution or the number of channels included in a package. Providers vary considerably in how seriously they take this aspect of a system, partly because cloud storage and proper access logging add cost and complexity that a purely local setup avoids.

Comparing providers on these specific points, rather than assuming all CCTV installers offer roughly the same thing, is a genuinely useful exercise. At Secuwatch, we help business owners and institutions in Kenya find and compare vetted security providers who offer this kind of tamper-resistant storage and cloud backup, which is particularly relevant for businesses that may one day need their footage to hold up under real legal or insurance scrutiny.

A Grounded Takeaway

The public conversation happening around CCTV tampering right now is a useful, if uncomfortable, prompt for any Kenyan business or institution to look honestly at its own security footage setup. A camera that records but cannot be trusted, because its footage lives on a single device that anyone with access could tamper with, offers a weaker form of protection than most owners realise. Investing in redundant backup, proper access controls, and a genuine audit trail is not about assuming the worst of your own staff or management. It is about making sure that if footage is ever needed to settle a dispute, defend a claim, or support an investigation, it can actually be trusted by everyone involved, including people who were not there.