Cybersecurity Services in Kenya
We test, harden and monitor the systems Kenyan businesses run on: penetration testing, vulnerability assessment, endpoint and network security, incident response, and the controls the Data Protection Act actually asks for. CloudSpinx is an infrastructure and security consultancy in Kenya, and almost every engagement starts with an assessment, because you cannot price a fix before you know the shape of the problem.
Who we build for
- 14organizations, from ISPs and payment platforms to a national regulator
- 6flagship engagements published in full, with the numbers counted
- 4thof all contributors to the open-source payment switch national systems run on
Everything in Our Cybersecurity Service
Every engagement covers the full scope: no hidden extras, no upselling.
Security assessment and gap analysis
External and internal scanning, configuration review, identity attack surface, and a prioritized remediation list with the risk rating and the effort next to each item.
Penetration testing
Network and web application testing against the OWASP Top 10, with proof of exploitation rather than a scanner dump, and a retest after you have fixed things.
Endpoint detection and response
CrowdStrike or Microsoft Defender for Endpoint deployed properly: policy tuned to your estate, rollback tested, and alerts going somewhere a human reads them.
Network and firewall security
Next-generation firewall policy, segmentation that actually contains a compromise, IDS and IPS tuning, and remote access that is not a flat VPN into everything.
Identity and access hardening
MFA everywhere it matters, Conditional Access, privileged access tiers, service account cleanup and the removal of the shared logins every estate turns out to have.
SOC and SIEM monitoring
Log aggregation and correlation with Wazuh or Splunk, detections tuned to your environment, and alerts triaged by an engineer instead of forwarded to your inbox.
Incident response
Containment, forensic preservation, recovery and a written post-incident report. We work the incident with you rather than sending a bill and a checklist.
Data Protection Act compliance
ODPC registration, data mapping, retention and consent policy, breach procedure with the 72-hour clock built in, and the evidence pack an auditor asks for.
Security awareness training
Phishing simulation and role-specific training for finance, HR and executives, who are the ones actually targeted, not a generic annual slide deck.
Technologies we use
What a security engagement costs, and why we assess first
We do not publish a rate card for security work, and the reason is not coyness. A penetration test on one web application and a full review of a multi-site estate with Active Directory, a payments integration and a compliance deadline are different orders of work. Almost every engagement therefore starts with a scoped assessment, because that is the only honest way to price a remediation.
What drives the number
The count of external addresses and applications in scope, whether testing is black box or credentialed, endpoint and user count, how many sites we visit, whether you need monitoring afterwards or only the report, and whether the output has to satisfy a specific standard or a client questionnaire. Compliance-driven work costs more than the same technical work without it, because the evidence pack is a deliverable in its own right.
The assessment is useful even if you stop there
You get a prioritized list with risk ratings and remediation effort, and it is yours to hand to anyone. Plenty of clients fix the top items with their own team and come back a year later for the retest. That is a good outcome. A security report that is only actionable by the firm that wrote it is a sales document, not an assessment.
The Kenya Data Protection Act, in practical terms
The Data Protection Act 2019 is the compliance obligation most Kenyan businesses actually have, and most of the ones we assess are not meeting it. Registration with the Office of the Data Protection Commissioner is required of controllers and processors above the prescribed thresholds, before processing begins rather than after. A personal data breach has to be reported to the Data Commissioner within 72 hours of you becoming aware of it, a processor has 48 hours to tell its controller, and affected people have to be told without undue delay where the risk to them is high. Administrative penalties reach KES 5 million, with criminal exposure beyond that.
- The 72-hour clock starts at awareness, not at certainty. If you wait until the investigation is complete you have already missed it, so the breach procedure has to be written before you need it.
- You cannot report what you cannot see. Without central logging, "we became aware" is whenever a customer tells you, which is usually months. This is the practical argument for monitoring, more than any threat statistic.
- Data mapping is the unglamorous prerequisite. Which systems hold personal data, whose, on what lawful basis, for how long, and who it is shared with. Everything else in the Act depends on this and it is the step people skip.
- Processors carry their own duties. If you handle personal data on behalf of other businesses, the obligations attach to you directly rather than only to your client.
- Cross-border transfer has conditions. Where your data physically sits is a compliance question and not only an architecture one, which is why it comes up in every hosting conversation we have.
What actually happens to Kenyan businesses
The attacks we get called about are not sophisticated. They are the same handful, repeatedly, and each has a boring control that would have stopped it.
Business email compromise
Someone spoofs a director or compromises a mailbox, watches the conversation for a few weeks, then sends revised bank details for a real invoice at exactly the right moment. It is the most expensive thing that happens to businesses here and the cheapest to defend against: SPF, DKIM and DMARC set to reject rather than to monitor, MFA on every mailbox, and a payment process where changed bank details are verified on a phone call to a number you already had. We fix the mail authentication as part of email and collaboration work, and we check it on every assessment.
Ransomware through remote access
The entry point is almost always Remote Desktop exposed to the internet, a VPN account with no MFA, or a firewall running firmware from four years ago. Then it spreads because the estate is flat and every user is a local administrator. Backups get encrypted too, because they were on a share the compromised account could reach. Segmentation, MFA on remote access, and an offline or immutable backup copy are the three controls that decide whether this is an incident or a catastrophe. Whether you are trading again the next morning is a disaster recovery question rather than a security one, and the two get planned together.
Mobile money and payment integration abuse
Where M-Pesa or a payment API is wired into an internal system, the weak point is usually the credentials and the callback endpoint rather than the payment platform. API keys in a shared spreadsheet, a callback URL with no signature verification, and no reconciliation alerting until month end. This needs the application and the infrastructure reviewed together, which is why we ask what is integrated before we scope.
Monitoring, and being honest about what it is
Continuous monitoring is worth having and it is also the thing most often oversold. A SIEM does not detect threats on its own. It collects logs and matches rules, and it is only as good as the sources feeding it and the tuning behind it. An untuned deployment produces hundreds of alerts a day, everybody stops reading them within a fortnight, and you now have an expensive false sense of safety. We would rather start with fewer log sources and detections that are tuned to your estate, then add scope as the noise stays manageable. If you cannot resource anyone to act on alerts, say so up front and we will design for that instead of pretending.
When we tell clients not to buy security work
The fastest way to waste a security budget is to buy the wrong layer first.
- Do not buy a penetration test if you already know the findings. If the estate is unpatched, has no MFA and has flat networking, a test will tell you that at a cost. Fix the known items first and test afterwards, when the result is actually information.
- Do not buy a SIEM before you have backups you have restored from. Detection is worth less than recovery. We have seen organizations with a monitoring subscription and no tested restore, and that ordering is backwards.
- Do not buy tooling to satisfy a questionnaire. If a client tender is driving this, the honest path is a gap analysis against what they asked for, then the smallest set of controls that genuinely closes it. Buying a platform because it is on a list is expensive and it does not make you safer.
- Under about ten staff with everything in a hosted suite, you probably need MFA, managed devices, a tested backup and half a day of training rather than a security program. We will do that and stop.
What you get, and what you own
The assessment report with an evidence appendix, the prioritized remediation plan with effort against each item, the policy documents in editable form, the breach procedure, and any tooling configured in tenants you own rather than in ours. If you take monitoring, the detection rules and the log pipeline are documented so another provider could take them over. Security work that leaves you dependent on the assessor has a conflict of interest built into it, which is the opposite of what you were buying. Ongoing operation of the controls runs through our managed support if you want it, and through your own team if you do not.
Tell us what needs testing
Enough for us to scope honestly and come back with a real figure. Every field has an escape hatch, and nothing here needs a security background to answer.
Ready to discuss Cybersecurity?
A 30-minute scoping call, free, and it commits you to nothing.
How Every Cybersecurity Engagement Starts
Scope and assess
Agree what is in scope and what is off limits, then test it. External and internal, identity, endpoints and the applications that matter, with rules of engagement in writing.
Report and prioritize
Findings with evidence, risk ratings and the effort each fix takes, ordered so the first week of work removes the most exposure. Written for your board as well as your engineers.
Remediate
We fix it, your team fixes it, or we split the list. Either way the plan names an owner and a date per item rather than leaving a PDF on a shared drive.
Retest and monitor
A retest that confirms the findings are actually closed, then continuous monitoring if you want it, with detections tuned to the estate we just mapped.