Infrastructure engineering for East Africa's operators, platforms and regulators See the work →
CloudSpinx · Cybersecurity

Cybersecurity Services in Kenya

We test, harden and monitor the systems Kenyan businesses run on: penetration testing, vulnerability assessment, endpoint and network security, incident response, and the controls the Data Protection Act actually asks for. CloudSpinx is an infrastructure and security consultancy in Kenya, and almost every engagement starts with an assessment, because you cannot price a fix before you know the shape of the problem.

Free 30-min consultation No lock-in contracts Local on-site engineers

Who we build for

  • 14organizations, from ISPs and payment platforms to a national regulator
  • 6flagship engagements published in full, with the numbers counted
  • 4thof all contributors to the open-source payment switch national systems run on
See the engineering record →
Certified engineers 24/7 support
72 hrs To report a breach in Kenya
KES 5M Maximum ODPC penalty
< 1hr Incident response target
What's Included

Everything in Our Cybersecurity Service

Every engagement covers the full scope: no hidden extras, no upselling.

Security assessment and gap analysis

External and internal scanning, configuration review, identity attack surface, and a prioritized remediation list with the risk rating and the effort next to each item.

Penetration testing

Network and web application testing against the OWASP Top 10, with proof of exploitation rather than a scanner dump, and a retest after you have fixed things.

Endpoint detection and response

CrowdStrike or Microsoft Defender for Endpoint deployed properly: policy tuned to your estate, rollback tested, and alerts going somewhere a human reads them.

Network and firewall security

Next-generation firewall policy, segmentation that actually contains a compromise, IDS and IPS tuning, and remote access that is not a flat VPN into everything.

Identity and access hardening

MFA everywhere it matters, Conditional Access, privileged access tiers, service account cleanup and the removal of the shared logins every estate turns out to have.

SOC and SIEM monitoring

Log aggregation and correlation with Wazuh or Splunk, detections tuned to your environment, and alerts triaged by an engineer instead of forwarded to your inbox.

Incident response

Containment, forensic preservation, recovery and a written post-incident report. We work the incident with you rather than sending a bill and a checklist.

Data Protection Act compliance

ODPC registration, data mapping, retention and consent policy, breach procedure with the 72-hour clock built in, and the evidence pack an auditor asks for.

Security awareness training

Phishing simulation and role-specific training for finance, HR and executives, who are the ones actually targeted, not a generic annual slide deck.

Technologies we use

CrowdStrikeMicrosoft Defender for EndpointMicrosoft Entra IDFortinetPalo AltoCiscoWazuhSplunkNessusMetasploitKali LinuxBurp SuiteOWASP ZAPWiresharkDMARCVeeam

What a security engagement costs, and why we assess first

We do not publish a rate card for security work, and the reason is not coyness. A penetration test on one web application and a full review of a multi-site estate with Active Directory, a payments integration and a compliance deadline are different orders of work. Almost every engagement therefore starts with a scoped assessment, because that is the only honest way to price a remediation.

What drives the number

The count of external addresses and applications in scope, whether testing is black box or credentialed, endpoint and user count, how many sites we visit, whether you need monitoring afterwards or only the report, and whether the output has to satisfy a specific standard or a client questionnaire. Compliance-driven work costs more than the same technical work without it, because the evidence pack is a deliverable in its own right.

The assessment is useful even if you stop there

You get a prioritized list with risk ratings and remediation effort, and it is yours to hand to anyone. Plenty of clients fix the top items with their own team and come back a year later for the retest. That is a good outcome. A security report that is only actionable by the firm that wrote it is a sales document, not an assessment.

The Kenya Data Protection Act, in practical terms

The Data Protection Act 2019 is the compliance obligation most Kenyan businesses actually have, and most of the ones we assess are not meeting it. Registration with the Office of the Data Protection Commissioner is required of controllers and processors above the prescribed thresholds, before processing begins rather than after. A personal data breach has to be reported to the Data Commissioner within 72 hours of you becoming aware of it, a processor has 48 hours to tell its controller, and affected people have to be told without undue delay where the risk to them is high. Administrative penalties reach KES 5 million, with criminal exposure beyond that.

  • The 72-hour clock starts at awareness, not at certainty. If you wait until the investigation is complete you have already missed it, so the breach procedure has to be written before you need it.
  • You cannot report what you cannot see. Without central logging, "we became aware" is whenever a customer tells you, which is usually months. This is the practical argument for monitoring, more than any threat statistic.
  • Data mapping is the unglamorous prerequisite. Which systems hold personal data, whose, on what lawful basis, for how long, and who it is shared with. Everything else in the Act depends on this and it is the step people skip.
  • Processors carry their own duties. If you handle personal data on behalf of other businesses, the obligations attach to you directly rather than only to your client.
  • Cross-border transfer has conditions. Where your data physically sits is a compliance question and not only an architecture one, which is why it comes up in every hosting conversation we have.

What actually happens to Kenyan businesses

The attacks we get called about are not sophisticated. They are the same handful, repeatedly, and each has a boring control that would have stopped it.

Business email compromise

Someone spoofs a director or compromises a mailbox, watches the conversation for a few weeks, then sends revised bank details for a real invoice at exactly the right moment. It is the most expensive thing that happens to businesses here and the cheapest to defend against: SPF, DKIM and DMARC set to reject rather than to monitor, MFA on every mailbox, and a payment process where changed bank details are verified on a phone call to a number you already had. We fix the mail authentication as part of email and collaboration work, and we check it on every assessment.

Ransomware through remote access

The entry point is almost always Remote Desktop exposed to the internet, a VPN account with no MFA, or a firewall running firmware from four years ago. Then it spreads because the estate is flat and every user is a local administrator. Backups get encrypted too, because they were on a share the compromised account could reach. Segmentation, MFA on remote access, and an offline or immutable backup copy are the three controls that decide whether this is an incident or a catastrophe. Whether you are trading again the next morning is a disaster recovery question rather than a security one, and the two get planned together.

Mobile money and payment integration abuse

Where M-Pesa or a payment API is wired into an internal system, the weak point is usually the credentials and the callback endpoint rather than the payment platform. API keys in a shared spreadsheet, a callback URL with no signature verification, and no reconciliation alerting until month end. This needs the application and the infrastructure reviewed together, which is why we ask what is integrated before we scope.

Monitoring, and being honest about what it is

Continuous monitoring is worth having and it is also the thing most often oversold. A SIEM does not detect threats on its own. It collects logs and matches rules, and it is only as good as the sources feeding it and the tuning behind it. An untuned deployment produces hundreds of alerts a day, everybody stops reading them within a fortnight, and you now have an expensive false sense of safety. We would rather start with fewer log sources and detections that are tuned to your estate, then add scope as the noise stays manageable. If you cannot resource anyone to act on alerts, say so up front and we will design for that instead of pretending.

When we tell clients not to buy security work

The fastest way to waste a security budget is to buy the wrong layer first.

  • Do not buy a penetration test if you already know the findings. If the estate is unpatched, has no MFA and has flat networking, a test will tell you that at a cost. Fix the known items first and test afterwards, when the result is actually information.
  • Do not buy a SIEM before you have backups you have restored from. Detection is worth less than recovery. We have seen organizations with a monitoring subscription and no tested restore, and that ordering is backwards.
  • Do not buy tooling to satisfy a questionnaire. If a client tender is driving this, the honest path is a gap analysis against what they asked for, then the smallest set of controls that genuinely closes it. Buying a platform because it is on a list is expensive and it does not make you safer.
  • Under about ten staff with everything in a hosted suite, you probably need MFA, managed devices, a tested backup and half a day of training rather than a security program. We will do that and stop.

What you get, and what you own

The assessment report with an evidence appendix, the prioritized remediation plan with effort against each item, the policy documents in editable form, the breach procedure, and any tooling configured in tenants you own rather than in ours. If you take monitoring, the detection rules and the log pipeline are documented so another provider could take them over. Security work that leaves you dependent on the assessor has a conflict of interest built into it, which is the opposite of what you were buying. Ongoing operation of the controls runs through our managed support if you want it, and through your own team if you do not.

Scope a Security Review

Tell us what needs testing

Enough for us to scope honestly and come back with a real figure. Every field has an escape hatch, and nothing here needs a security background to answer.

Free, and it commits you to nothing. If you are dealing with an active incident, WhatsApp us instead of waiting on email.

Next step

Ready to discuss Cybersecurity?

A 30-minute scoping call, free, and it commits you to nothing.

Our Process

How Every Cybersecurity Engagement Starts

01

Scope and assess

Agree what is in scope and what is off limits, then test it. External and internal, identity, endpoints and the applications that matter, with rules of engagement in writing.

02

Report and prioritize

Findings with evidence, risk ratings and the effort each fix takes, ordered so the first week of work removes the most exposure. Written for your board as well as your engineers.

03

Remediate

We fix it, your team fixes it, or we split the list. Either way the plan names an owner and a date per item rather than leaving a PDF on a shared drive.

04

Retest and monitor

A retest that confirms the findings are actually closed, then continuous monitoring if you want it, with detections tuned to the estate we just mapped.

FAQ

Common Questions

How much does a security assessment cost in Kenya?
It depends on scope: the number of external addresses and applications tested, whether testing is credentialed, endpoint and user count, the number of sites, and whether the output has to satisfy a specific standard or client questionnaire. We scope it before quoting rather than publishing a rate, because a single web application and a multi-site estate with a payments integration are not the same job. Send the shape of your environment through the form and you get a scope and one figure.
What does the Kenya Data Protection Act require of my business?
Registration with the Office of the Data Protection Commissioner if you are a controller or processor above the prescribed thresholds, and that has to happen before you start processing. A lawful basis for the personal data you hold, retention limits, and the ability to respond to data subject requests. A breach must be reported to the Data Commissioner within 72 hours of you becoming aware, with a processor notifying its controller within 48 hours. Administrative penalties reach KES 5 million.
We had a breach. What do you do first?
Contain, then preserve, then recover, in that order. Containment isolates the affected systems without destroying the evidence you will need, which is why pulling everything off the network and rebuilding immediately is usually the wrong first move. We preserve logs and images, work out the entry point and the blast radius, then recover from a known-good backup. The written report follows, and it is what supports your 72-hour notification.
Do small businesses in Kenya really get attacked?
Yes, and mostly not deliberately. Ransomware and credential attacks are automated and indiscriminate, so the question is whether you are exposed rather than whether you are interesting. Business email compromise, on the other hand, is targeted, and it disproportionately hits small and mid-sized businesses because the payment approval process runs through two or three people who trust each other.
What is the difference between a vulnerability scan and a penetration test?
A scan enumerates known weaknesses from a signature database and produces a long list, much of it noise. A penetration test tries to exploit them, chains findings together and tells you what an attacker could actually reach. Scans are cheap and useful on a schedule; tests are the ones you commission before a launch, after a major change, or when a client asks for evidence. Anyone selling you a scanner report as a penetration test is overcharging you.
Can you help us get ISO 27001 certified?
We can do the technical work and the gap analysis, build the control evidence and prepare you for audit. The certification itself is issued by an accredited certification body, not by us, and any consultant who implies otherwise is misleading you. In practice most Kenyan organizations asking for ISO 27001 are responding to a client questionnaire, and it is worth checking whether the client actually requires certification or just the controls.
Do we need a SOC, or is that overkill?
It depends on whether anyone can act on what it produces. Monitoring is valuable when there is a person or a rota that responds to an alert at 02:00 and an estate documented well enough to understand the alert. Without those, a SIEM subscription buys you log storage and a false sense of safety. Backups you have restored from, MFA and patching come first, and we will say so even though monitoring is the recurring revenue.
How do you protect against business email compromise?
SPF, DKIM and DMARC configured to reject rather than merely to monitor, which is where most Kenyan domains stop. MFA on every mailbox with no exceptions for executives, who are the actual targets. Alerting on mailbox forwarding rules, which is how the attacker stays invisible. Then the non-technical control that stops the loss: any change to payment details is verified by calling a number you already held, never a number in the email.
Will testing disrupt our production systems?
Scanning and most testing is safe, but denial-of-service testing and some exploitation is not, so the rules of engagement name exactly what is in scope, what is excluded and what the stop conditions are, signed before anything starts. Where a system is too fragile to test safely, that is itself a finding worth writing down. We schedule intrusive work outside business hours and keep a contact on call throughout.
What do we get at the end?
The report with evidence, the prioritized remediation plan with effort per item, policy documents in editable form, and a breach procedure. Tooling is configured in your own tenants. If you take monitoring, the detection rules and log pipeline are documented well enough for another provider to take them over. You should never be locked in by the firm that assessed you.
WhatsApp