Solutions / Cybersecurity and risk advisory
Know how an attacker would get in, and close that route first
Most breaches of small and mid-sized businesses use ordinary weaknesses: a reused password, an unpatched laptop, an invoice email nobody questioned. We find those weaknesses in your business and fix them in order of risk.
What goes wrong
Security spending often goes to products while the simple gaps stay open. A firewall does not help when the finance manager's email has no second login step.
Directors are usually the last to know how exposed the business is, because nobody has measured it in terms they can act on.
What it costs the business
Under the Data Protection Act 2019, a breach of personal data must be reported to the Data Protection Commissioner within 72 hours, and penalties can reach KES 5 million or 1% of annual turnover, whichever is lower.
The larger cost is usually operational: days without systems, a diverted supplier payment, or a client who asks for your security evidence and does not get it.
What we do
Security assessment
We test your controls the way an attacker would and report findings ranked by business impact, not by technical severity alone.
Vulnerability management
Regular scanning and patching with a monthly report a director can read in five minutes.
Security governance
Policies, a risk register and evidence that match what your regulator or clients ask for.
Staff awareness training
Short sessions for staff on phishing and payment fraud, using the kinds of message your business receives.
Monitoring and response
Alerting on the systems we manage for you, and a rehearsed plan for the day something does get through.
Prefer to talk it through?
A 30-minute call with Denis to describe the problem and hear how we would approach it. If we are not the right fit, we will say so.