Defending What Matters Most.
Kiruh helps East African organisations understand their real exposure, close meaningful gaps, and build security postures that last — without the enterprise jargon.
A method that gives you answers you can act on
Our methodology is our main differentiator — a repeatable process built to surface real risk, not tick a compliance box.
Scope & Understand
We spend time understanding your environment, business context, and threat profile before touching a single tool.
Test & Assess
Structured testing across your attack surface — mapped to real-world attacker techniques, not just checklists.
Report Clearly
Plain-language findings with a risk-ranked action list. Every finding comes with a practical remediation path.
Verify & Close
We retest remediated findings and confirm closure — a clean bill of health, not a point-in-time snapshot.
Security work scoped to your actual environment
Not a one-size-fits-all package — engagements shaped around your systems, sector, and risk.
Penetration Testing
Simulated adversarial attacks on your network, applications, and cloud to find what a real attacker would exploit.
Vulnerability Assessments
Systematic identification and prioritisation of weaknesses across your full asset inventory.
Cloud Security Audits
Configuration-level reviews of AWS, Azure, and GCP environments against CIS benchmarks.
Incident Response
Rapid containment, forensic analysis, and recovery support when something has already gone wrong.
Security Awareness
Phishing simulations and practical training that turn your people into a first line of defence.
Compliance & Gap Analysis
Structured assessments against the Kenya Data Protection Act, ISO 27001, and sector requirements.
Built for East African organisations — not head-office checklists
We pair senior practitioners with genuine regional context: the regulatory landscape, the local threat actors, and the infrastructure realities on the ground. You get testing that reflects how attacks actually reach you.
Senior consultants on every engagement
Your work is done — and reviewed — by experienced practitioners, not handed to junior staff after the first call.
Sized for SMEs
Fixed-scope engagements with transparent pricing. No enterprise retainer lock-in, no billing surprises.
Regional context built in
We understand the East African regulatory environment, local threat actors, and on-the-ground infrastructure realities.