Our Work

Case Studies

Real problems, measured outcomes — a sample of the work we have done and the results we have helped clients achieve.

100%Critical findings remediated
0Material findings at audit
3Client sectors served
4East African countries
Penetration Test Financial services penetration test
0material findings raised at regulatory audit
Financial Services · Kenya

Passing a CBK audit with zero material findings

Challenge

A mid-sized financial services company preparing for a CBK regulatory audit needed an independent assessment of its internet-facing systems and internal network before the examination window.

What we did

A two-week external and internal penetration test across web applications, VPN infrastructure, and Active Directory — scoped tightly to avoid disruption to live banking operations.

Outcome

We surfaced critical findings, including an unauthenticated API endpoint exposing customer account data. All were remediated before the audit, and the client passed with no material security findings raised.

ISO 27001 Gap Analysis NGO ISO 27001 gap analysis
93Annex A controls assessed against ISO 27001:2022
International NGO · Nairobi & Kampala

A board-approved roadmap to ISO 27001

Challenge

An international NGO was required by a major donor to demonstrate ISO 27001 alignment. With no existing ISMS, they needed to understand the gap before committing to certification.

What we did

A structured gap assessment against all ISO 27001:2022 Annex A controls, a review of existing policies and technical controls, and interviews with department heads across IT, HR, and finance.

Outcome

We delivered a gap report and a phased remediation roadmap sized for a lean IT team — which the client used to secure board budget approval for an ISMS implementation project.

Cloud Security Audit SaaS startup cloud security audit
100%critical cloud findings remediated pre-launch
Series A SaaS Startup · Health Data

Closing critical AWS gaps ahead of enterprise sales

Challenge

A SaaS startup processing health data needed to demonstrate security rigour to enterprise customers running procurement due diligence. Its AWS environment had grown quickly without a formal review.

What we did

We audited the AWS environment against CIS Benchmark Level 2, reviewed IAM roles and policies, checked S3 bucket permissions, and assessed logging and monitoring posture.

Outcome

We found high-severity misconfigurations including publicly accessible S3 buckets. All critical findings were remediated quickly, and the client shared our report with enterprise prospects as evidence of due diligence.

Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top