What We Do

Our Services

Every engagement follows the same core process — understand the context, test methodically, report clearly, verify closure.

Capabilities

Security work scoped to your actual environment

From offensive testing to compliance readiness — senior-led, fixed-scope engagements shaped around your systems and sector.

Vulnerability assessments

Vulnerability Assessments

A structured scan-and-validate cycle across your full asset inventory — breadth over depth, giving you a complete risk inventory to prioritise and track over time.

Asset inventorySeverity register
Cloud security audits

Cloud Security Audits

Configuration-level reviews of AWS, Azure, and GCP against CIS benchmarks — IAM, storage, network exposure, logging, and encryption.

CIS scorecardIAM risk summary
SOC / managed security

SOC / Managed Security

Continuous visibility without building an internal team — threat monitoring, alert triage, and escalation, with direct access to the analyst handling your alerts.

Threat-intel briefingTriaged tickets
Security awareness training

Security Awareness Training

Practical, scenario-based training — staff learn to recognise real threats relevant to their role, not sit through compliance slide decks. In-person or online.

Phishing simulationCompletion tracking
Incident response

Incident Response

When something goes wrong, the first hours matter most. A senior practitioner on the phone within hours — not a ticket queue — to contain, investigate, and recover.

Scope assessmentRoot-cause analysis
Compliance and gap analysis

Compliance & Gap Analysis

Know exactly where you stand against the Kenya Data Protection Act, ISO 27001, or sector requirements — with a prioritised roadmap to close the gaps.

Control-by-controlBoard-ready summary
Engagement Model

Fixed scope. Clear deliverables. No surprises.

No open-ended retainers, no billing by the hour with no ceiling. You get a clear estimate before any commitment.

STEP 01

Scoping Call

A short conversation to understand your environment, objectives, and constraints — no obligation.

STEP 02

Fixed Proposal

A written proposal with defined scope, deliverables, timeline, and a fixed price.

STEP 03

Delivery

Senior-led execution with clear communication throughout — no black boxes.

STEP 04

Retest & Close

We verify remediation and confirm closure, so fixes are proven — not assumed.

FAQ

Common questions

Most focused assessments run one to three weeks from kick-off to final report, depending on scope. We agree the timeline in the proposal before you commit, and we hold to it.

Kiruh is deliberately sized for SMEs. Our engagements are fixed-scope and priced transparently — you get senior-consultant delivery without an enterprise budget or a long-term retainer lock-in.

We scope every engagement to avoid operational impact, agree rules of engagement up front, and can test in windows that suit you. Where risk exists, we flag it before we begin.

Yes. Verifying that remediation actually closed a finding is part of our process, not an upsell. You get a clean bill of health, not a point-in-time snapshot.

Yes — we work day to day with the Kenya Data Protection Act, ISO 27001, and the requirements of regulators across East Africa, and we map findings to the standards that matter to your sector.

Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top