What We Do

Our Services

Every engagement follows the same core process — understand the context, test methodically, report clearly, verify closure.

Capabilities

Security work scoped to your actual environment

From offensive testing to compliance readiness — senior-led, fixed-scope engagements shaped around your systems and sector.

Testing & Operations

Hands-on technical services that find and reduce real risk across your systems.

Vulnerability assessments

Vulnerability Assessments

A structured scan-and-validate cycle across your full asset inventory — breadth over depth, giving you a complete risk inventory to prioritise and track over time.

Asset inventorySeverity register
Cloud security audits

Cloud Security Audits

Configuration-level reviews of AWS, Azure, and GCP against CIS benchmarks — IAM, storage, network exposure, logging, and encryption.

CIS scorecardIAM risk summary
SOC / managed security

SOC / Managed Security

Continuous visibility without building an internal team — threat monitoring, alert triage, and escalation, with direct access to the analyst handling your alerts.

Threat-intel briefingTriaged tickets
Security awareness training

Security Awareness Training

Practical, scenario-based training — staff learn to recognise real threats relevant to their role, not sit through compliance slide decks. In-person or online.

Phishing simulationCompletion tracking
Application security testing

Application Security

Secure the software you build and buy — source-code review, SAST/DAST, API and mobile testing, and threat modelling that finds the flaws before attackers do.

Code & API reviewThreat modelling
DevSecOps pipeline security

DevSecOps

Build security into your pipeline, not around it — CI/CD hardening, automated security gates, secrets and dependency scanning, and infrastructure-as-code review.

Pipeline hardeningShift-left automation

Advisory & Assessments

Strategic guidance to measure where you stand and plan what comes next.

Compliance and gap analysis

Compliance & Gap Analysis

Know exactly where you stand against the Kenya Data Protection Act, ISO 27001, or sector requirements — with a prioritised roadmap to close the gaps.

Control-by-controlBoard-ready summary
Security maturity assessment

Security Maturity Assessment

Measure your security programme against a recognised framework — NIST CSF, ISO 27001, or C2M2 — and get a prioritised, board-ready roadmap from where you are to where you need to be.

Framework benchmarkMaturity roadmap
Cloud maturity assessment

Cloud Maturity Assessment

Evaluate how well your cloud adoption balances security, cost, and resilience across AWS, Azure, and GCP — a structured review with a staged plan to level up your architecture and governance.

Well-Architected reviewStaged roadmap
Engagement Model

Fixed scope. Clear deliverables. No surprises.

No open-ended retainers, no billing by the hour with no ceiling. You get a clear estimate before any commitment.

STEP 01

Scoping Call

A short conversation to understand your environment, objectives, and constraints — no obligation.

STEP 02

Fixed Proposal

A written proposal with defined scope, deliverables, timeline, and a fixed price.

STEP 03

Delivery

Senior-led execution with clear communication throughout — no black boxes.

STEP 04

Retest & Close

We verify remediation and confirm closure, so fixes are proven — not assumed.

FAQ

Common questions

Most focused assessments run one to three weeks from kick-off to final report, depending on scope. We agree the timeline in the proposal before you commit, and we hold to it.

Kiruh is deliberately sized for SMEs. Our engagements are fixed-scope and priced transparently — you get senior-consultant delivery without an enterprise budget or a long-term retainer lock-in.

We scope every engagement to avoid operational impact, agree rules of engagement up front, and can test in windows that suit you. Where risk exists, we flag it before we begin.

Yes. Verifying that remediation actually closed a finding is part of our process, not an upsell. You get a clean bill of health, not a point-in-time snapshot.

Yes — we work day to day with the Kenya Data Protection Act, ISO 27001, and the requirements of regulators across East Africa, and we map findings to the standards that matter to your sector.

Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top