Who We Are

About Kiruh

A cybersecurity consultancy built around a straightforward belief: security advice is only useful if the people receiving it can act on it.

The Kiruh team at work
Who We Are

A tight team of senior practitioners

Kiruh is a team of security practitioners with backgrounds across offensive security, application security, cloud architecture, and compliance. We work primarily with organisations in Kenya and across East Africa — from financial services and healthcare to technology companies and government entities.

We are a smaller firm, deliberately. We keep our team tight so the person you speak to in the scoping call is the person doing the work — and reviewing the final report before it reaches you.

10+Years average experience
12+Industry certifications held
4East African countries
100%Senior-led delivery
How We Think

Most organisations have a visibility problem, not a security problem

They don’t know what they have, what’s exposed, or what a realistic attacker would target first. These four principles shape how we close that gap.

Honest by default

We report severity as it is — not inflated to justify the engagement, not softened to keep you comfortable.

Senior-led, always

The person in your scoping call is the person doing the work — and reviewing the report before it reaches you.

Practical over theoretical

Findings come with a remediation path your team can act on, in language leadership and engineers both understand.

Rooted in the region

We understand East African regulators, threat actors, and infrastructure realities — context generic testing misses.

Our Team

The disciplines behind the work

As a security practice, we present our people by capability, not by name. Discretion is part of the work — for our clients and for us. Every engagement is led by a senior practitioner in the relevant discipline.

Lead Penetration Tester

Leads offensive engagements end to end — external, internal, web, and API testing that mirrors how real attackers operate.

Cloud Security Lead

Reviews and hardens AWS, Azure, and GCP environments against CIS benchmarks and real-world misconfiguration patterns.

Application Security Lead

Reviews source code, APIs, and mobile apps — SAST/DAST and threat modelling to secure the software you build and buy.

DevSecOps Lead

Builds security into CI/CD pipelines — automated gates, secrets and dependency scanning, and infrastructure-as-code review.

GRC & Compliance Lead

Guides ISO 27001 and Kenya Data Protection Act readiness in language lean teams can actually act on.

East Africa regional focus
Regional Focus

Rooted in East Africa

We work across Kenya, Uganda, Tanzania, and Rwanda. We understand the regulatory environment — the Kenya Data Protection Act, sector requirements from the Central Bank of Kenya and the Communications Authority, and the ISO 27001 framework increasingly demanded by enterprise procurement.

We also understand the infrastructure realities: hybrid environments, constrained IT teams, and the particular threat actors targeting East African financial services and public-sector organisations.

KenyaUgandaTanzaniaRwanda
Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top