About Kiruh
A cybersecurity consultancy built around a straightforward belief: security advice is only useful if the people receiving it can act on it.

A tight team of senior practitioners
Kiruh is a team of security practitioners with backgrounds across offensive security, incident response, cloud architecture, and compliance. We work primarily with organisations in Kenya and across East Africa — from financial services and healthcare to technology companies and government entities.
We are a smaller firm, deliberately. We keep our team tight so the person you speak to in the scoping call is the person doing the work — and reviewing the final report before it reaches you.
Most organisations have a visibility problem, not a security problem
They don’t know what they have, what’s exposed, or what a realistic attacker would target first. These four principles shape how we close that gap.
Honest by default
We report severity as it is — not inflated to justify the engagement, not softened to keep you comfortable.
Senior-led, always
The person in your scoping call is the person doing the work — and reviewing the report before it reaches you.
Practical over theoretical
Findings come with a remediation path your team can act on, in language leadership and engineers both understand.
Rooted in the region
We understand East African regulators, threat actors, and infrastructure realities — context generic testing misses.
The people behind the work
Senior consultants who lead engagements end to end. (Placeholder profiles — replace photos, names, and bios before launch.)

[Name]
[Role — e.g. Principal Security Consultant][One or two lines on their focus area and background — e.g. 10+ years in offensive security, previously at Z, leads red-team engagements.]

[Name]
[Role — e.g. Cloud Security Lead][One or two lines on their focus area and background — e.g. cloud architecture and CIS-benchmark audits across AWS, Azure, and GCP.]

[Name]
[Role — e.g. Incident Response Lead][One or two lines on their focus area and background — e.g. DFIR and threat hunting for financial-sector clients across the region.]

[Name]
[Role — e.g. GRC & Compliance Consultant][One or two lines on their focus area and background — e.g. ISO 27001 and Kenya Data Protection Act readiness for lean IT teams.]

Rooted in East Africa
We work across Kenya, Uganda, Tanzania, and Rwanda. We understand the regulatory environment — the Kenya Data Protection Act, sector requirements from the Central Bank of Kenya and the Communications Authority, and the ISO 27001 framework increasingly demanded by enterprise procurement.
We also understand the infrastructure realities: hybrid environments, constrained IT teams, and the particular threat actors targeting East African financial services and public-sector organisations.