About Kiruh
A cybersecurity consultancy built around a straightforward belief: security advice is only useful if the people receiving it can act on it.

A tight team of senior practitioners
Kiruh is a team of security practitioners with backgrounds across offensive security, application security, cloud architecture, and compliance. We work primarily with organisations in Kenya and across East Africa — from financial services and healthcare to technology companies and government entities.
We are a smaller firm, deliberately. We keep our team tight so the person you speak to in the scoping call is the person doing the work — and reviewing the final report before it reaches you.
Most organisations have a visibility problem, not a security problem
They don’t know what they have, what’s exposed, or what a realistic attacker would target first. These four principles shape how we close that gap.
Honest by default
We report severity as it is — not inflated to justify the engagement, not softened to keep you comfortable.
Senior-led, always
The person in your scoping call is the person doing the work — and reviewing the report before it reaches you.
Practical over theoretical
Findings come with a remediation path your team can act on, in language leadership and engineers both understand.
Rooted in the region
We understand East African regulators, threat actors, and infrastructure realities — context generic testing misses.
The disciplines behind the work
As a security practice, we present our people by capability, not by name. Discretion is part of the work — for our clients and for us. Every engagement is led by a senior practitioner in the relevant discipline.
Lead Penetration Tester
Leads offensive engagements end to end — external, internal, web, and API testing that mirrors how real attackers operate.
Cloud Security Lead
Reviews and hardens AWS, Azure, and GCP environments against CIS benchmarks and real-world misconfiguration patterns.
Application Security Lead
Reviews source code, APIs, and mobile apps — SAST/DAST and threat modelling to secure the software you build and buy.
DevSecOps Lead
Builds security into CI/CD pipelines — automated gates, secrets and dependency scanning, and infrastructure-as-code review.
GRC & Compliance Lead
Guides ISO 27001 and Kenya Data Protection Act readiness in language lean teams can actually act on.

Rooted in East Africa
We work across Kenya, Uganda, Tanzania, and Rwanda. We understand the regulatory environment — the Kenya Data Protection Act, sector requirements from the Central Bank of Kenya and the Communications Authority, and the ISO 27001 framework increasingly demanded by enterprise procurement.
We also understand the infrastructure realities: hybrid environments, constrained IT teams, and the particular threat actors targeting East African financial services and public-sector organisations.