Who We Are

About Kiruh

A cybersecurity consultancy built around a straightforward belief: security advice is only useful if the people receiving it can act on it.

The Kiruh team at work
Who We Are

A tight team of senior practitioners

Kiruh is a team of security practitioners with backgrounds across offensive security, incident response, cloud architecture, and compliance. We work primarily with organisations in Kenya and across East Africa — from financial services and healthcare to technology companies and government entities.

We are a smaller firm, deliberately. We keep our team tight so the person you speak to in the scoping call is the person doing the work — and reviewing the final report before it reaches you.

10+Years average experience
12+Industry certifications held
4East African countries
100%Senior-led delivery
How We Think

Most organisations have a visibility problem, not a security problem

They don’t know what they have, what’s exposed, or what a realistic attacker would target first. These four principles shape how we close that gap.

Honest by default

We report severity as it is — not inflated to justify the engagement, not softened to keep you comfortable.

Senior-led, always

The person in your scoping call is the person doing the work — and reviewing the report before it reaches you.

Practical over theoretical

Findings come with a remediation path your team can act on, in language leadership and engineers both understand.

Rooted in the region

We understand East African regulators, threat actors, and infrastructure realities — context generic testing misses.

Our Team

The people behind the work

Senior consultants who lead engagements end to end. (Placeholder profiles — replace photos, names, and bios before launch.)

Team member

[Name]

[Role — e.g. Principal Security Consultant]

[One or two lines on their focus area and background — e.g. 10+ years in offensive security, previously at Z, leads red-team engagements.]

OSCPCREST10+ yrs
Team member

[Name]

[Role — e.g. Cloud Security Lead]

[One or two lines on their focus area and background — e.g. cloud architecture and CIS-benchmark audits across AWS, Azure, and GCP.]

CISSPAWS Security8+ yrs
Team member

[Name]

[Role — e.g. Incident Response Lead]

[One or two lines on their focus area and background — e.g. DFIR and threat hunting for financial-sector clients across the region.]

GCIHGCFA9+ yrs
Team member

[Name]

[Role — e.g. GRC & Compliance Consultant]

[One or two lines on their focus area and background — e.g. ISO 27001 and Kenya Data Protection Act readiness for lean IT teams.]

ISO 27001 LACIPP7+ yrs
East Africa regional focus
Regional Focus

Rooted in East Africa

We work across Kenya, Uganda, Tanzania, and Rwanda. We understand the regulatory environment — the Kenya Data Protection Act, sector requirements from the Central Bank of Kenya and the Communications Authority, and the ISO 27001 framework increasingly demanded by enterprise procurement.

We also understand the infrastructure realities: hybrid environments, constrained IT teams, and the particular threat actors targeting East African financial services and public-sector organisations.

KenyaUgandaTanzaniaRwanda
Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top