Our Services
Every engagement follows the same core process — understand the context, test methodically, report clearly, verify closure.
Security work scoped to your actual environment
From offensive testing to compliance readiness — senior-led, fixed-scope engagements shaped around your systems and sector.
Penetration Testing
We simulate the techniques a motivated external or internal attacker would use against your systems — scoped by surface: network, web application, mobile, API, or physical. You receive a plain-language report with risk-ranked findings, proof-of-concept evidence, and a remediation guide your team can act on without a security background.

Vulnerability Assessments
A structured scan-and-validate cycle across your full asset inventory — breadth over depth, giving you a complete risk inventory to prioritise and track over time.

Cloud Security Audits
Configuration-level reviews of AWS, Azure, and GCP against CIS benchmarks — IAM, storage, network exposure, logging, and encryption.

SOC / Managed Security
Continuous visibility without building an internal team — threat monitoring, alert triage, and escalation, with direct access to the analyst handling your alerts.

Security Awareness Training
Practical, scenario-based training — staff learn to recognise real threats relevant to their role, not sit through compliance slide decks. In-person or online.

Incident Response
When something goes wrong, the first hours matter most. A senior practitioner on the phone within hours — not a ticket queue — to contain, investigate, and recover.

Compliance & Gap Analysis
Know exactly where you stand against the Kenya Data Protection Act, ISO 27001, or sector requirements — with a prioritised roadmap to close the gaps.
Fixed scope. Clear deliverables. No surprises.
No open-ended retainers, no billing by the hour with no ceiling. You get a clear estimate before any commitment.
Scoping Call
A short conversation to understand your environment, objectives, and constraints — no obligation.
Fixed Proposal
A written proposal with defined scope, deliverables, timeline, and a fixed price.
Delivery
Senior-led execution with clear communication throughout — no black boxes.
Retest & Close
We verify remediation and confirm closure, so fixes are proven — not assumed.
Common questions
Most focused assessments run one to three weeks from kick-off to final report, depending on scope. We agree the timeline in the proposal before you commit, and we hold to it.
Kiruh is deliberately sized for SMEs. Our engagements are fixed-scope and priced transparently — you get senior-consultant delivery without an enterprise budget or a long-term retainer lock-in.
We scope every engagement to avoid operational impact, agree rules of engagement up front, and can test in windows that suit you. Where risk exists, we flag it before we begin.
Yes. Verifying that remediation actually closed a finding is part of our process, not an upsell. You get a clean bill of health, not a point-in-time snapshot.
Yes — we work day to day with the Kenya Data Protection Act, ISO 27001, and the requirements of regulators across East Africa, and we map findings to the standards that matter to your sector.