Skip to content

DDoS Defence • SOC & SIEM • Zero Trust • Incident Response

CyberSecurity

We learned security where it is hardest to fake: inside carrier networks, where a routing mistake is a national outage and the management plane is the crown jewel. That discipline — visibility first, containment by design, response as a rehearsed procedure — is what we bring to every enterprise estate.

Security is not a product. It is an engineering discipline.

01 — Approach

Security From the Operator Side

Most security consultancies arrive from the audit side: frameworks first, controls as checkboxes, and a report that describes the network without ever having run one. We arrived from the other direction. We secured satellite-upstream core networks at InterSAT serving ISPs across Africa and the Middle East, deployed carrier DPI (Allot SG Sigma) and DDoS-class defences in the region’s leading data-network operator, and delivered full security hardening across core, backhaul, and distribution in the DSI carrier-network overhaul in the DRC — VLAN segmentation, management-plane isolation, and clean AfriNIC prefix origination included.

That history changes how we practise. We treat visibility as the first control — you cannot defend flows you cannot see. We treat segmentation and identity as architecture, not products to be bolted on. And we treat response as an operational skill that decays without drills, the same way NOC failover discipline decays without testing. Formal grounding runs from Cisco CCNA and CyberOps through Radware (DDoS) and Allot certification to current ISO 27001 and Kenya Data Protection Act practice.

The seven practice areas below are how we engage. Each stands alone; together they cover the estate from the internet edge to the audit binder — and each links deeper into our domain catalogue where you want the full capability list.

02 — What We Deliver

Security Practice Areas

Seven disciplines, one posture — from packet-level defence at the edge to the governance evidence your regulator wants.

01
Radware-TrainedBGP DiversionCarrier-Scale

DDoS Protection & Mitigation

Terabit-era defence, engineered by people who ran the pipes.

DDoS defence is a routing and capacity problem before it is a security product — which is why it belongs to engineers who have operated BGP at carrier scale. We are Radware-trained and have defended operator infrastructure where the attack traffic and the revenue traffic share the same interfaces. We design layered mitigation: upstream and exchange-level filtering, BGP-signalled diversion into scrubbing (on-premises or cloud), and application-layer defence for the services that volumetric filters cannot see. Carpet-bombing across whole prefixes, IoT-botnet floods, and DNS amplification each get their own playbook, because they fail differently.

  • Attack-surface and dependency mapping: which prefixes, services, and upstreams actually carry the business
  • Volumetric mitigation architecture — RTBH, Flowspec, and BGP diversion into scrubbing centres
  • On-premises vs cloud scrubbing trade-offs engineered on latency, cost, and sovereignty — not vendor slides
  • Application-layer (L7) defence: HTTP floods, Slowloris-class attacks, API abuse, and bot management
  • Anycast and DNS resilience so the control plane survives what the data plane is absorbing
  • Upstream and IXP coordination — mitigation clauses and traffic engineering negotiated in carrier language
  • Detection tuned for carpet-bombing across /24s and /16s, not just per-destination thresholds
  • Attack post-mortems with packet-level forensics and a hardening list that gets executed

Attacks become an operational event with a procedure — not an outage with a press statement.

02
Microsoft SentinelDetection-as-CodeNOC Discipline

SOC, SIEM & Detection Engineering

Detection quality is won in the telemetry plumbing.

A SOC is a data-engineering problem wearing a security badge. NetFlow, RADIUS, firewall, endpoint, and cloud logs arrive in different formats at different rates — and the unglamorous normalization work is where detection quality is won or lost. We build SOCs from the telemetry up: decide what to collect, enrich, and drop before it hits a per-GB licence; write use cases against the threats the business actually faces; and wire alert-to-ticket automation with the deduplication discipline we learned running NOCs, so a real incident produces one actionable ticket instead of four hundred.

  • SIEM architecture and deployment — Microsoft Sentinel, Wazuh, and ELK-based stacks sized to real ingest
  • Security data pipelines: collection, normalization, enrichment, and tiered retention that controls licence spend
  • Detection engineering: use cases mapped to MITRE ATT&CK, tuned against your environment, versioned like code
  • UEBA and correlation rules that link failed logins, odd flows, and privilege changes into one story
  • Alert triage workflows, escalation paths, and SOC runbooks modelled on carrier NOC operations
  • SOC metrics that matter: detection coverage, time-to-triage, false-positive rates — reported monthly
  • In-house vs managed vs hybrid SOC models costed honestly for African enterprise realities
  • Telecom-specific telemetry: NetFlow/IPFIX, RADIUS accounting, and DPI feeds folded into detection

A SOC that turns alerts into action — with telemetry engineered as a product, not hoarded as a cost.

03
Digital FootprintLeak MonitoringThreat Profiling

OSINT & Threat Intelligence

Know what attackers know about you — before they use it.

Every breach begins with reconnaissance, and most organisations have never looked at themselves the way an attacker does. We run structured open-source-intelligence assessments: the credentials already leaked, the subdomains and management interfaces exposed, the staff profiles that make spear-phishing trivial, the supplier whose compromise becomes yours. Then we operationalise it — continuous monitoring, threat-actor profiling relevant to your sector and region, and intelligence feeds wired into the SOC so early warning becomes early action rather than another unread report.

  • Digital-footprint assessment: domains, subdomains, exposed services, and shadow infrastructure
  • Credential-leak and dark-web monitoring for corporate identities and brand abuse
  • Executive and VIP threat profiling — what a targeted attacker assembles in an afternoon
  • Phishing-domain and look-alike detection with takedown coordination
  • Third-party and supply-chain exposure discovery before contracts are signed
  • Sector- and region-specific threat-actor tracking: the TTPs actually used against African finance, telecom, and government
  • Intelligence integration: IoC feeds, enrichment, and hunting hypotheses delivered into the SIEM

The reconnaissance phase of the next attack happens with you watching — not six months before you find out.

04
Risk-RankedNetwork & WebRemediation-First

Vulnerability & Offensive Security

Find the doors before someone walks through them.

Scanning tells you what is theoretically weak; testing tells you what actually breaks. We run both as a programme, not an annual event: continuous vulnerability management with risk-based prioritisation, and penetration testing scoped against the systems where compromise costs real money — the billing stack, the payment integration, the management plane, the Active Directory that everything trusts. Because we build and run these systems ourselves, our findings come with remediation engineering, not just severity scores: the patch plan, the compensating control, the segmentation change that closes the class of bug rather than the instance.

  • Vulnerability management programmes: scanning cadence, asset coverage, and risk-based prioritisation
  • Network and infrastructure penetration testing — external, internal, and management-plane
  • Web application and API testing against OWASP Top 10 and business-logic abuse
  • Active Directory and identity-attack-path assessment: the routes from one phished user to domain admin
  • Wireless, VoIP, and telecom-specific testing — SIP abuse, toll fraud, and RF-side exposure
  • Configuration and hardening reviews against CIS benchmarks for network gear, servers, and cloud
  • Attack-surface management: continuous discovery of what the internet can see of you
  • Remediation engineering and retest cycles — findings closed, not filed

A shrinking, measured attack surface — and proof, because we tried the doors ourselves.

05
Zero TrustEntra ID & PAMSegmentation

Zero-Trust Architecture & IAM

Segmentation and identity as architecture — not aspiration.

Zero trust is what carrier engineers always did for the management plane, generalised to the whole estate: authenticate everything, segment by default, and assume the flat network is already lost. We designed VLAN segmentation and management-plane isolation across core, backhaul, and distribution for a national ISP in the DRC; the same thinking scales down to a 200-seat enterprise and up to a bank. Identity is the new perimeter, so we engineer it like one: conditional access, privileged-access management, and the admin-tiering that stops one phished helpdesk account from becoming domain-wide compromise.

  • Zero-trust roadmaps sequenced from current reality — not a rip-and-replace fantasy
  • Network segmentation and microsegmentation: VLANs, VRFs, and policy engines matched to how traffic actually flows
  • Management-plane isolation for network gear, hypervisors, and out-of-band access — carrier practice applied to enterprise
  • Identity architecture on Entra ID and hybrid AD: conditional access, MFA everywhere, and device compliance
  • Privileged Access Management: admin tiering, just-in-time elevation, and session recording for the accounts that matter
  • Service-account and secrets governance — the credentials nobody owns until they leak
  • Secure remote access: ZTNA patterns replacing the flat VPN, with satellite and low-bandwidth sites accounted for
  • East-west inspection and lateral-movement containment design

A breach in one segment stays in one segment — and identity stops being the easiest way in.

06
IR PlaybooksTabletop DrillsEvidence-Grade

Incident Response & Forensics

The 3 a.m. procedure, written and rehearsed before you need it.

The cost of an incident is decided by the quality of the response, and response quality is decided long before the incident. We write IR plans that people can execute under adrenaline — decision trees, containment options with their blast radii pre-computed, communication templates for the board, the regulator, and the customer. We run the tabletop exercises that expose the gaps, and when the real thing happens we work the incident alongside your team: containment, evidence preservation that survives legal scrutiny, eradication, and the honest post-incident review. Two decades of operator escalations taught us the difference between panic and procedure.

  • Incident response plans and scenario playbooks — ransomware, BEC, data breach, insider, DDoS
  • Roles, escalation trees, and out-of-band communications that work when the domain is compromised
  • Tabletop exercises and live simulations with timed findings reported to management
  • Hands-on response: containment, eradication, and recovery worked jointly with your engineers
  • Digital forensics: evidence acquisition, chain of custody, and timeline reconstruction
  • Ransomware-specific readiness: isolated recovery environments and clean-room restore procedures
  • Regulatory notification mapping — Kenya DPA (72-hour), GDPR, and sector rules — drafted before the clock starts
  • Post-incident reviews that change architecture, not just paperwork

When it happens, everyone knows their job — and the evidence, the systems, and the story survive.

07
ISO 27001Kenya DPAPCI DSS · GDPR

Governance, Risk & Compliance

Compliance as engineering evidence — not a parallel paper universe.

The worst compliance programmes live in documents that describe a network nobody runs. We build GRC the other way: controls mapped to the systems as they actually exist, evidence generated by the infrastructure itself — logs, configs, access reviews — and risk registers that engineering recognises as true. ISO 27001, the Kenya Data Protection Act, GDPR, and PCI DSS share most of their skeleton; we implement the control set once and map it outward, so each new framework is a delta, not a fresh project. Compliance is the baseline. The goal is an estate you can defend in front of an auditor and an attacker.

  • Security posture and gap assessments against ISO 27001, NIST CSF, and CIS Controls
  • ISMS build-out: policies, control implementation, and internal audit ahead of certification
  • Kenya Data Protection Act programmes: registration, DPIAs, breach procedures, and data-subject rights handling
  • PCI DSS scoping and segmentation — shrinking the cardholder environment before assessing it
  • Risk assessment and treatment registers that map to real systems and named owners
  • Third-party and vendor risk management with security clauses that survive procurement
  • Evidence automation: control proof drawn from logs and configuration, not screenshots in a binder
  • Board and executive reporting: security posture translated into business risk language

Certification when you need it, defensibility always — with evidence the infrastructure produces for free.

03 — Ecosystem

Where the Discipline Comes From

Every claim on this page traces to production work: securing satellite-upstream cores at InterSAT, DPI and mitigation deployment at KDN/Liquid, full-estate hardening for DSI in the DRC, and formal grounding from Cisco CCNA & CyberOps through Radware and Allot certification to current ISO 27001 and Kenya DPA practice.

  • Cisco CCNA & CyberOps
  • Radware (DDoS)
  • Allot ACTE (DPI)
  • Microsoft Defender & Sentinel
  • ISO 27001
  • Kenya DPA
  • MITRE ATT&CK

Start With a Security Posture Review

A Phase 0 security review maps your estate the way an attacker would — exposure, identity, segmentation, detection, and response readiness — and hands you a prioritised engineering plan, not a scare report.