Eight Practice Catalogues • One Accountable Team
Services & Capabilities
The full map of the practice: seven dedicated catalogues, six deep practice pages, and the specialised consulting capabilities behind them — all built on two decades inside production infrastructure.
01 — Catalogues
The Service Catalogues
Eight practice areas, each with a dedicated section — organised, illustrated, and linked all the way down.
Start with the catalogue closest to your problem; each one deep-links into the detailed practice pages and capability lists behind it.
CyberSecurity
Operator-grade security: DDoS mitigation, SOC & SIEM engineering, OSINT, offensive security, zero trust, incident response, and GRC.
Open catalogueSoftware DEV — Helix Studios
The HCS software unit: bespoke software and APIs, payment systems, the Helix Cloud NMS product line, web development (Next.js, PHP, WordPress), DevOps, and full-lifecycle delivery.
Open catalogueCloud
AWS & GCP architecture, hybrid networking, migration, containerization & Kubernetes, virtualization & private cloud, operations, FinOps, and disaster recovery with tested failovers.
Open catalogueEnterprise Services
The business estate: Microsoft 365 up to E7, Odoo ERP, systems engineering, SD-WAN & MPLS, unified comms, Yeastar IP PBX, managed IT, and continuity.
Open catalogueFinTech
IFRS 9 ECL modelling with Python and Excel model builders, open-weight AI inside the bank (OpenClaw, Ollama, Open WebUI) with Slack and Discord integration, econometrics, and M-Pesa & mobile money integration.
Open catalogueBig Data & Analytics
The data platform end to end: Apache Kafka event streaming as a flagship practice, Hadoop, Spark & PySpark, Databricks lakehouse, data engineering, analytics & BI, and production machine learning.
Open catalogueISP Operations
The home turf: access networks, core & backbone, NOC operations, subscriber & revenue systems, satellite & hybrid connectivity, and ISP launch.
Open catalogueAI
AI put to work: enterprise & executive training, integration & transformation, AI in financial services, and private open-weight deployment.
Open catalogue02 — Practices
Primary Practices
Deep, page-level expertise — each practice stands on its own
03 — Opportunities
Consulting Opportunities
Specialised capabilities offered through Helix Cloud Solutions
Beyond the primary practices, we take on focused engagements across every field the team has operated in. If your problem touches one of these areas, it is in scope.
Satellite Communication & RF Engineering
Satellite work is unforgiving: a mispointed feed, a dirty cross-pol, or a lazy link budget shows up as real money and real outage minutes. We have done this at every layer — teleport and hub infrastructure, end-user VSATs, and the RF engineering in between — including Avanti fleet ground monitoring operations in Kenya and Tanzania and a 7.3m earth-station CPI normalization with satellite tracking for a UNSOA project in Mogadishu. That background matters now more than ever, because the multi-orbit era (GEO HTS alongside LEO) rewards teams who can size, commission, and defend a link — not just resell capacity.
- Teleport and hub infrastructure engineering — from antenna systems and RF chains to hub-side commissioning and operations
- Large earth-station work: 7.3m antenna CPI (cross-pol isolation) normalization and satellite tracking alignment
- VSAT installation, commissioning and line-up discipline (Avanti-trained, 2013)
- Ground-segment fleet monitoring operations — carrier health, interference triage, and outage response across multiple sites
- Link budgeting and frequency planning for satellite and terrestrial microwave (Cambium frequency planning workshop, 2016)
- Wireless and microwave access, distribution and backhaul design as the terrestrial half of hybrid networks
- Satellite-to-fibre migration planning — sequencing cutovers so remote sites gain capacity without losing resilience (KDN program experience)
By 2026 the ground segment is a multi-orbit problem: GEO HTS, MEO and LEO constellations get blended per-site, and the differentiator is no longer access to capacity but the engineering to pick, commission and monitor the right mix. Interference management and disciplined RF practice matter more, not less, as the sky gets crowded.
Data Analytics & Business Intelligence
Most dashboards die because nobody trusts the numbers underneath them — so we start with the data model, not the visuals. We work across the modern analytics stack: SQL and data modelling at the core, Power BI and Tableau on top, and Databricks with PySpark when the data outgrows a single machine. Our training runs through the ALX Data Analytics programme (2026) and IBM's Python for Data Science, grounded in hands-on data analytics and engineering competency. The discipline is unglamorous — clean pipelines, defined metrics, one version of the truth — and that is exactly why it works.
- SQL query design and optimisation against production relational databases
- Power BI report and semantic model development — DAX measures, star-schema data modelling, row-level security
- Tableau dashboard development for exploratory and executive reporting
- Distributed data processing with Apache PySpark on Hadoop and Databricks
- Data modelling and database management — schema design, normalisation, and metric definition
- Python for data science: pandas-based cleaning, analysis, and automation (IBM-trained, 2025)
- Spreadsheet-to-warehouse migration paths — moving teams off fragile Excel logic onto governed models
- Data and AI literacy enablement for business teams (ALX Data Analytics, 2026)
In 2026 the centre of gravity has shifted from dashboards to agentic BI — Power BI, Tableau, and Databricks all now ship AI agents that query data directly, which makes a governed semantic layer and disciplined data modelling the difference between trustworthy answers and confident nonsense. The stack itself has settled: lakehouse compute underneath, defined metrics in the middle, and increasingly an agent rather than a chart on top.
FinTech & Financial Systems
Financial systems fail quietly: a model that overstates collateral haircuts, a reconciliation job that drifts, an API that a regulator's auditor cannot trace. We approach fintech from the infrastructure side up — we have spent years connecting banks before we started building for them, from Kenya's major banks as connectivity clients at KDN to the Central Bank of Burundi via CBINET and Stanbic and KCB in South Sudan. That background shapes how we work on IFRS 9 ECL modelling, AI in financial systems, and Dynamics 365 Finance: everything must survive an audit, a failover, and a sceptical risk committee.
- IFRS 9 expected credit loss (ECL) modelling — PD/LGD/EAD estimation, staging logic, and forward-looking macroeconomic overlays that stand up to auditor and central-bank scrutiny
- AI in financial systems — credit scoring on alternative data, fraud and anomaly detection, and model governance that keeps machine learning explainable to risk committees
- Microsoft Dynamics 365 Enterprise: Finance — chart-of-accounts design, financial consolidation, and integration with core banking and payment rails
- Bank-grade connectivity and infrastructure — experience serving all major Kenyan banks at KDN and central-bank environments (Central Bank of Burundi via CBINET)
- Cross-border financial operations in hard environments — Stanbic and KCB connectivity work in South Sudan, where uptime engineering is not optional
- Payments and open-finance integration — real-time payment systems, mobile-money interconnection, and API architectures aligned with CBK-era open finance direction
- Regulatory and audit alignment — building financial data pipelines and models with the traceability that IFRS 9 provisioning and supervisory review demand
By 2026, AI in African banking has moved from pilot to core infrastructure — fraud detection and alternative-data credit scoring are now table stakes — while Kenya's regulatory wave (the FPS real-time rails, the VASPs Act, open-finance APIs under the CBK's 2025–2028 inclusion strategy) means the hard work has shifted from building features to building systems that regulators can trace and auditors can trust.
Microsoft 365 & Power Platform
We work the Microsoft stack as delivery partners — Power Automate and Power Apps for the workflows people actually run, Copilot and M365 agentic AI where automation earns its keep, and Dynamics 365 Finance and Supply Chain Management at the ERP core. The hard part of this platform in 2026 isn't building an agent or a flow; it's governance — Purview labels that actually propagate, environment strategy, connector policies, and Copilot credit spend that doesn't surprise the CFO. Low-code without guardrails becomes shadow IT with a nicer logo, so we treat the admin center as seriously as the app.
- Power Automate workflow design — cloud flows, approvals, connector governance and DLP policies
- Power Apps development on Dataverse for line-of-business applications
- Microsoft Copilot rollout and adoption — grounding agents in SharePoint and Dataverse, metering credit consumption
- M365 agentic AI cloud machines — building and operating governed AI agents across the tenant
- Microsoft Purview — sensitivity labeling, data classification, and compliance posture for Copilot-era data estates
- Dynamics 365 Enterprise implementation — Finance and Supply Chain Management
- Delivery under Microsoft partnership — licensing guidance, environment strategy, and tenant administration
2026 is the year Microsoft's story shifted from "Copilot as assistant" to governed agents as operational teammates — Agent 365, the E7 bundle, and risk-tiered agent governance in the Power Platform admin center all landed this cycle. The winners are teams that classify agents by risk and wire Purview and Entra controls in before scaling, not after.
Enterprise & Open-Source Systems
Enterprise software fails in Africa for predictable reasons: systems chosen for licence cost instead of total cost, data locked in tools nobody can extend, and integrations held together by one person's goodwill. We work across that whole spectrum — open-source platforms like DHIS2, ODK and Kobo Toolbox on one end, Dynamics 365 on the other — and we have deployed them where it counts: national health systems with Jembi Health and the Rwanda Ministry of Health, and payment and ticketing architecture for Tanzania National Parks with MTN Business. The discipline is the same everywhere: get the data model right, make the integrations boring, and leave the client able to run the system without us.
- DHIS2 deployment and configuration for national-scale health information management, including aggregate and tracker data models
- Mobile-first field data collection with ODK and Kobo Toolbox — form design, offline sync, and pipelines into analysis systems
- Health information system and network infrastructure deployment, delivered with Jembi Health and the Rwanda Ministry of Health
- Payment and ticketing platform architecture with a centralized data centre, built for Tanzania National Parks with MTN Business
- Microsoft Dynamics 365 Supply Chain Management implementation and integration
- CRM and ERP selection, deployment, and data migration — matching the platform to the process, not the other way round
- System integration and interoperability: APIs, data exchange between open-source and commercial platforms, and single-source-of-truth data models
In 2026 the interesting work is in interoperability, not installation: African ministries and enterprises are standardising on open architectures — OpenHIE patterns and FHIR in health, modular cloud ERP elsewhere — under frameworks like the AU Data Policy Framework, and the practical question has shifted from "which system?" to "can our systems talk to each other, and can we take our data with us?"
Virtualization & Business Continuity
We were virtualizing production workloads before it was fashionable — the first VMware vCentre deployment in the region at KDN, built with Dell and VMware, and DR platforms whose early corporate customers (Centum, HELB) trusted them enough to later move primary production onto them. That taught us the uncomfortable truth of business continuity: the replication is the easy part, and the failback nobody rehearsed is where recoveries die. So we design for tested RTOs, not brochure RTOs — immutable copies, documented runbooks, and restore drills that actually run. With Broadcom's licensing squeeze pushing enterprises to rethink their hypervisor estate, we help teams choose between staying, migrating, or mixing — on the numbers, not the vendor pitch.
- VMware vSphere and vCentre design, deployment, and lifecycle management — grounded in formal vSphere and Dell EqualLogic training and production estates run since 2010
- Hypervisor estate strategy in the post-Broadcom era: stay/migrate/hybrid cost modelling across vSphere, Proxmox VE, Hyper-V, and KVM-based stacks
- Disaster-recovery platform design as a product: replication topologies, failover orchestration, and the failback plan most DR designs forget
- Backup and recovery posture reviews — RPO/RTO reality-checks, restore testing, immutability and air-gap verification, retention and 3-2-1 hygiene
- Shared virtualization infrastructure economics: consolidation ratios, capacity planning, and leasing virtual capacity to third parties (built and run at DSI in the DRC)
- Dell EqualLogic and iSCSI SAN storage architecture: multipathing, snapshot and replication scheduling, storage sizing for virtual workloads
- Ransomware-aware continuity planning: isolated recovery environments, clean-room restores, and runbooks written for the 3 a.m. incident, not the audit binder
The Broadcom acquisition turned virtualization from a settled question back into a strategic one — with subscription-only licensing, 72-core minimums, and price increases customers report in the hundreds of percent, Gartner expects most enterprise VMware shops to migrate at least half their workloads by 2028. Meanwhile DR has shifted from insurance policy to ransomware survival plan: immutable, air-gapped copies and rehearsed restores are now the baseline, because roughly a third of teams still miss their RTO simply because backups were never tested.
Internet Resources & Peering
Latency in Africa is usually a routing problem before it is a bandwidth problem — traffic tromboning through Europe because nobody sat down and fixed the peering. We have done the unglamorous parts of fixing it: securing AfriNIC IPv4, IPv6, and ASN resources and originating them cleanly, building peering at KIXP, JINX, and LINX to pull traffic off expensive transit, and serving as technical lead for the first Google Global Cache node in East and Central Africa. We also know the capacity side, having planned submarine-fibre capacity on SEACOM and TEAMS against Level 3 and PCCW transit — so we argue from route tables and cost-per-Mbps, not slideware.
- AfriNIC number-resource strategy: IPv4/IPv6 allocation justification, ASN acquisition, and clean prefix origination (delivered end-to-end for DSI in the DRC)
- BGP peering architecture at African and European exchanges — KIXP, JINX, LINX — engineered to cut transit spend and round-trip latency
- Content-cache and CDN node deployment: technical lead for the first Google Global Cache in East & Central Africa, brokered across KDN, TESPOK, and Google
- IPv6 addressing plans and dual-stack rollout, grounded in AfriNIC IPv6 training (Ghana, 2011) and live operator deployment
- Submarine-cable capacity planning on SEACOM and TEAMS, balanced against Level 3 and PCCW IP transit commitments
- Transit cost engineering: traffic-ratio analysis, peering-vs-transit economics, and 95th-percentile billing discipline
- Routing hygiene for AfriNIC members: IRR/route-object maintenance and RPKI route-origin authorization so announced space stays reachable and trusted
The 2026 story is traffic finally staying on the continent: African IXPs like Nigeria's IXPN have crossed multi-terabit peaks as carrier-neutral data centres and hyperscaler caches land directly on exchange fabrics, while AfriNIC's near-empty IPv4 pool makes IPv6 planning and disciplined address stewardship a commercial necessity, not a checkbox.
Electrical & Power Systems
Power is the first single point of failure in African infrastructure — most "network outages" we've traced ended at a breaker, a tired battery bank, or a generator that never got its load test. We bring advanced electrical and power systems engineering shaped by work in the power and energy sector, including KenGen, and we've attacked the demand side too: virtualization projects at KDN Telehouse and DSI that cut facility power consumption outright. From utility intake to the last DC bus, we design for the grid you actually have — sags, surges, and all — not the one on the datasheet. The cheapest kilowatt remains the one your equipment never draws.
- Facility power architecture: utility intake, transfer switching (ATS/STS), distribution, and earthing/grounding design for telecom and data facilities
- UPS engineering — sizing, runtime modeling, and lead-acid to lithium-ion migration for smaller footprint and longer ride-through
- Hybrid power design for unstable grids: generator, solar PV, and battery energy storage (BESS) integration with autonomy and fuel-burn calculations
- -48V DC power plants, rectifier systems, and battery banks for telecom, ISP, and satellite ground infrastructure
- Power-demand reduction through consolidation and virtualization — proven approach from facility power-cut projects at KDN Telehouse and DSI
- Electrical automation, monitoring, and control: SCADA-style telemetry, per-circuit metering, and alarming on power anomalies before they become outages
- Energy audits and PUE-driven efficiency work: load profiling, harmonic and power-factor correction, and cooling/power co-optimization
- Generation-sector-grade engineering discipline from power and energy work including KenGen — protection coordination, redundancy design, and maintenance regimes
Across Africa in 2026 the conversation has shifted from diesel-as-default to hybrid architectures — lithium-ion UPS riding through grid disturbances, behind-the-meter solar plus battery storage cutting energy costs sharply as BESS prices fall below $90/kWh — with most new facilities built modular and phased rather than monolithic. The practical skill is no longer buying backup; it's orchestrating grid, solar, storage, and generator so diesel becomes the last resort instead of the first.
Delivery & Enablement
Projects fail in the last mile: the kit arrives, the link is up, and nobody on the ground can run it. We manage delivery end to end — scoping, vendor and logistics coordination, rollout, then structured handover — and we treat training as part of the deliverable, not an afterthought. Our team has coordinated multi-country deployments, including field logistics for 73 BBC World Service partner stations, and has run ISP capacity-building programmes for technical and business teams across West, East and Central Africa. When we leave, your people can operate what we built.
- Project coordination and delivery management for telecom/ISP rollouts — scoping, scheduling, vendor and site coordination through commissioning
- Multi-country field logistics: equipment staging, shipping and customs coordination, and site readiness across African markets
- Technical training design and delivery for NOC, field and support teams — hands-on labs, runbooks and structured handover packs
- Commercial enablement: training sales and business teams to scope, price and support connectivity and cloud services credibly
- Pre-sales support — solution scoping, bill-of-materials and proposal input grounded in what actually deploys cleanly
- Post-sales support structures: escalation paths, SLA-aligned support processes and knowledge transfer to in-house teams
- Technical research and evaluation — testing equipment and platforms before they are committed to a customer network
- Team leadership and cross-functional coordination between engineering, vendors, logistics and customer stakeholders
In 2026 the enablement conversation across African telecom is about closing the skills gap that automation exposes: operators are pairing network rollouts with structured learnership and workforce-transformation programmes, because AI-assisted operations still fail without trained local hands. The practical shift is toward blended delivery — classroom plus on-site practical work — and toward treating partner and reseller education as core infrastructure, not marketing.
Not Sure Where Your Problem Fits?
Start with a focused technical review — we will locate the real problem before proposing anything.