WhitepaperRansomware Readiness: A Field Playbook for East African Enterprises
The decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
Core banking, payment rails and customer channels, secured to the standard a supervised institution is actually held to — with the evidence your regulator and your board both ask for.

Protecting the money and the trust behind it.
A bank carries an unusual combination of pressures: an attacker motivated by direct financial gain, a customer base that will leave over a single loss of confidence, and a supervisor entitled to ask how you know your controls work. Security that satisfies only one of the three is incomplete.
Our banking work concentrates on the paths money and credentials actually move along — payment initiation and authorisation, core banking interfaces, the vendor connections into both, the privileged access that operations staff hold, and the digital channels customers use. These are where losses originate, and they are also the areas where supervisory questions are most specific.
We work to the expectations set out in the Central Bank of Kenya’s Guidance Note on Cybersecurity for the Banking Sector, alongside the control frameworks your auditors will reference — ISO/IEC 27001:2022, PCI DSS for card environments, and the SWIFT Customer Security Controls Framework where you are connected to the network.
Business email compromise remains the most common route to a material loss, and it needs no malware. A phished mailbox, a forwarding rule and a hijacked invoice thread are enough — which is why out-of-band verification of payment-detail changes is a control we test for first.
Core banking platforms, switch providers, agency-banking aggregators and managed service providers all hold access into your environment. Each is a trust relationship you did not build the controls for, and each is a path we assess independently.
Operations and support tooling that combines lookup with adjustment, used by a wide group, logging to a system the same group administers, is the configuration behind most insider cases we investigate. Separating read from write is usually the single highest-value change available.
The institutions that recover without paying are the ones holding a backup copy production credentials cannot delete, with a restore time they have actually measured. Both are verifiable in advance, and both are routinely assumed rather than tested.
Mobile and internet banking applications, card-present terminals and ATM estates each present their own abuse paths — business-logic flaws, authorisation gaps between steps, SIM-swap-enabled account takeover and physical tampering among them.
Multi-factor authentication enabled in policy but bypassable through a legacy protocol, a service account or a conditional-access exclusion left in place "temporarily" is the recurring finding in our assessments of bank identity estates.
The sequence below is what a banking engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Banking teamWe start from how value and instructions move through your institution and work outward to the systems that carry them, rather than testing an inventory top to bottom. It produces a shorter list of findings that matter more.
Technical testing of core interfaces, digital channels and payment integrations runs alongside assessment of the human processes around them — payment authorisation, vendor onboarding, privileged access approval and customer verification.
Every engagement closes with findings mapped to the control frameworks you report against, so the work feeds your supervisory submissions and internal audit cycle instead of sitting beside them as a separate document.
Incident response retainers put the commercial arrangement in place before you need it, with named contacts on both sides and an agreed first-hour sequence — so the first call is technical rather than contractual.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperThe decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Research ReportHow fraud actually enters mobile money and agent-banking platforms — social engineering, SIM swap, agent collusion, API abuse — and the control patterns that stand up to each.