WhitepaperRansomware Readiness: A Field Playbook for East African Enterprises
The decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
Networks designed to be open, populated by tens of thousands of unmanaged devices, holding student records and research data — secured without turning the campus into an enterprise.

Open campuses, closed systems.
A university is the hardest kind of environment to secure well, because openness is not a weakness to be eliminated but a requirement of the institution. Students bring their own devices, researchers need unusual software and external collaboration, departments run their own systems, and the network has to accommodate all of it.
Attempting to apply an enterprise security model to that produces either a programme that is ignored or an institution that cannot do its work. The approach that succeeds accepts an open access layer and concentrates control where it matters: student records, finance, research data and identity infrastructure, each separated from the open network and from each other.
Our higher-education work starts with identity, because consolidating authentication is the single change that makes everything else possible, and ends with the two places institutions are actually losing: ransomware against administrative systems, and credential phishing aimed at student finance.
Student records, finance and human resources are the systems whose loss stops the institution — admissions, registration, payroll and examinations all depend on them. They are also the systems most often on the same flat network as a teaching lab.
Student portal credentials are targeted for direct financial gain: changing disbursement details, redirecting refunds, or reselling access. Campaigns are timed to registration and disbursement periods and are highly convincing.
Funded research, pre-publication results and collaboration data attract both commercial and state-aligned interest, and are frequently held on departmental infrastructure outside central IT’s visibility.
Tens of thousands of devices you do not administer connect every term. The realistic posture is not controlling them but ensuring they reach nothing of consequence from where they sit.
Faculty-run servers, lab systems and legacy project sites accumulate for decades, often unpatched, sometimes internet-exposed, usually without a current owner. Discovery is the first and most productive piece of work.
Separate credentials across portal, email, library, learning platform and departmental systems make multi-factor authentication unenforceable, de-provisioning unreliable and compromise detection close to impossible.
The sequence below is what a higher education engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Higher Education teamExternal attack-surface mapping plus internal discovery finds the departmental and legacy systems nobody has an inventory for. Institutions are consistently surprised by this stage, and it reprioritises everything after it.
Bringing systems behind single sign-on makes multi-factor authentication, conditional access, de-provisioning and compromise detection achievable at once. It is the highest-leverage project available to most institutions.
Student records, finance and identity infrastructure move behind their own boundary with their own administrative credentials, so an open access network stays open without being a path to the registry.
Targeted campaigns timed to registration and disbursement windows, aimed at the specific phishing patterns your institution actually receives, rather than a generic annual module nobody completes.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperThe decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Research ReportA practical threat model for systems where a language model can take actions — tool access, prompt injection, credential scope, and the audit trail you will wish you had.