WhitepaperThe Kenya Data Protection Act: An Engineering Checklist
What the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Critical national infrastructure, subscriber data at scale, and the signalling and care processes that account-takeover attacks actually run through.

Critical national infrastructure.
An operator is simultaneously a target and a dependency. The direct risk is to your own network and revenue; the systemic risk is to everything built on top of you — mobile money, authentication for banks and government services, and the connectivity other critical sectors assume.
That second role is why subscriber identity deserves disproportionate attention. When a bank uses a phone number as an authentication factor, your SIM re-issue process becomes part of that bank’s security control set, and the process is reachable by social engineering of customer care and by insider collusion. Hardening it protects customers you do not have a contract with.
Our telecommunications work covers the network and the processes around it: core and signalling exposure, subscriber data access across care and self-service channels, availability under attack, and the identity processes that account takeover depends on.
SIM re-issue abused through customer care, agent channels or insider access produces losses at the institutions relying on your number as an authentication factor. Verification strength, approval separation and post-swap cooling-off periods are the controls that matter.
Legacy signalling protocols were designed for a small set of mutually trusting operators. Location disclosure, message interception and subscriber enumeration through interconnect and roaming partners remain real exposures requiring filtering and monitoring at the edge.
Customer relationship management, billing and self-care platforms hold identity documents, call records and location history for millions of subscribers, reachable by large support populations. Bulk-export capability is the critical control point.
Distributed denial of service against your infrastructure or your customers is routine, and your upstream arrangements are part of your control set. Readiness is a tested configuration with a rehearsed escalation path.
Large, distributed care and agent populations with access to subscriber data and provisioning functions create insider risk that is structural rather than exceptional. Entitlement minimisation, dual approval and append-only logging are the response.
Network equipment vendors and managed service providers hold deep, often permanent access to core infrastructure. Each needs brokered access, session recording and an independently revocable credential path.
The sequence below is what a telecommunications engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Telecommunications teamConfiguration and architecture review of core network elements, signalling interfaces and interconnect filtering, alongside testing of the self-care and partner-facing systems that reach subscriber data.
We review SIM re-issue, number porting and account recovery end to end — the technical path, the care script, the agent channel and the approval chain — and design the verification and separation that make abuse expensive.
Entitlement review across care platforms, bulk-export controls with alerting, and logging written to a store the care organisation cannot modify, scoped so that legitimate support work is unaffected.
An operator’s environment never stops changing and never stops being probed. We design, build or run the monitoring and response capability, including the coordination route to the National KE-CIRT/CC.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Research ReportHow fraud actually enters mobile money and agent-banking platforms — social engineering, SIM swap, agent collusion, API abuse — and the control patterns that stand up to each.
Research ReportA practical threat model for systems where a language model can take actions — tool access, prompt injection, credential scope, and the audit trail you will wish you had.