Skip to content

Security assessment and penetration testing in Kenya

We test your web, API and mobile applications, servers, cloud accounts and API gateways within an agreed scope, and give you findings ranked by risk with specific fixes and a retest.

What changes

  • You know which weaknesses in your systems matter most, and why.
  • Every finding comes with evidence your engineers can reproduce and a specific fix.
  • Your management gets a plain-language summary of risk, not a scanner dump.
  • Fixed issues are retested and confirmed closed.
Hands plug labelled network cables into a switch in a server cabinet

What’s included

  • Scope, testing windows and rules of engagement agreed in writing
  • External and internal vulnerability scanning
  • Penetration testing of web, API and mobile applications
  • Review of authentication, access control and session handling
  • Configuration review of servers, databases, cloud accounts and API gateways
  • WSO2 API Manager and Micro Integrator configuration review
  • Review of personal-data handling against the Kenya Data Protection Act
  • A report with findings ranked by risk, evidence and fixes
  • A retest of fixed findings

How it runs

  1. Step 1

    Scope

    We agree the systems, environments, testing windows and rules of engagement in writing, with named contacts on both sides.

  2. Step 2

    Assess

    Scanning, manual testing and configuration review within that scope. Anything critical is reported to you at once, not saved for the report.

  3. Step 3

    Report

    Findings ranked by risk, each with evidence, impact and a specific fix, plus a summary written for management.

  4. Step 4

    Fix and retest

    We help your team work through the fixes, then retest to confirm each finding is closed.

Why test before someone else does

Every system exposed to the internet is scanned by strangers every day. The question is whether you find its weaknesses first. An assessment gives you that head start: a clear list of what is exposed, what could be abused and what to fix first.

What we look for

  • Access control. Whether one user or partner can reach another’s data or functions by changing an ID, a role or a request.
  • Authentication and sessions. Passwords, one-time codes, tokens and sessions that are weaker than they look.
  • Injection and input handling. Data that reaches a database, a command or another system without being checked.
  • Exposed data and routes. Administrative pages, debug endpoints, backups and personal data that should not be public.
  • Configuration. Servers, databases, cloud accounts and gateways left on defaults, missing updates or with more access than they need.

Applications, APIs and gateways

Most banking, payments and business systems are now reached through APIs, so we spend much of an assessment there. For WSO2 API Manager and Micro Integrator we review what is published, how callers are separated, how tokens are validated and how the servers beneath are hardened. See Integrations for how we build these platforms.

An honest report

We report what we tested, what we found and what was out of scope. An assessment reduces risk at a point in time; it does not remove it, and we will not tell you otherwise. For ongoing assurance, we can repeat testing after major releases and help build security checks into your delivery pipeline.

See Cybersecurity for the whole practice, including hardening, secure development and incident readiness.

Common questions

What is the difference between a vulnerability scan and a penetration test?

A scan uses tools to find known weaknesses quickly across many systems. A penetration test adds a person who tries to use those weaknesses, chains them together and tests the logic of your application, such as whether one customer can see another customer's data. Most assessments need both.

Will testing disrupt our live systems?

We agree testing windows, environments and limits before we start, and we test production only where you have approved it. Where possible we test a staging copy, and we stop and call your named contact if anything behaves unexpectedly.

Can you review our WSO2 API gateway?

Yes. We check which routes are published, how tokens are issued and validated, whether back ends trust the gateway correctly, how throttling and credentials are set per caller, and how the servers underneath are configured.

Does an assessment make us compliant with the Data Protection Act?

No single assessment does. We review how your systems handle personal data and recommend practical controls aligned with the Kenya Data Protection Act 2019. Compliance decisions, and any registration with the Data Commissioner, stay with your organisation.

How much does a security assessment cost?

It depends on the number of applications, APIs and servers in scope and the depth of testing, so we price after a short scoping call. You get a written scope and price before testing starts.

Planning a security assessment or hardening?

Tell us which systems, APIs and gateways are in scope, and what is driving the review. We agree written scope and rules of engagement with your IT and risk teams before any testing starts.