Everything here should be verifiable — that's the point of this page.
Not a biography page. This is where we lay out who does the work, how we work, and what credentials back it up — so you don't have to take our word for it.
A consulting and forensics firm first — everything else follows from that.
Cyber Security Africa is an information security consulting and digital forensics firm based in Nairobi, working across East Africa. Our identity is built on three connected capabilities: advisory consulting for boards and risk leaders, evidentiary forensic and fraud investigation work, and hands-on technical training — delivered by the same practitioners across all three, not separate teams operating under one brand.
We don't describe ourselves as a research institution or a managed security provider, because we aren't one. What we are is a firm that has spent over a decade doing investigative and advisory work specifically for African banks, enterprises, and institutions — and this page exists to make that claim checkable.
Africa headquarters in Nairobi, Kenya, with engagement history across East Africa including Ethiopia.
Consulting, forensics, and training delivered by the same practitioner base — not outsourced or franchised.
Convener of the Banking & ICT Summit since its founding edition.
Credentialed practitioners, not a marketing team.
Fraud & Forensic Examiners
Certified Fraud Examiners lead every forensic and fraud investigation engagement, from scoping through final findings.
Governance & Risk Advisors
Advisory consultants translate technical findings into board- and regulator-ready reporting.
Security Testing & Training Practitioners
Practicing testers and instructors who deliver both client assessments and Training Academy courses.
We've kept this page role-based rather than naming individuals, since our source material doesn't include named leadership bios to draw from responsibly. If you'd like named team profiles and photography added, send us the details and we'll build them out accurately.
The same standard, applied to every engagement type.
Scope to Business Context
We start with what's actually at risk for your organization, not a generic checklist.
Do the Technical Work
Assessment, testing, or investigation, conducted to a standard that holds up under scrutiny.
Document the Evidence
Every finding is traceable — chain of custody, methodology notes, and sourcing intact.
Translate to Decisions
Findings are delivered in the language the audience needs — board, regulator, or technical team.
Credentials that back the work, not just the name.
Certified Fraud Examiner
Held by staff leading fraud and financial investigation engagements.
IT Governance Practice
Advisory work benchmarked against established governance frameworks.
Tools we recommend and deploy, through named partners.
Four principles that show up in the work, not just this page.
Evidence Over Assertion
Every claim we make about our own work should be checkable — same as the findings we deliver to clients.
Regional Fluency
We work in the regulatory and threat context our clients actually operate in, not a generic global template.
Technical Seriousness
Forensic and investigative rigor is the foundation of everything else we offer, including advisory work.
Capability Transfer
Training exists to raise our clients' internal capability, not just to sell courses.
We hire for the same seriousness this page describes.
Roles in consulting, forensics, and training open periodically. If you don't see a current opening that fits, reach out anyway — we'd rather hear from a strong candidate early than miss one waiting for a formal posting.
No open roles are listed in this prototype. Send us your current openings and we'll build out full role pages.
Anything on this page you'd like us to expand on?
We'd rather answer directly than let a claim sit unverified — ask us anything about our team, methodology, or credentials.