OT/ICS and critical-infrastructure cybersecurity advisory at the intersection of IEC 62443 and Kenya's Critical Information Infrastructure Regulations, where technical security meets regulatory obligation.
Port254 is principal-led, not a delivery pipeline: the person who scopes the engagement is the person who does the work.
More than two decades across networking, infrastructure and cybersecurity. Tony currently operates at Principal Advisor/Consultant level in Australia, working directly with critical infrastructure and operational-technology environments, the same class of systems Kenya's designated CII operators run.
He holds an MSc in Computer Science, is ISA/IEC 62443 Expert-certified across all four domains (fundamentals, risk assessment, system design, and maintenance), and contributes to ISA/IEC 62443 standards working groups. His networking background is CCNP-certified; his offensive-security background is OSCP and OSEP; and he holds OffSec's AI Red Teamer (OSAI) certification for assessing AI systems entering operational environments. He is also a CISSP.
Port254 exists to apply that combination (OT/ICS engineering depth, international standards practice, and offensive-security grounding) directly to Africa's critical infrastructure, starting in Kenya.
Two principles underpin every port254 engagement.
IEC 62443 is the only international standard purpose-built for securing industrial control systems. Every assessment, recommendation, and remediation roadmap we deliver is anchored to it. Not ISO 27001 adapted for OT (Operational Technology), not a generic framework stretched to fit. We hold ISA/IEC 62443 Expert certification across all four domains: fundamentals, risk assessment, system design, and maintenance.
Kenya's CII Regulations are in force. The compliance deadlines have passed. NC4 (the National Computer and Cybercrimes Co-ordination Committee), the body that enforces Kenya's CII Regulations, has formal audit powers and can enter premises with 30 days' notice. We understand the regulation in detail: the obligation stack, the CISO requirements, the 24-hour incident reporting window, the data localisation rules. We build that into every engagement so clients aren't managing two separate programmes.
port254 engagements are delivered by a practitioner certified across the full CII security lifecycle, from regulatory compliance and risk assessment through to offensive security, networking, and AI system security.
We work with operators across Kenya's designated CII sectors: energy, water, transport, and financial services, where the security of operational infrastructure directly impacts safety, service delivery, and national resilience.
Sector-specific detail: view Industries →
Looking for OT/ICS and critical-infrastructure cybersecurity advisory in Kenya? Let's discuss how port254 can help your organisation secure its operational infrastructure and meet its regulatory obligations.