We work with operators across Kenya's designated CII sectors, where the security of operational infrastructure directly impacts safety, service delivery, and national resilience.
Power generation, transmission and distribution, and petroleum/gas networks. SCADA (Supervisory Control and Data Acquisition), energy management systems (EMS), and DCS (Distributed Control Systems) security. KenGen, KPLC (Kenya Power), KETRACO and sector peers.
Zone/conduit modelling and segmentation for generation-site and national-grid SCADA environments, aligned to IEC 62443 target security levels.
Security review of World Bank and development-finance-institution funded modernisation programmes connecting previously air-gapped OT environments.
Water treatment, distribution, and wastewater management systems. Process control and remote site security across county and national water authorities.
Assessment of treatment-plant process-control systems and the network paths connecting remote sites back to central operations.
Review of remote-access and third-party maintenance paths into distributed water infrastructure, a common, under-assessed entry point.
Rail, aviation, maritime, and road transport control systems. Signalling, fleet management, port and airport operations, and air navigation security.
Operational-technology environments specific to airport ground systems, air navigation services, and the IT/OT boundary around them, assessed under Regulation 39(d) and IEC 62443 together.
Signalling and port-operations control system security, including third-party and shipping-line interconnection points.
Banking infrastructure, payment systems, and stock exchange technology. Critical systems underpinning Kenya's financial market integrity.
Security assessment and offensive assurance for the infrastructure underpinning payment, mobile money, and settlement systems.
Audit readiness and risk assessment for financial-sector CII owners against Legal Notice 44 of 2024.
Kenya's energy, water, and transport infrastructure is undergoing rapid modernisation. World Bank and development finance institution (DFI)-funded SCADA upgrades, smart grid deployments, and digital transformation programmes are connecting operational technology environments that were previously air-gapped, expanding the attack surface at the same time that Kenya's CII Regulations create enforceable compliance obligations.
The gap between IT security maturity and OT security maturity is significant. Most critical infrastructure operators have IT security functions. Very few have OT-specific capability. IEC 62443, combined with the CII regulatory framework, provides the structure to close that gap systematically.
Whichever sector you operate in, the starting point is the same: a structured assessment of what you're running against what the standard and the regulation require.