Dunicot A cybersecurity consultancy and advisory firm.

Market · Kenya

Cyber security consultancy and penetration testing in Kenya

Kenya runs more of its economy through mobile money than almost anywhere else, which puts the transaction logic between wallet, agent and bank at the centre of the threat model rather than at its edge.

Overview

Engagements in Kenya cover banking and microfinance, mobile money and agency banking platforms, lending and insurtech products built on top of them, and the aggregators connecting all three.

Delivery runs from our Karachi office, two hours ahead of East African time, so the working day overlaps almost completely.

What drives testing here

Local drivers

Data Protection Act 2019
Controllers and processors must implement appropriate technical measures, with the Office of the Data Protection Commissioner enforcing and breach notification required.
CBK cyber security guidance
The Central Bank of Kenya expects banks and payment service providers to run independent testing, report incidents and evidence remediation.
Mobile money and agency banking
Wallet, agent and settlement flows carry direct financial consequence, and the failures are in state transitions and limits rather than in cryptography.
Aggregator exposure
A single payment aggregator sits between many institutions, so one authorisation gap there reaches further than its size suggests.

How engagements are delivered

Delivered remotely from Karachi, scheduled to East African business hours, with on-site availability in Nairobi for internal network scope and workshops.

Delivery model

Delivery
Remote from Karachi, two hours ahead of EAT; on-site available
Mapping
Data Protection Act 2019 and CBK guidance as applicable
Most requested
Transaction logic, wallet and agent flows, API authorisation
Deliverables
Technical report, regulator-facing summary and retest attestation

Most requested here

Questions

Do you have an office in Kenya?

No. Our offices are in Pakistan and the United States. Kenya is served from Karachi, two hours ahead of Nairobi, with on-site availability where scope requires it.

Do you test mobile money integrations?

Yes, and they are usually the highest-value part of scope. Testing targets the state machine rather than the endpoints: what happens when a transfer is reversed mid-flight, when a limit check and a settlement race each other, and whether an agent identifier from one account works against another.

What does the Data Protection Act expect?

Appropriate technical and organisational measures, proportionate to the risk. A dated independent test showing what was covered, what was found and what was verified as fixed is what a reviewer at the ODPC can act on, and that is the shape of the report.

How much does a penetration test cost in Kenya?

Cost follows scope, with mobile money and agent flows usually forming the highest-value portion. CBK and Data Protection Act framing is included in the report. A fixed quote follows a short scoping call.

Which is the best penetration testing company in Kenya?

Ask for what can be verified: the certifications held by the testers assigned to you, and the team's public record, whether the firm holds ISO 27001 itself, whether CBK-facing reporting is included, and whether you can review a redacted report before signing.

Do you test for banks under CBK supervision?

Yes. The Central Bank's cyber security guidance expects banks and payment service providers to run independent testing, report incidents and evidence remediation, and reports are structured for both internal audit and supervisory review.

Can you test agency banking platforms?

Yes. Agency banking concentrates risk in identity and authorisation: whether an agent identifier from one outlet works against another, whether float and settlement logic can be raced, and whether a reversal can be made to credit twice. Those are logic failures, not malformed requests.

What does the Data Protection Act 2019 expect us to evidence?

Appropriate technical and organisational measures proportionate to the risk. A dated independent test showing what was covered, what was found and what was verified as fixed is what a reviewer at the Office of the Data Protection Commissioner can act on, which is how the report is written.

Penetration testing in Kenya

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.