Skip to content
Cloud Infra

SOC · live monitoring· 01 / 03

The threat inbox, one queue for every report

Nairobi · regional threat intelligence

The attacks aimed at this region, catalogued — then closed.

We are built on one advantage: we can see what is actually being sent to East African organisations. That intelligence drives our assessments, and it drives Seraph CTI — the platform that turns it into simulations and training your staff actually receive.

One practice · two ways to work with us · both fed by the same intelligence

How the practice works

One loop, four moves

Everything we do runs on the same circuit. Each pass through it makes the next assessment sharper and the next simulation more like the real thing.

01

Report

A Report button in Outlook and Gmail. One click sends the full message to an analyst Threat Inbox, attributed to the organisation that caught it.

02

Analyse

Reports meet the catalogue: known-exploited flags, profiled threat actors, and breach-exposure monitoring of your domains.

03

Simulate

Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.

04

Train

The people who clicked get the course that closes their specific gap. Completion tracked, repeat-clickers surfaced.

Two ways to work with us

Bring in the team, or run the platform

Most organisations start with one and end up with both — the assessment finds the exposure, the platform closes it and keeps it closed. You do not have to decide today.

Seraph CyberServices
Engagement

Bring in the team

Analysts on your estate, with the regional intelligence picture in hand. Scoped to your environment, delivered with a report your board can read.

  • Security assessments and audits
  • Vulnerability testing against your live stack
  • Compliance, data-privacy and risk programmes
  • Incident response and containment
Book an assessmentScoped and quoted
Seraph CTIPlatform
Subscription

Run the platform

Simulations, training and one-click reporting in a closed loop — priced per seat, with the published rate on the page and a calculator to model your own.

  • Phishing simulations by department and risk profile
  • Training assigned from outcomes, not from a calendar
  • Breach and infostealer monitoring of your domains
  • Per-tenant SAML SSO, enforced MFA, audit exports
See pricingEssentials · $2.50 / seat / month

The spine

What we are watching, and where it comes from

Global vendors see Kenya as a region. We see it as the dataset. These figures are read live from the platform — the same numbers our analysts work from.

141,422Vulnerabilities cataloguedMatched against the technologies each client actually runs.
1,685CISA known-exploitedFlagged where exploitation has been observed in the wild.
176Threat actors profiledMapped to MITRE ATT&CK techniques and tooling.
Regional briefs

The first brief is being written

A monthly regional threat brief starts here. An assessment gets you the same picture of your own estate now.

The intelligence page
What we do not hold

Breach and infostealer monitoring runs behind a strict redaction boundary. Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion.

Writing

What we make of it

Analysis and argument from the people doing the work — separate from the monthly brief, and written when there is something worth saying.

Governance

Board accountability: cybersecurity is governance, not IT

Cybersecurity should not be treated as only an IT function. It is a governance issue that requires active board oversight, accountability, and strategic leadership. Strong board involvement helps organizations manage cyber risk, strengthen resilience, and protect business continuity, reputation, and stakeholder trust.

Seraph Cyber ·

Awareness

Why Cybersecurity Awareness Training Matters

Cybersecurity awareness training is essential because employees are often the first line of defense against cyber threats. It helps them recognize risks such as phishing and social engineering, handle sensitive data responsibly, and follow proper security practices. Training also supports regulatory compliance and improves early detection of incidents. Overall, it fosters a culture of shared responsibility, reducing human error and strengthening an organization’s ability to prevent and respond to cyber risks.

Seraph Cyber ·

Threat analysis

The State of Social Engineering in Cybersecurity

The cybersecurity landscape has witnessed a dramatic transformation in social engineering attacks from 2024 to 2025, characterized by unprecedented growth in AI-powered threats and a fundamental shift in attack methodologies.

Seraph Cyber ·

Who we work with

The organisations we work for, in their words

Every mark and every quote on this page is published against written permission held on file. Nothing appears here on the strength of a handshake.

  • PesaWay Ltd logoPesaWay Ltd
  • NLS Banking logoNLS Banking
  • Enwealth Financial Services logoEnwealth Financial Services
  • Unaitas logoUnaitas

Seraph Cyber conducted a full security audit for our systems and uncovered vulnerabilities we didn't know existed. Their recommendations were practical, and implementation was seamless.

Mabeya ConserayManaging Director · NLS Banking

What stood out was their responsiveness. When we faced a potential incident, Seraph Cyber acted immediately and helped us secure our systems before damage occurred.

Sammy KariukiCEO · PesaWay Limited

Trust & security

Built to pass your security review

We handle the most sensitive signal an organisation has — how its people respond to attack. Every statement below reflects how the system actually works, and no certification badge appears on this site until one has been earned.

Tenant isolation

Every record is scoped to its organisation, with a guard layer enforcing that scope on database queries at runtime.

Authentication

Enforced MFA, per-tenant SAML SSO with signed assertions, replay rejection, and short-lived single-use handoff codes.

Credentials & secrets

Adaptive one-way password hashing, org-scoped API keys stored hashed, and a hard redaction boundary on breach data.

Auditability

Sign-ins, administrative changes and authorisation denials recorded in a hash-chained log your own admins can export.

Transport

TLS 1.2 and 1.3 only, a restricted modern cipher suite, long-lived HSTS, and hardening headers served platform-wide.

The paperwork

Terms, a privacy notice, a real data processing agreement and a public status page — linked in the footer, not on request.

Start anywhere

Watch one phish become intelligence

Thirty minutes with your team: the lures currently landing in your sector, how an assessment would scope, and the intelligence view your organisation would see on day one. We reply within one business day.