
SOC · live monitoring· 01 / 03
The threat inbox, one queue for every report
Nairobi · regional threat intelligence
The attacks aimed at this region, catalogued — then closed.
We are built on one advantage: we can see what is actually being sent to East African organisations. That intelligence drives our assessments, and it drives Seraph CTI — the platform that turns it into simulations and training your staff actually receive.
One practice · two ways to work with us · both fed by the same intelligence
How the practice works
One loop, four moves
Everything we do runs on the same circuit. Each pass through it makes the next assessment sharper and the next simulation more like the real thing.
Report
A Report button in Outlook and Gmail. One click sends the full message to an analyst Threat Inbox, attributed to the organisation that caught it.
Analyse
Reports meet the catalogue: known-exploited flags, profiled threat actors, and breach-exposure monitoring of your domains.
Simulate
Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.
Train
The people who clicked get the course that closes their specific gap. Completion tracked, repeat-clickers surfaced.
Two ways to work with us
Bring in the team, or run the platform
Most organisations start with one and end up with both — the assessment finds the exposure, the platform closes it and keeps it closed. You do not have to decide today.
Bring in the team
Analysts on your estate, with the regional intelligence picture in hand. Scoped to your environment, delivered with a report your board can read.
- Security assessments and audits
- Vulnerability testing against your live stack
- Compliance, data-privacy and risk programmes
- Incident response and containment
Run the platform
Simulations, training and one-click reporting in a closed loop — priced per seat, with the published rate on the page and a calculator to model your own.
- Phishing simulations by department and risk profile
- Training assigned from outcomes, not from a calendar
- Breach and infostealer monitoring of your domains
- Per-tenant SAML SSO, enforced MFA, audit exports
The spine
What we are watching, and where it comes from
Global vendors see Kenya as a region. We see it as the dataset. These figures are read live from the platform — the same numbers our analysts work from.
The first brief is being written
A monthly regional threat brief starts here. An assessment gets you the same picture of your own estate now.
The intelligence pageBreach and infostealer monitoring runs behind a strict redaction boundary. Recovered credential values are read only to set an exposure flag and are never written to our systems — only field names survive ingestion.
Writing
What we make of it
Analysis and argument from the people doing the work — separate from the monthly brief, and written when there is something worth saying.

Board accountability: cybersecurity is governance, not IT
Cybersecurity should not be treated as only an IT function. It is a governance issue that requires active board oversight, accountability, and strategic leadership. Strong board involvement helps organizations manage cyber risk, strengthen resilience, and protect business continuity, reputation, and stakeholder trust.
Seraph Cyber ·

Why Cybersecurity Awareness Training Matters
Cybersecurity awareness training is essential because employees are often the first line of defense against cyber threats. It helps them recognize risks such as phishing and social engineering, handle sensitive data responsibly, and follow proper security practices. Training also supports regulatory compliance and improves early detection of incidents. Overall, it fosters a culture of shared responsibility, reducing human error and strengthening an organization’s ability to prevent and respond to cyber risks.
Seraph Cyber ·

The State of Social Engineering in Cybersecurity
The cybersecurity landscape has witnessed a dramatic transformation in social engineering attacks from 2024 to 2025, characterized by unprecedented growth in AI-powered threats and a fundamental shift in attack methodologies.
Seraph Cyber ·
Services
What the team is engaged to do
Six offers, each scoped to the client rather than sold as a package. Where an engagement is better served by software than by days, we say so.
Security assessments & audits
Identify Weaknesses. Strengthen Defenses.
02Vulnerability Testing and Penetration TestingRuns on Seraph CTI
We identify and safely test vulnerabilities across your digital environment to understand real-world risks and strengthen your security posture.
03Security awareness training
Empower Your Team. Build a Cyber-Resilient Workforce.
04Cloud security & infrastructure
Secure Your Cloud. Protect Your Infrastructure.
05Regulatory Compliance & Data Privacy
Achieve Compliance. Protect Sensitive Data.
06Security strategy & risk managementRuns on Seraph CTI
Align Cybersecurity with Business Goals. Reduce Risk.
Who we work with
The organisations we work for, in their words
Every mark and every quote on this page is published against written permission held on file. Nothing appears here on the strength of a handshake.
PesaWay Ltd
NLS Banking
Enwealth Financial Services
Unaitas
Seraph Cyber conducted a full security audit for our systems and uncovered vulnerabilities we didn't know existed. Their recommendations were practical, and implementation was seamless.
What stood out was their responsiveness. When we faced a potential incident, Seraph Cyber acted immediately and helped us secure our systems before damage occurred.
Trust & security
Built to pass your security review
We handle the most sensitive signal an organisation has — how its people respond to attack. Every statement below reflects how the system actually works, and no certification badge appears on this site until one has been earned.
Tenant isolation
Every record is scoped to its organisation, with a guard layer enforcing that scope on database queries at runtime.
Authentication
Enforced MFA, per-tenant SAML SSO with signed assertions, replay rejection, and short-lived single-use handoff codes.
Credentials & secrets
Adaptive one-way password hashing, org-scoped API keys stored hashed, and a hard redaction boundary on breach data.
Auditability
Sign-ins, administrative changes and authorisation denials recorded in a hash-chained log your own admins can export.
Transport
TLS 1.2 and 1.3 only, a restricted modern cipher suite, long-lived HSTS, and hardening headers served platform-wide.
The paperwork
Terms, a privacy notice, a real data processing agreement and a public status page — linked in the footer, not on request.
Start anywhere
Watch one phish become intelligence
Thirty minutes with your team: the lures currently landing in your sector, how an assessment would scope, and the intelligence view your organisation would see on day one. We reply within one business day.
