Overview
Engagements in Kenya cover banking and microfinance, mobile money and agency banking platforms, lending and insurtech products built on top of them, and the aggregators connecting all three.
Delivery runs from our Karachi office, two hours ahead of East African time, so the working day overlaps almost completely.
What drives testing here
Local drivers
- Data Protection Act 2019
- Controllers and processors must implement appropriate technical measures, with the Office of the Data Protection Commissioner enforcing and breach notification required.
- CBK cyber security guidance
- The Central Bank of Kenya expects banks and payment service providers to run independent testing, report incidents and evidence remediation.
- Mobile money and agency banking
- Wallet, agent and settlement flows carry direct financial consequence, and the failures are in state transitions and limits rather than in cryptography.
- Aggregator exposure
- A single payment aggregator sits between many institutions, so one authorisation gap there reaches further than its size suggests.
How engagements are delivered
Delivered remotely from Karachi, scheduled to East African business hours, with on-site availability in Nairobi for internal network scope and workshops.
Delivery model
- Delivery
- Remote from Karachi, two hours ahead of EAT; on-site available
- Mapping
- Data Protection Act 2019 and CBK guidance as applicable
- Most requested
- Transaction logic, wallet and agent flows, API authorisation
- Deliverables
- Technical report, regulator-facing summary and retest attestation
Most requested here
API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Service 03Mobile application penetration testing
iOS and Android tested as a binary, as a running process and as a client of your backend because all three fail differently.
Service 01Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Questions
Do you have an office in Kenya?
No. Our offices are in Pakistan and the United States. Kenya is served from Karachi, two hours ahead of Nairobi, with on-site availability where scope requires it.
Do you test mobile money integrations?
Yes, and they are usually the highest-value part of scope. Testing targets the state machine rather than the endpoints: what happens when a transfer is reversed mid-flight, when a limit check and a settlement race each other, and whether an agent identifier from one account works against another.
What does the Data Protection Act expect?
Appropriate technical and organisational measures, proportionate to the risk. A dated independent test showing what was covered, what was found and what was verified as fixed is what a reviewer at the ODPC can act on, and that is the shape of the report.
How much does a penetration test cost in Kenya?
Cost follows scope, with mobile money and agent flows usually forming the highest-value portion. CBK and Data Protection Act framing is included in the report. A fixed quote follows a short scoping call.
Which is the best penetration testing company in Kenya?
Ask for what can be verified: the certifications held by the testers assigned to you, and the team's public record, whether the firm holds ISO 27001 itself, whether CBK-facing reporting is included, and whether you can review a redacted report before signing.
Do you test for banks under CBK supervision?
Yes. The Central Bank's cyber security guidance expects banks and payment service providers to run independent testing, report incidents and evidence remediation, and reports are structured for both internal audit and supervisory review.
Can you test agency banking platforms?
Yes. Agency banking concentrates risk in identity and authorisation: whether an agent identifier from one outlet works against another, whether float and settlement logic can be raced, and whether a reversal can be made to credit twice. Those are logic failures, not malformed requests.
What does the Data Protection Act 2019 expect us to evidence?
Appropriate technical and organisational measures proportionate to the risk. A dated independent test showing what was covered, what was found and what was verified as fixed is what a reviewer at the Office of the Data Protection Commissioner can act on, which is how the report is written.