AGPO Certified (Women)KRA Tax ComplianteGP Registered Supplier
0722 723 362  ·  info@abushatech.com
Cybersecurity · Patching · Vulnerability Management

We find the weaknesses before attackers do — and keep them closed.

Abusha Technology keeps Kenyan government, county, institutional and corporate systems patched, hardened, monitored and backed up. Aligned to ISO/IEC 27001, CIS Benchmarks and the Kenya Data Protection Act, 2019.

ISO/IEC 27001 aligned CIS Benchmarks OWASP Top 10 / ASVS NIST CSF Kenya DPA 2019
abusha-soc · security health check
FindingsCVSS scored
Re-testFree after fix
Turnaround3–5 days
0Year founded
0Counties served
0Monitoring & alerting
0Kenyan owned · women-led
Core cybersecurity services

Unpatched servers, exposed services and untested backups sit behind most incidents. We remove all three.

Our security practice keeps systems current, finds weaknesses before attackers do, and gives management a prioritised, CVSS-scored picture of risk.

02

Vulnerability Assessment & Penetration Testing

Internal and external scans, web-application testing aligned to OWASP, mail-platform testing and scoped grey/black-box penetration tests.

  • OpenVAS/Greenbone, Nessus, Nmap, Nikto
  • Proof-of-concept exploits and remediation workshop
  • Free re-test after fixes
Learn more →
03

Server & Network Hardening

CIS Benchmark hardening for Ubuntu, RHEL-family and Windows Server, least-privilege access and segmented, firewalled networks.

  • SSH key-only access, MFA, sudo policy
  • ufw/nftables, fail2ban, SELinux/AppArmor, disk encryption
  • Perimeter firewall, VLAN segmentation, VPN
Learn more →
04

Monitoring, SIEM & Incident Response

24×7 monitoring and alerting, centralised logging, intrusion detection and file-integrity monitoring with defined response times.

  • Zabbix, Prometheus/Grafana, uptime and capacity checks
  • Wazuh / ELK SIEM, log retention
  • Incident response under SLA
Learn more →
05

Backup & Disaster Recovery

3-2-1 backup design with off-site and cloud copies, quarterly restore tests, documented DR runbooks and failover drills.

  • RPO/RTO targets agreed and tested
  • Backup verification reports
  • Ransomware-resilient, immutable copies
Learn more →
06

Compliance Readiness

Gap assessment against ISO 27001 and the Kenya Data Protection Act 2019, security policies and staff awareness training.

  • Audit-ready evidence of a maintained estate
  • Policy set and DPA 2019 registers
  • Annual review and awareness sessions
Learn more →
Service packages

Pick the engagement that fits — from a one-off health check to a managed security retainer.

PackageWhat you receiveCadence
Security health checkOne-off external + internal scan, configuration review of servers, mail and firewall, executive risk reportOnce · 3–5 days
Patch & vulnerability managementPatching windows, scans, CVSS-prioritised remediation, compliance dashboardMonthly
Penetration testScoped grey/black-box test, proof-of-concept exploits, remediation workshop, re-testAnnual or pre-go-live
Managed security & backup24×7 monitoring and alerting, log retention, backup verification, incident responseContinuous · under SLA
Compliance readinessGap assessment against ISO 27001 / DPA 2019, policies, staff awareness trainingProject + annual review
Secure by default

Every server, mail platform and network we deliver is patched, hardened, backed up and scanned before handover.

Then it stays that way under a managed-services SLA. You get audit-ready evidence, a named contract manager and one point of escalation.

  • NDA, rules of engagement and DPA 2019 compliance on every engagement
  • Executive summary plus technical findings, CVSS scored
  • Change control, rollback plans and snapshots for production systems
  • Credentials handed over and rotated; least-privilege named accounts
  • Security reports shared only with the client's written consent
Why buyers choose us
Typical estate — before vs. after 90 days
Critical / high CVEs open (before)38
Critical / high CVEs open (after)0
Admin consoles exposed to internet (before)5
Admin consoles exposed (after — VPN + MFA)0
Backup restore verified (before)Never
Backup restore verified (after)Quarterly

Illustrative outcomes from a managed patch & vulnerability programme.

How we deliver

From first call to a maintained, secure estate

Enquiry & systems survey

Free scoping call, site or remote survey and asset inventory.

Costed proposal & scope of works

Itemised quotation, milestones, rules of engagement and NDA.

Assessment, hardening or migration

Work inside agreed change windows with snapshots and rollback.

Testing, security scan & handover

Post-work vulnerability scan, runbooks, credentials handover.

Support, patching & maintenance

30-day hypercare, then SLA-based managed support.

Beyond security

Server infrastructure, enterprise email and the rest of the ICT stack — from one accountable supplier.

02

Server Infrastructure & Enterprise Email

Linux/Windows server builds and OS upgrades, Zimbra 9.x/10.x multi-server platforms (LDAP, proxy/MTA, mailbox, archive), Postfix/Dovecot, Microsoft 365 / Google Workspace hybrid, migrations and decommissioning. See the reference Zimbra upgrade scope →

01

Computers & ICT Equipment

Laptops, desktops, servers, storage, printers, UPS, structured cabling, switches, routers, firewalls and access points, software licensing and ICT support contracts.

03

Electronics & Security Equipment

IP CCTV, access control and biometrics, alarms and electric fencing, AV and conferencing, solar and backup power — network devices delivered on segmented VLANs with default credentials changed.

04

Office Supplies & Toners

Genuine toners and consumables, stationery, cleaning supplies and office furniture under fixed-price framework contracts with countrywide delivery.

Tender-ready compliance

Ready for restricted, reserved and open tenders

Certificate of IncorporationPVT-EY13LVRRPrivate Limited Company · 06 March 2021
KRA Tax CompliancePIN P052520051STCC KRAWON1539838826 · valid to 08 March 2027
AGPO Certificate (Women)NT/PPD/2026/DGW/2818Valid to 10 March 2028 · 30% reserved window
eGP Supplier RegistrationSR/eGP/2026/63000Goods, Works, Consultancy & Non-Consultancy · to 06 April 2028
Start here

Get a free security health check

External and internal scan, configuration review of servers, mail and firewall, and an executive risk report — delivered in 3 to 5 days. We respond to every enquiry within one working day.