Every engagement is governed by an NDA and signed rules of engagement, reported with an executive summary plus CVSS-scored technical findings, and closed with a free re-test after fixes.
Most breaches exploit a vulnerability with a patch already available. We run scheduled patch windows across your whole estate, with pre-checks, snapshots and rollback, and give management a monthly compliance dashboard.
We scan, then we prove. Automated internal and external scans establish the baseline; a scoped grey- or black-box penetration test shows what an attacker could actually reach, with proof-of-concept evidence and a remediation workshop.
A default install is not a secure install. We apply CIS Benchmarks to every server, lock down remote administration, enforce least privilege and segment the network so that a single compromised device cannot reach everything else.
You cannot respond to what you cannot see. We centralise logs, watch for intrusions and configuration drift, alert on capacity and availability, and respond to incidents within defined times.
A backup that has never been restored is a hope, not a plan. We design 3-2-1 backups with off-site and cloud copies, restore-test them every quarter, and document DR runbooks with agreed RPO/RTO targets.
We assess the gap between where you are and what ISO/IEC 27001 and the Kenya Data Protection Act, 2019 require, then close it with policies, controls, evidence and trained staff.
Our engineering desk designs, builds, upgrades and migrates the server platforms organisations run on, with a specialism in enterprise email. Every change is planned around zero data loss and minimal downtime: new nodes are built alongside the old, data is migrated and verified, DNS and routing are cut over in a controlled window, and legacy servers are decommissioned only after sign-off.
A representative scope for upgrading a multi-server Zimbra infrastructure from 9.x on Ubuntu 20.04 to Zimbra 10.1.20 on Ubuntu 24.04, using a side-by-side build so the live platform stays in service throughout. Indicative effort: approximately 20 engineer-days, priced as a fixed-scope project or on a day-rate basis.
Add 4 new LDAP servers as replicas of the current directoryPhase 1 · Directory
PHASE 1Promote the new LDAP servers to masters and verify replication health
PHASE 1Upgrade the new LDAP servers to Zimbra 10.1.20 with configuration backups taken first
PHASE 1Remove old LDAP servers and repoint all existing servers to the new masters
CUT-OVERInstall new proxy servers on 10.1.20 and validate IMAP/POP/HTTPS proxyingPhase 2 · Edge
PHASE 2Retire old proxy/MTA servers; update MX records, mail routing and firewall rules
CUT-OVERInstall the new 10.x LDS server (licence / directory services)Phase 3 · Core
PHASE 3Install 6 new mailbox servers on Zimbra 10.x / Ubuntu 24.04
PHASE 3Install 3 archive servers for retention and discovery
PHASE 3Test migrations with pilot accounts; validate mail flow, calendars, shares and mobile syncPhase 4 · Migrate
PHASE 4Migrate user data — executed by, or jointly with, the client's team using the agreed runbook
PHASE 4Decommission old Zimbra servers once migration is verified and signed offPhase 5 · Close
PHASE 5Fix settings and finalise — global/COS settings, DNS, monitoring, backup jobs, documentation and handover
PHASE 5Costed, itemised proposal with milestones, rules of engagement and NDA.