AGPO Certified (Women)KRA Tax ComplianteGP Registered Supplier
0722 723 362  ·  info@abushatech.com
Division 02 — Cybersecurity, Servers & Enterprise Email

Cybersecurity services that leave you audit-ready

Every engagement is governed by an NDA and signed rules of engagement, reported with an executive summary plus CVSS-scored technical findings, and closed with a free re-test after fixes.

Standards ISO/IEC 27001 · CIS · OWASP · NIST CSF Confidentiality NDA · RoE · DPA 2019 Delivery Remote or on-site, inside agreed windows
01 · MONTHLY

System Patch Management

Most breaches exploit a vulnerability with a patch already available. We run scheduled patch windows across your whole estate, with pre-checks, snapshots and rollback, and give management a monthly compliance dashboard.

Critical / zero-day patching within agreed SLA hours
  • Scheduled OS and application patching — Linux (apt/dnf), Windows (WSUS/Intune), hypervisors and firmware
  • Zimbra, mail, web and database patch cycles with pre-checks and rollback snapshots
  • Critical and zero-day emergency patching within agreed SLA hours
  • Monthly vulnerability scan after patching to prove closure
  • Compliance dashboard and audit-ready patch evidence
Ubuntu / DebianRHEL · Rocky · AlmaWindows ServerProxmox · VMware · Hyper-VZimbra 9.x / 10.xMySQL · PostgreSQL
02 · ANNUAL OR PRE-GO-LIVE

Vulnerability Assessment & Penetration Testing

We scan, then we prove. Automated internal and external scans establish the baseline; a scoped grey- or black-box penetration test shows what an attacker could actually reach, with proof-of-concept evidence and a remediation workshop.

CVSS-scored findingsFree re-test after fixes
  • Internal and external vulnerability scans across servers, network devices and endpoints
  • Web application testing aligned to OWASP Top 10 and OWASP ASVS
  • Mail-platform testing — open relay, TLS, SPF/DKIM/DMARC, authentication and admin-console exposure
  • Scoped grey / black-box penetration test with proof-of-concept exploits
  • Executive summary, technical findings, prioritised remediation plan and re-test
OpenVAS / GreenboneNessusNmapNiktoBurp SuiteOWASP ZAPMetasploit
03 · PROJECT + RETAINER

Server & Network Hardening

A default install is not a secure install. We apply CIS Benchmarks to every server, lock down remote administration, enforce least privilege and segment the network so that a single compromised device cannot reach everything else.

  • CIS Benchmark hardening for Ubuntu, RHEL-family and Windows Server
  • SSH key-only access, MFA, sudo policy and least-privilege service accounts
  • Host firewalls (ufw/nftables), fail2ban, SELinux/AppArmor and disk encryption
  • Perimeter firewall, VLAN segmentation, VPN and secure remote administration
  • TLS 1.2+/1.3 only, current cipher suites and valid certificates on every service
  • Admin consoles restricted by IP/VPN with MFA
CIS-CATLynisnftables · ufwfail2banAppArmor · SELinuxWireGuard · OpenVPN
04 · CONTINUOUS · UNDER SLA

Monitoring, SIEM & Incident Response

You cannot respond to what you cannot see. We centralise logs, watch for intrusions and configuration drift, alert on capacity and availability, and respond to incidents within defined times.

  • 24×7 monitoring and alerting — Zabbix, Prometheus/Grafana, uptime and capacity checks
  • Centralised logging and SIEM (Wazuh / ELK) with log retention for audit
  • Intrusion detection and file-integrity monitoring
  • Incident response with defined response and resolution times
  • Monthly service report with security events and trends
ZabbixPrometheus · GrafanaWazuhELK StackSuricataUptime Kuma
05 · CONTINUOUS + QUARTERLY TESTS

Backup & Disaster Recovery

A backup that has never been restored is a hope, not a plan. We design 3-2-1 backups with off-site and cloud copies, restore-test them every quarter, and document DR runbooks with agreed RPO/RTO targets.

  • 3-2-1 backup design with off-site / cloud copies and immutable, ransomware-resilient storage
  • Quarterly restore tests with signed verification reports
  • Documented DR runbooks, RPO/RTO targets and failover drills
  • Mail-platform, database and virtual-machine level backups
Proxmox Backup ServerVeeamBorgBackup · resticrsyncS3-compatible object storage
06 · PROJECT + ANNUAL REVIEW

Compliance Readiness — ISO 27001 & Kenya DPA 2019

We assess the gap between where you are and what ISO/IEC 27001 and the Kenya Data Protection Act, 2019 require, then close it with policies, controls, evidence and trained staff.

  • Gap assessment against ISO/IEC 27001 and the Kenya Data Protection Act, 2019
  • Information security policy set, risk register and asset inventory
  • Data-processing agreements, records of processing and breach procedures
  • Staff security awareness and phishing-resilience training
  • Annual review and evidence pack for auditors and procuring entities
Division 02 — Part A

Server Infrastructure & Enterprise Email

Our engineering desk designs, builds, upgrades and migrates the server platforms organisations run on, with a specialism in enterprise email. Every change is planned around zero data loss and minimal downtime: new nodes are built alongside the old, data is migrated and verified, DNS and routing are cut over in a controlled window, and legacy servers are decommissioned only after sign-off.

Server platforms & operating systems

  • Linux server builds — Ubuntu LTS (20.04 → 22.04 → 24.04), Debian, RHEL/Rocky/Alma
  • Windows Server, Active Directory, DNS/DHCP and file services
  • Virtualisation — Proxmox VE, VMware, Hyper-V; container hosts (Docker)
  • In-place and side-by-side OS release upgrades with rollback plans

Enterprise email — Zimbra & open-source mail

  • Zimbra Collaboration 9.x / 10.x (incl. 10.1.x) design, install and upgrades
  • Multi-server topologies: LDAP masters/replicas, proxy, MTA, mailbox, LDS and archive servers
  • Postfix/Dovecot, mail relays, spam and antivirus gateways
  • Microsoft 365 / Google Workspace hybrid, routing and coexistence

Migrations & upgrades

  • Zimbra release and OS migrations (e.g. 9.x on Ubuntu 20.04 → 10.x on Ubuntu 24.04)
  • Adding new LDAP servers, promotion to master, then retiring old LDAP
  • New proxy/MTA nodes with MX, routing and firewall updates
  • Mailbox and archive server build-out, test migrations and decommissioning

Directory, identity & core services

  • OpenLDAP / Zimbra LDAP, AD integration and SSO
  • DNS (authoritative & resolver), SPF/DKIM/DMARC and PTR records
  • Reverse proxies, load balancers, TLS certificates (Let's Encrypt / commercial)
  • Web, database (MySQL/MariaDB, PostgreSQL) and application servers
Reference scope of works

Enterprise mail platform upgrade & migration

A representative scope for upgrading a multi-server Zimbra infrastructure from 9.x on Ubuntu 20.04 to Zimbra 10.1.20 on Ubuntu 24.04, using a side-by-side build so the live platform stays in service throughout. Indicative effort: approximately 20 engineer-days, priced as a fixed-scope project or on a day-rate basis.

01

Add 4 new LDAP servers as replicas of the current directoryPhase 1 · Directory

PHASE 1
02

Promote the new LDAP servers to masters and verify replication health

PHASE 1
03

Upgrade the new LDAP servers to Zimbra 10.1.20 with configuration backups taken first

PHASE 1
04

Remove old LDAP servers and repoint all existing servers to the new masters

CUT-OVER
05

Install new proxy servers on 10.1.20 and validate IMAP/POP/HTTPS proxyingPhase 2 · Edge

PHASE 2
06

Retire old proxy/MTA servers; update MX records, mail routing and firewall rules

CUT-OVER
07

Install the new 10.x LDS server (licence / directory services)Phase 3 · Core

PHASE 3
08

Install 6 new mailbox servers on Zimbra 10.x / Ubuntu 24.04

PHASE 3
09

Install 3 archive servers for retention and discovery

PHASE 3
10

Test migrations with pilot accounts; validate mail flow, calendars, shares and mobile syncPhase 4 · Migrate

PHASE 4
11

Migrate user data — executed by, or jointly with, the client's team using the agreed runbook

PHASE 4
12

Decommission old Zimbra servers once migration is verified and signed offPhase 5 · Close

PHASE 5
13

Fix settings and finalise — global/COS settings, DNS, monitoring, backup jobs, documentation and handover

PHASE 5

Built-in safeguards

  • Full configuration and LDAP backups before each phase
  • Rollback plan and snapshot per server change
  • Change windows agreed in advance; MX TTL lowered ahead of cut-over
  • Pilot-group migration before bulk moves
  • Old servers kept powered-off, not deleted, for an agreed retention period
~20Engineer-days
MinutesDowntime per cut-over, not hours
Next step

Tell us what you run — we'll scope it within one working day

Costed, itemised proposal with milestones, rules of engagement and NDA.