Resources & Insights

Cybersecurity Knowledge
Built for Africa.

Guides, blog posts, awareness materials, and practical tools - all grounded in the African regulatory environment and designed to help your organisation make informed security decisions.

Free Interactive Tool
Kenya DPA 2019 Readiness Check
Answer 12 quick questions, get your instant compliance score, and download a personalised action plan. Takes 2 minutes — no login.
Start the check →
Blog & Insights
GRC & Compliance
Third-Party Vendor Risk Management for Kenyan Enterprises: A Practical Playbook
Your vendors are now your biggest attack surface. Here's how Kenyan enterprises can build a third-party risk management programme that satisfies regulators, protects customer data, and actually works in practice.
August 2026 5 min read →
Security Operations
Building a Security Operations Centre on a Limited Budget: A Practical Guide for East African Enterprises
Most Kenyan mid-market firms assume a Security Operations Centre requires millions of shillings and a dedicated team of twelve. It doesn't. Here's how to build a functional SOC on a lean budget without cutting the corners that matter.
August 2026 5 min read →
Cloud Security
Cloud Security Misconfigurations in AWS and Azure: What African Enterprises Keep Getting Wrong
Most cloud breaches affecting African enterprises don't come from sophisticated attackers — they come from preventable misconfigurations. Here are the specific AWS and Azure mistakes we keep finding across Kenyan banks, telcos, and SaaS firms, and how to fix them before an auditor or attacker does.
August 2026 4 min read →
Security Operations
Building an Incident Response Plan Before Ransomware Hits Your East African Business
Ransomware attacks against African enterprises are climbing, and most victims discover their incident response gaps mid-crisis. This guide walks Kenyan and East African business leaders through building a response plan that actually works when the encryption starts.
July 2026 5 min read →
Awareness & Training
Phishing Simulations: Turning Failed Clicks Into a Stronger Security Culture
A failed phishing simulation isn't a disciplinary event — it's a learning signal. Here's how Kenyan and East African enterprises can build phishing programs that actually change employee behaviour and reduce breach risk.
July 2026 5 min read →
GRC & Compliance
When to Bring in a Virtual CISO: A Guide for Kenyan Mid-Sized Enterprises
Most Kenyan mid-sized enterprises need executive-level security leadership long before they can justify a full-time CISO salary. A virtual CISO closes that gap — here's how to know when it's time to make the call.
July 2026 5 min read →
Weekly Security Tips

Security Awareness Posters
for Your Workplace.

A new security awareness poster every week. Print them, share them on Slack, or post them on your office wall. Click any poster to view it in full, then download it free.

Compliance Guides

In-Depth Guides for
Compliance Decision-Makers.

Comprehensive PDF guides produced by SecureZaidi's compliance specialists. Download or read them directly in your browser — free, no sign-up required.

Kenya DPA 2019 · PDF
The Kenya Data Protection Act Compliance Guide (2025 Edition)
Comprehensive guide covering ODPC registration, lawful bases for processing, all nine data subject rights, DPO obligations, breach notification, cross-border transfer rules, enforcement penalties, and a practical compliance checklist. Essential reading for compliance officers, legal teams, and IT leaders operating in Kenya.
ISO 27001:2022 · PDF
ISO 27001 Implementation Guide for East African Organisations
Step-by-step guide to implementing ISO 27001:2022 — covering gap analysis, ISMS scope definition, risk assessment methodology, Statement of Applicability, all four control themes, mandatory documentation, internal audit, and the certification audit process. Includes realistic timeline and budget guidance for East African organisations.
Security Awareness · PDF
Building a Security-First Culture: A 12-Month Programme Guide
How to design and run a security awareness programme that genuinely changes employee behaviour. Covers month-by-month planning, phishing simulation methodology, departmental deep dives, the Security Champions model, and key performance indicators. All examples are grounded in the East African threat landscape.
GRC · Risk Management · PDF
Cybersecurity Risk Assessment Guide: From Identification to Board Reporting
A practical guide to conducting structured cybersecurity risk assessments — from asset inventory and threat identification through likelihood/impact scoring, risk treatment options, and maintaining your risk register. Includes a dedicated section on translating technical risk into financial language for board-level reporting.
Glossary

Cybersecurity Terms
Explained Simply.

A plain-language glossary of key cybersecurity and compliance terms - useful for non-technical stakeholders, board members, and anyone new to the field.