Five Cyber Security Habits Every Kenyan Business Should Adopt
Most breaches we investigate did not require sophisticated attacks — they exploited habits that take an afternoon to fix.
Over the past year our team has been called in after a number of security incidents at Kenyan businesses. What stands out is how few of them involved anything sophisticated. In almost every case, the attacker walked through a door that had been left open.
Here are the five habits that would have prevented most of what we have seen.
1. Turn on multi-factor authentication everywhere
Password reuse is universal, and credential lists from breached websites are traded openly. Multi-factor authentication means a stolen password on its own is worthless. Microsoft 365, Google Workspace and most banking platforms include it at no extra cost — it simply needs switching on.
Start with email. An attacker inside a company email account can reset passwords everywhere else, read months of correspondence and intercept invoices.
2. Patch within a fortnight
The vulnerabilities exploited in real attacks are rarely new. They are typically months or years old, with patches long available. Set a standing rule: security updates applied within fourteen days, no exceptions.
3. Back up, then actually test the restore
We have lost count of the businesses who discovered their backups had been silently failing for months — at exactly the moment they needed them. A backup you have never restored from is a hope, not a plan. Schedule a quarterly restore drill and document the result.
4. Verify payment changes by phone
Business email compromise is the most costly attack we see locally. The pattern is consistent: an attacker monitors email traffic, then sends a convincing message asking for bank details to be updated before a large payment.
The defence costs nothing. Any change to payment details gets verified by phone, on a number you already hold — never one supplied in the email requesting the change.
5. Remove access the day someone leaves
Former staff accounts are a standing risk, particularly when the departure was not amicable. Make account deactivation part of the exit checklist, alongside collecting the office keys.
Where to start
If you do only one thing this month, enable multi-factor authentication on email. It is the single highest-value change available to most organisations, and it takes an afternoon.
If you would like a review of where your business currently stands, our team offers a no-obligation security assessment.