Skip to main content

CybersecurityBuiltfortheWayAfricaGetsAttacked

FortiGate Perimeter | Endpoint Protection | Incident Response

National KE-CIRT/CC detected over 4.5 billion cyber-threat events in Kenya from October to December 2025. 912 addresses exposure across identity, network segmentation, perimeter controls, and endpoints. The FortiGate and FortiAnalyzer architecture shown here was deployed end-to-end for a Kenyan manufacturer.

Request Consultation

Use your company email if you have one — it helps us prepare for your call. Gmail works too.

Technologies in use

FortinetBitdefender GravityZoneCiscoMicrosoft Security
Platforms and standards referenced
ISO/IEC 27001
Microsoft ecosystem
AWS platform
Cisco infrastructure
Fortinet security
Buyer fit and next step

When this service becomes urgent

912 builds cybersecurity around distinct operating layers: Bitdefender GravityZone endpoint protection, FortiGate perimeter controls, identity hardening, VPN discipline, recovery, and incident readiness. Each control has a stated owner, support window, and limit.

Firewall rules have not been audited in years.
Endpoint protection exists but no one reviews risk trends or EDR alerts.
Remote access, passwords, and admin privileges are unmanaged.

Discovery call agenda

Firewall and endpoint baseline (FortiGate + Bitdefender GravityZone), policy cleanup, vulnerability review, identity hardening, EDR alert routing, monitoring cadence, and incident-response escalation.

  1. 1Review current firewall, endpoint tool, and EDR coverage.
  2. 2Identify top exposure paths and compliance pressure (ODPC, CBK, PCI-DSS).
  3. 3Define remediation sprint or Security Shield retainer scope.
Book a discovery call
Why now

What the numbers say about leaving this alone

The question is not whether your perimeter gets probed. It is whether anyone would notice, and how long the gap between the breach and the discovery would run.

  • National KE-CIRT/CC detected 68,726,238 malware threats and 12,115,001 web-application attacks in Kenya during Q3 FY2025–26.

    Communications Authority of Kenya / National KE-CIRT/CC(opens in a new tab)threats detected in Kenya, Q3 FY2025-26

  • In Serianu’s Kenya research, 37% of surveyed organisations experienced a cyber incident in the previous year and 35% rated their resilience as low.

    Serianu(opens in a new tab)Africa Cybersecurity Report — Kenya

  • IBM’s Cost of a Data Breach study reported a mean time of 247 days to identify and contain a breach.

    IBMin IBM's own Cost of a Data Breach study

Enterprise Defense Architectures

Hardware-Accelerated Perimeter

  • SSL/TLS inspection at wire speed
  • 18× GE ports + 10GE SFP+ uplinks, dual power supplies
  • 480GB onboard storage for local logging and forensics

Centralized Intelligence

  • Centralized log aggregation across the estate
  • Security analytics and compliance reporting
  • An audit trail that survives the device that generated it

Zero-Trust & Identity

  • Active Directory / LDAP integration
  • Time-based access restrictions
  • 2FA / MFA enforced at the edge

The Reality of Kenyan Cybersecurity

Over 4.5 billion cyber-threat events detected in Kenya from October to December 2025 (National KE-CIRT/CC).

Legacy firewall and remote-access configurations that have not been reviewed.

Fragmented security tools that don't communicate with each other.

Lack of specialized incident response talent in-house.

Honest Risk Framing

What this protects against — and what it doesn't.

Support covers our configurations, not yours

Post-deployment support covers the rules, policies, and configurations 912 deployed. Major new requirements introduced by your team after handover — new VPN endpoints, new VLAN segments, new SaaS integrations — require a separate scoping engagement.

Endpoint pricing depends on device counts and tier

Endpoint protection (Bitdefender GravityZone) is licensed per device, and the tier matters: not every business needs full EDR. We size the recommendation to your actual risk — not every business needs Enterprise — and surface licence cost transparently so renewals aren't a surprise.

User behavior is outside the firewall's scope

FortiGate can block phishing payloads at the perimeter and GravityZone can isolate compromised endpoints, but neither stops a user voluntarily approving an MFA prompt. Cybersecurity Training engagements layer human-factor mitigation on top of the technical stack.

How a Deployment Actually Runs

The same shape as our delivered FortiGate engagement — including the honest parts most vendors leave off the quote.

Part of the 912 six-phase engagement model — this is how it runs for this service.

01

Audit & Specification

Baseline the current firewall, endpoint, and identity stack. Specify the right appliance for your throughput — with the full cost on the table: licence term, deployment fee, and the renewal OPEX three years out.

02

Procurement & Staging

Honest delivery windows quoted up front — enterprise firewall hardware typically runs about six weeks; virtual appliances like FortiAnalyzer land in days. Configuration is staged while hardware ships.

03

Deployment & Policy Build

Install, segment the network, build the security policies, integrate identity (AD/LDAP, MFA), and wire all telemetry into FortiAnalyzer.

04

Support & Handover

Six months of support on every configuration 912 deploys — security policies and network management included — plus documented policies your team can audit. Ongoing monitoring is available as a separate retainer.

Why 912

Deployed, Not Just Specified

The FortiGate + FortiAnalyzer architecture on this page isn't a brochure diagram — it was deployed end-to-end for a Kenyan manufacturer.

TCO on the Table

Our firewall quotes state the deployment fee, the licence term, and the post-licence renewal cost before you sign — because a perimeter you can't afford to renew in year four is a security incident on a timer.

Layers That Match the Threat

Perimeter (FortiGate), endpoint (Bitdefender GravityZone — independently verified to detect 100% of MITRE ATT&CK attack steps for three straight years), and the human layer (security training) — each covers what the others can't. We're explicit about which layer stops which attack, and which tier of GravityZone your risk profile actually needs.

Buyer decision guides

Compare the deployment model, operating work, lifecycle, prerequisites, and where another option may be the better fit before selecting a product.

All vendor decision guides
Expert Insight

Executive Intelligence

How does 912 secure a Kenyan enterprise network?

With layered, identity-centric architecture: a hardware-accelerated FortiGate perimeter performing SSL/TLS inspection, VLAN segmentation so a breach in one zone can't roam the estate, MFA enforced on administrative and remote access, Bitdefender GravityZone on the endpoints, and all telemetry centralized in FortiAnalyzer for analysis and compliance reporting. 912 deployed this architecture end-to-end for a Kenyan manufacturer, with six months of configuration support included after deployment.

100%MITRE ATT&CK attack-step detection, 3 years runningSource: Bitdefender GravityZone / MITRE Engenuity ATT&CK Evaluations

From the Delivered Engagement

FortiGate 121G + FortiAnalyzer VM, deployed for a Kenyan manufacturer.

Speak to Our Experts
Deployed
End-to-end engagement
3-year
Licence bundle deployed
6 mo
Config support included
TECHNOLOGIES IN USE

Fortinet

Technology in scope

Bitdefender GravityZone

Technology in scope

Cisco

Technology in scope

Microsoft Security

Technology in scope

Common Questions

Everything you need to know about Cybersecurity Built for the Way Africa Gets Attacked.

What does the latest KE-CIRT/CC report show about cyber threats in Kenya?

KE-CIRT/CC reporting shows large volumes of detected threat events across categories such as malware and web-application attacks. Detected events are not the same as successful breaches, and the figures do not identify one universal entry route for every organisation. 912 therefore scopes controls across identity, endpoints, networks, and the perimeter.

Do you offer incident response for ransomware attacks already in progress?

Yes. 912 takes emergency incident-response engagements: we triage, contain, and invoice only on agreed engagement scope. We have recovered an enterprise mid-crisis with full data restoration and rebuilt operating documentation — see the Senegal Factory Rescue case study. Response logistics are confirmed at first contact based on your location and the state of your backups.

Is 912 compliant with the Kenya Data Protection Act 2019?

The Data Protection Act applies to how each organisation collects, uses, protects, retains, and reports personal data. 912 can scope technical controls, data-flow documentation, incident records, and remediation support, but a product or vendor cannot guarantee compliance. Legal duties and reportability decisions remain with the controller or processor and its advisers.

What does 912's security monitoring actually cover?

Endpoint protection alerts, identity events (Active Directory/Azure AD), network telemetry (FortiGate/FortiAnalyzer), email threats, brute-force and port-scan log analysis, Geo-IP blocking, and physical security correlation (CCTV + access) where deployed. Coverage hours and response expectations are set by your Security Shield tier — Basic, Standard, or Premium — and put in writing as part of the retainer.

How much does enterprise cybersecurity cost?

Cost depends on endpoint count, licence edition and add-ons, firewall capacity, implementation scope, monitoring window, reporting cadence, and response responsibilities. The GravityZone licence component starts from KES 1,800 + VAT per endpoint per year for a minimum 15-endpoint paid deployment, but it is bundled into a managed-service quote and is not the complete service price.

Do you do penetration testing?

Yes — internal, external, and web-app penetration testing with a written report and a prioritised, budgeted remediation plan. Scope and duration are agreed per engagement based on the size of the estate and the systems in play.

Where do you operate?

Cybersecurity services across Kenya and cross-border engagements in the wider region, with delivery led from our Nairobi headquarters.

Ready when you are

One contract.
Every technology need.

Book a free 30-minute discovery call. We map your stack, identify duplicate spend, and propose a fixed-price One Contract plan within 5 business days.