Our Security Operations Centre watches your environment around the clock — detecting, triaging and responding to threats so your team can run the business with confidence. Purpose-built for Kenyan banks, microfinance institutions, SACCOs and enterprise.
Our Security Operations Centre watches your environment around the clock — detecting, triaging and responding to threats so your team can run the business with confidence. Purpose-built for Kenyan banks, microfinance institutions, SACCOs and enterprise.
What to expect
A clear, predictable engagement
01
Discovery workshop to map your environment, crown-jewel assets and current tooling.
02
Onboarding of log sources, EDR agents and cloud telemetry into our detection platform.
03
Baseline tuning to suppress noise and align detections to your risk profile.
04
Go-live with 24/7 monitoring, defined SLAs, and a named customer success lead.
05
Continuous improvement: monthly threat reports, tabletop exercises and detection updates.
Benefits
What you gain
24/7 Visibility
Eyes-on-glass every minute, including weekends and Kenyan public holidays.
Rapid response
Defined SLAs for triage, containment and customer notification.
Threat hunting
Proactive hunts using current TTPs and threat intelligence.
Reduced dwell time
Catch intrusions early — before they become incidents.
Audit-ready reporting
Evidence packs and dashboards aligned to CBK, SASRA and ISO 27001.
Local accountability
A Nairobi-based team that picks up the phone — not a faceless ticket queue.
Who is this for?
Built for regulated institutions
Mid to large institutions with regulated log-retention requirements and complex environments that span on-prem, cloud and remote endpoints.
Why Market Light
Deep local expertise, world-class tech
We deliver detections built on the MITRE ATT&CK framework and operated by analysts who have responded to real ransomware, business email compromise and insider events at Kenyan institutions.
Pricing: Contact us for a scoped quotation
FAQ
Frequently asked questions
A SOC continuously collects security telemetry from endpoints, servers, network devices and cloud platforms, correlates it for malicious patterns, and responds to confirmed incidents. For a Kenyan bank it also produces audit evidence for the Central Bank and supports fraud and AML teams when account-takeover or insider misuse is suspected.
Our standard SLAs are: critical alerts triaged within 15 minutes, containment actions initiated within 1 hour, and an incident report within 24 hours. Faster SLAs are available for higher tiers.
No. We extend them. The SOC handles 24/7 detection and triage, while your internal team retains ownership of business decisions, change management and stakeholder communication.
We support major EDR (CrowdStrike, Microsoft Defender, Kaspersky), SIEM (Rapid7 InsightIDR, Microsoft Sentinel), firewalls (Fortinet, Cisco, Palo Alto), cloud (Azure, AWS, GCP) and identity providers (Entra ID, Okta).
Our analysts are based in Nairobi with a follow-the-sun escalation model for overnight cover, so customer data stays within reputable jurisdictions and on platforms compliant with Kenyan data-protection law.