Briefings
Notes on regulation, controls and the things that go wrong.
Written for the person who has to act on it — a head of risk, an IT director, a board member with an uncomfortable question. No gated PDFs.
Data protection · 4 August 2026
What the ODPC actually asks for when it comes knocking
Kenya’s Data Protection Act has been in force since 2019. What the regulator wants to see is narrower, and more boring, than most compliance programmes assume.
6 min read
Continuity · 21 July 2026
Your DR plan has never been tested. Here’s what that costs.
An untested recovery plan is a document, not a capability. The gap between the two is discovered at the worst possible moment, and it is measurable in advance.
6 min read
Security · 2 July 2026
Reading a penetration test report without panicking
A first penetration test report tends to arrive with a red bar chart and a lot of findings. Here is how to work out which ones actually matter this week.
7 min read
Question behind the article
If one of these describes your week, say so.
We would rather have a fifteen-minute call about a specific problem than send you a capability statement.
+254 721 687846 taarifa@techrisk.co.ke