FAQ

Frequently Asked Questions

Common questions about how HilSec's cybersecurity services work and how to get started.

Questions & Answers

What Clients Ask Us

We offer a broad range of services spanning offensive security (penetration testing, red team operations, vulnerability assessments, secure code review), managed security and SOC services, cloud and identity security, GRC and compliance, and advisory services such as vCISO and security awareness training. See our Services page for the full list.

Yes. Our Managed Security Services (MSSP) offering includes round-the-clock monitoring, threat detection, and response delivered through our Security Operations Center.

Reach out through our contact form, phone, or WhatsApp with a brief description of the systems or applications you'd like assessed. Our team will follow up to scope the engagement and agree on timing, methodology, and rules of engagement.

We work across sectors including government, banking and finance, healthcare, education, telecommunications, insurance, manufacturing, energy and utilities, retail, NGOs, and technology. See our Industries page for more detail.

Yes. While HilSec is headquartered in Nairobi, Kenya, we support clients across multiple countries and are equipped to engage with organizations internationally.

Our GRC and compliance team has experience aligning organizations to frameworks such as ISO 27001, ISO 22301, NIST CSF, CIS Controls, OWASP, PCI DSS, GDPR, HIPAA, and SOC 2. The right framework depends on your industry and regulatory environment, which we help assess during engagement scoping.

It typically begins with an initial conversation to understand your environment, goals, and constraints, followed by scoping, a proposal, and - once agreed - the start of the engagement itself. You can kick this off any time through our Contact page.

Yes, our Managed Security Services include continuous monitoring, threat hunting, incident response, and digital forensics delivered through our SOC, so your team isn't carrying detection and response entirely on its own.

Yes. Our cloud and identity practice covers cloud security posture, identity and access management, endpoint detection and response, and DevSecOps practices across major cloud providers including AWS, Azure, and Google Cloud.

If you are an existing client experiencing an active incident, contact your engagement team or reach us immediately by phone or WhatsApp at (254) 783 765 395. If you are not yet a client, use our Contact page and mark your message as urgent, and our team will respond as quickly as possible.