case study

CyberSentinel.
MSc Research → Live ToolA free, self-guided cybersecurity assessment and training tool for digital-services SMEs in Nairobi — the phone-and-Instagram, M-Pesa-dependent businesses that most cybersecurity guidance ignores. It tells a business owner exactly where they stand across six practical areas, in plain language matched to how technical their business actually is, and gives them a specific, prioritized plan to improve — not a generic checklist.
Research Origin
CyberSentinel grew out of an MSc Information Security thesis at USIU-A: "Design and Validation of a Lightweight Cybersecurity Maturity Assessment Model for Digital Services SMEs in Nairobi County," supervised by Dr. Paula Musuva.
The starting problem: existing cybersecurity frameworks — NIST, ISO 27001, and the like — are built for enterprises with IT departments and dedicated budgets. No cybersecurity maturity model had been validated specifically for resource-constrained, digital-services SMEs in an African context. The study used a sequential mixed-methods design: qualitative interviews first, to understand real SME practice and barriers, followed by a quantitative phase to validate the resulting model at scale.
The 20-Interview Finding
Semi-structured interviews with 20 SME owners, IT managers, and practitioners across Nairobi were thematically analyzed using the Braun & Clarke method, producing 11 consolidated themes — plus 4 additional patterns surfaced on a full-transcript verification pass.
- →
Digital Maturity Divide — A sharp split between tech-savvy and non-technical owners in how they handle security at all.
- →
Financial Constraint — The dominant barrier — named directly by 60% of participants (12 of 20).
- →
Regulatory awareness without compliance — Most had heard of Kenya's Data Protection Act; very few knew their actual ODPC registration status.
- →
M-Pesa STK-push fraud — A cross-sector, recurring fraud pattern nearly every participant recognized on sight.
- →
Social media account loss as an existential risk — For many businesses, losing the Instagram or Facebook account is losing the business.
- →
Talent turnover — Access not revoked when staff leave — surfaced on the full-transcript re-verification pass.
- →
Time and bandwidth constraint — A barrier distinct from money — owners simply don't have the hours, also surfaced on re-verification.
- →
Impersonation / fake-page fraud — Distinct from losing your own account — someone else's page pretending to be you, surfaced on re-verification.
- →
Solo-operator single point of failure — When one person is the whole business, there's no one to catch what they miss — surfaced on re-verification.
The distinctive finding
Self-exclusion belief — a real, if smaller than first thought, belief that "cybersecurity isn't for a business like mine." On full re-verification it traced to 1 confirmed participant, down from an original claim of 3. Small in count, but it became the emotional throughline for the whole product — not just a data point.
What The Model Does
It's not a machine-learning model — it's a structured, rule-based maturity-scoring model, closer in design to CMMI or CIS frameworks. It runs on two independent axes.
- 01
Implementation Tier (A / B / C) — derived from 5 self-classification questions (headcount, IT delivery model, digital footprint, data sensitivity, prior framework exposure), controlling which register of language and which set of expectations apply to that business.
- 02
Maturity Level (0–5) — scored separately per domain, across six domains.
Input — a respondent's answers to the 5 tier-classification questions, plus a battery of agree/disagree statements per domain, scored cumulatively: a level only counts if every level below it is also endorsed, so partial or inconsistent practice can't inflate the score.
Output — a level (0–5) per domain, a weighted composite score across all six (weights are researcher-set starting points, disclosed as provisional rather than empirically fixed), a maturity band label, and a personalized gap-analysis action plan pointing to specific training content.
The D4 Gate
D4 is Awareness & Training — the domain covering whether staff can actually recognize and respond to real threats, not just whether policies exist on paper. It carries the highest weight of the six domains (0.25) and functions as a gate: if a business scores below Level 2 on D4, their overall composite score is capped, regardless of how strong the other five domains look.
"You can't be rated cybersecurity-mature overall if your team would still fall for a basic scam — because that's exactly how most small businesses actually get breached in practice, no matter how good everything else looks on paper."
This is grounded directly in the interview evidence: strong technical controls kept failing in the real stories participants told, specifically because a person — not a system — was the point of failure. Someone entering an M-Pesa PIN into a fake prompt. Someone clicking a convincing link.