Aisle of glowing server racks in a data centre

Cyperace Group · Enterprise technology · Kampala, Uganda

Build it once.Secure it properly.Keep it running.

We design, secure, operate, and maintain the systems your customers, your teams, and your critical services depend on.

Where our capabilities operate across the framework

NIST CSF 2.0 · NIST CSWP 29
Choose a framework function

Framework intent

The organization’s cybersecurity risk strategy, expectations, and policy are established, communicated, and monitored.

What we do here

Governance, risk, and control improvement programmes that make policy and ownership explicit rather than assumed.

Framework intent

The organization’s current cybersecurity risks are understood.

What we do here

Application, infrastructure, and vulnerability assessment across the estate you actually operate, not an idealised diagram of it.

Framework intent

Safeguards to manage the organization’s cybersecurity risks are in use.

What we do here

Network and firewall design, hardened cloud architecture, security engineered into software from the first design decision, and staff awareness training.

Framework intent

Possible cybersecurity attacks and compromises are found and analyzed.

What we do here

Security monitoring alongside infrastructure monitoring, alerting, and operational reporting, so a signal has somewhere to arrive.

Framework intent

Actions regarding a detected cybersecurity incident are taken.

What we do here

Incident response planning, rehearsal exercises, and technical support during an incident, with escalation paths agreed in advance.

Framework intent

Assets and operations affected by a cybersecurity incident are restored.

What we do here

Backup, disaster recovery, and business continuity engineering, maintained and tested under a standing support programme.

The operating context · each figure keeps its publisher’s stated scope

31%

of breaches began with vulnerability exploitation in Verizon’s global 2026 dataset.

Verizon 2026 DBIR

96%

4G population coverage in Uganda, while GSMA still identifies a substantial usage gap.

GSMA Uganda report, 2025

577.5

out of 900: Uganda’s communications-sector security rating, classed as basic with elevated risk.

UCC FY 2024/25 report

Inside the engagement

You see the same evidence we do.

Every capability reports through an operating console. Scope, coverage, ageing exposures, and the improvement backlog stay visible between reviews instead of arriving as a slide at the end of a quarter.

Illustrative interface previews with sample data — not customer data

Choose a console to preview
Security console · exposure — illustrative interface preview CYPERACE CONSOLE MONITOR Overview Exposure 312 Assets Controls Incidents 4 REPORT Evidence pack Service review SCOPE Primary estate Branch network Cloud accounts OP Operations Security / Exposure PRIMARY ESTATE LAST 30 DAYS SEARCH CVE OPEN CRITICAL 41 +6 MEDIAN AGE 6.4 days KEV-FLAGGED 12 +2 CISA CATALOG MATCH CONTROL COVERAGE 93.7% +0.4 1,284 OF 1,366 ASSETS Critical exposures SEVERITY: CRITICAL STATUS: OPEN + ADD FILTER EXPORT IDENTIFIER ASSET SEVERITY AGE OWNER REMEDIATION CVE-2026-1183 edge-gw-01 CRITICAL 92 d KM In review CVE-2026-0947 core-db-02 CRITICAL 61 d AT Patch window 14 Aug CVE-2025-8812 vpn-node-03 CRITICAL 44 d KM Vendor fix pending CVE-2026-1420 app-web-11 HIGH 28 d JN Patch window 09 Aug CVE-2026-1377 app-web-07 HIGH 26 d JN Awaiting change approval CVE-2025-9004 file-srv-02 HIGH 19 d AT Risk accepted · review 30 Sep CVE-2026-1502 edge-gw-02 HIGH 12 d KM Patch window 09 Aug CVE-2026-1611 print-srv-01 MEDIUM 9 d Unassigned CVE-2026-1655 app-api-04 MEDIUM 5 d JN Queued CVE-2026-1702 mail-gw-01 MEDIUM 3 d AT Queued 1–10 OF 312 SYNCED 4 MIN AGO · ILLUSTRATIVE INTERFACE PREVIEW

The exposure queue: what is open, how long it has been open, who owns it, and when the fix lands.

Evidence on this screen

  • Asset and control coverage
  • Critical exposure ageing
Operations console · service health — illustrative interface preview CYPERACE CONSOLE OPERATE Service health Alerts 3 Changes 7 Capacity Backup & restore ESTATE Data centre Cloud accounts Network & edge End-user compute ON CALL KM Primary AT Escalation OP Operations Operations / Service health ALL REGIONS ROLLING 30D SEARCH SERVICE OBJECTIVE ATTAINMENT 99.94% MET TARGET 99.90% ERROR BUDGET LEFT 62% OPEN ALERTS 3 of 148 nodes 1 SUPPRESSED IN CHANGE WINDOW LAST TESTED RESTORE 6 d PASS CORE-DB-01 · 41 MIN Business services TIER 1 AND TIER 2 + ADD FILTER NEW REVIEW SERVICE TIER ATTAINMENT 30-DAY TREND P95 LAST RESTORE STATE Core banking 1 99.98% 28 ms 4 d · pass Healthy Payment gateway 1 99.91% 34 ms 6 d · pass Healthy Branch network 2 99.62% 96 ms 9 d · pass Degraded 2 SITES Citizen portal 2 99.95% 52 ms 11 d · pass Healthy Data warehouse 3 99.87% 118 ms 23 d · due Healthy Field service app 3 99.93% 61 ms 8 d · pass Healthy Approved change windows NEXT 14 DAYS 09 AUG · 22:00 Edge gateway firmware CAB APPROVED Ready 14 AUG · 01:00 Core database patch set AWAITING SIGN-OFF Blocked SHOWING 6 OF 41 SERVICES SYNCED 2 MIN AGO · ILLUSTRATIVE INTERFACE PREVIEW

Objective attainment per business service, what is degraded right now, and when each service was last restored from backup.

Evidence on this screen

  • Service objective attainment
  • Lifecycle and monitoring coverage
  • Backup and tested restore results
Delivery console · release detail — illustrative interface preview CYPERACE CONSOLE DELIVER Backlog Releases Environments Test evidence Threat model PRODUCT Field service app Branch portal Integration layer ENVIRONMENTS Production v2.7.1 Staging v2.8.0 Candidate 2481 OP Operations Releases / Build 2481 GATE HELD VIEW ARTEFACTS ROLLBACK PLAN COMMIT a7f39c2 14 FILES · 2 SERVICES TESTS PASSED 514 / 514 COVERAGE 81.4% OPEN FINDINGS 2 REVIEW BOTH DEPENDENCY ADVISORIES ROLLBACK REHEARSED Yes STAGING · 07 AUG · 3m 20s Pipeline TOTAL 11m 42s STAGE RESULT DURATION STARTED GATE Build and package Succeeded 1m 04s 08:12:03 AUTOMATIC Unit and contract tests 418 passed 2m 51s 08:13:07 AUTOMATIC Integration tests 96 passed 4m 18s 08:15:58 AUTOMATIC Security review 2 findings to triage 3m 29s 08:20:16 HELD FOR REVIEW Deploy to staging Queued BLOCKED BY GATE Release to production Queued MANUAL APPROVAL Security review findings GHSA-4x7q-9v2f Transitive parser advisory TRIAGE GHSA-8m3p-1kdc Outdated crypto helper TRIAGE Broken access control suite 0 OPEN OWNER: JN · DUE BEFORE STAGING Journey steps · staging Session start 4,182 100% Identity verified 3,801 90.9% Job sheet submitted 3,428 81.9% Confirmed while offline 3,094 73.9% ILLUSTRATIVE INTERFACE PREVIEW

A candidate build held at the security gate — stage durations, the findings blocking it, and the rollback that was rehearsed.

Evidence on this screen

  • Release quality and rollback readiness
  • Journey completion and performance
  • Authorization and security test results
Support console · ticket queue — illustrative interface preview CYPERACE CONSOLE SUPPORT Queue 38 Problems 6 Requests Assets Licences PLAN Maintenance calendar Improvement backlog 9 Service reviews QUEUE FILTERS Breaching soon 4 Unassigned 2 Awaiting customer 7 OP Operations Support / Queue ALL SERVICES THIS WEEK SEARCH TICKETS MEAN TIME TO DETECT 4m 12s TARGET 10m · MET MEAN TIME TO RESTORE 38m 05s TARGET 45m · MET SLA BREACHES 1 THIS WEEK BRANCH NETWORK · P2 REPEAT INCIDENTS 8 −6 DOWN FROM 14 LAST MONTH Open tickets SORT: SLA REMAINING + ADD FILTER NEW TICKET REF SUMMARY PRIORITY SLA LEFT ASSIGNEE STATE INC-4471 Branch link flapping · 2 sites P1 14m KM Investigating INC-4468 Payment gateway latency spike P1 41m AT Mitigating INC-4459 Restore drill failed · legacy ERP P2 3h 20m AT Root cause REQ-2210 Licence reconciliation · Q3 P2 1d 04h JN In progress INC-4452 Print server queue stalling P3 2d 11h Unassigned INC-4447 Mailbox delegation errors P3 3d 02h KM Awaiting customer REQ-2204 Laptop refresh · 12 devices P3 5d 08h JN Scheduled Improvement backlog REVIEWED MONTHLY · NEXT 29 AUG Close monitoring gaps on branch links FROM INC-4471 KM P1 · OPEN Re-run restore drill for legacy ERP FROM INC-4459 AT P1 · OPEN SHOWING 7 OF 38 TICKETS ILLUSTRATIVE INTERFACE PREVIEW

The live queue sorted by time left against service level, and the improvement backlog each incident fed into.

Evidence on this screen

  • Detection and restoration performance
  • Repeat incidents and problem closure
  • Service objective and change performance
Abstract visualization of protected network traffic

Solution showcase

A risk-based security programme for a multi-branch organization

An illustrative operating model for finding exposed assets, prioritizing actively exploited vulnerabilities, coordinating maintenance windows, and reporting residual risk.

Illustrative capability scenario — an evidence-led approach, not a claimed client engagement or customer outcome.

Delivery governance

A visible path from uncertainty to operation.

Each phase can stand alone or form part of a wider programme. Decisions and evidence carry forward instead of disappearing between suppliers.

  1. 01

    AssessWe start with your reality

    A structured review of your estate, goals, evidence, and gaps across security, infrastructure, and software, ending in a prioritized roadmap.

  2. 02

    DesignAgree the blueprint

    Architecture, risk, service expectations, acceptance evidence, scope, and commercial assumptions are reviewed before delivery begins.

  3. 03

    DeliverBuild, secure, deploy

    Dedicated engineers and security specialists deliver in working increments, quality-gated at every stage against the agreed plan.

  4. 04

    OperateRun and improve

    Monitoring, maintenance, support, reporting, and improvement continue against the service model agreed for the engagement.

Why Cyperace

Accountability built into the operating model.

About the group

One accountable team

We build, secure, and run your systems ourselves. No hand-offs between vendors — every engagement has a single team that owns the outcome end to end.

Built for your environment

We account for connectivity, power, regulatory, device, and operating constraints instead of assuming every environment behaves the same way.

Security first

Security is the foundation everything inherits, never a bolt-on. Compliance and resilience are engineered in from the first design decision.

Transparent SLAs

Service scope, response expectations, escalation paths, exclusions, evidence, and review cadence are agreed before operations begin.

Start with your context

Bring us the operating problem, the evidence, and the constraints.

We will help you frame the current state, identify priorities, and define what a credible next step should include.