Skip to main content
Loyca

LOYCA LIMITED · INTELLIGENCE WITHOUT LIMITS

Intelligence Without Limits

Cybersecurity advisory, audit, testing and training for organisations that cannot afford to guess.

DEFENSE: ACTIVE
33 PROTOCOLS
COMPLIANCEGDPR & ISO 27001
SIGNAL TELEMETRY0ms LATENCY

PRACTICE AREAS & PORTFOLIO

Eight practice areas, one engagement sequence

Advise, audit, test, build, govern, watch, train, innovate. Most work starts at the top of that list and moves down.

33 Services Portfolio across 8 Hubs
RADIAL ASSURANCE ENGINE

Continuous Security Lifecycle

Continuous Signal · No Endpoint
PHASE01Advise

Click any station to explore the continuous security pipeline

01PHASE 1 OF 8 · Advise
5 Services

Advisory & Consulting

Strategy & Risk Appetite

Most security spend goes wrong at the decision, not the implementation. Our advisory work sets the strategy, the risk appetite, and the roadmap before a single tool is bought — so the money you spend next quarter solves a problem you actually have.

WHY THIS MATTERS IN THE CYCLE

Strategy, board-level guidance, and the security decisions that shape everything downstream.

Why Loyca

Why clients call us

A high-precision cybersecurity partner built for organizations with zero tolerance for security blindspots.

0% FLUFF / 100% DEPTH

Regulator-aware from day one

GDPR, ISO 27001, PCI DSS and your own sector's supervisory expectations are built into how we scope work — not bolted on at the audit.

Direct Senior Lead Engagement
Regulatory Readiness100% ALIGNED

Advisory through to execution

The same team that writes your policy can test your application, stand up your SOC, and train the staff who will run it.

Cross-Jurisdiction Compliance Expertise
POSTURE MONITOR24/7 CONTINUOUS
ZERO ENDPOINT GAPACTIVE

Findings you can act on

Every engagement ends with prioritised, costed remediation your engineers can start on Monday — not a 90-page PDF nobody opens.

No Blindspots. Ongoing Protection.

Most requested

Six high-impact starting points representing where 90% of our enterprise and institutional clients initiate their cybersecurity journey.

01Advisory
2–4 weeks

Cybersecurity Advisory

Know where you stand before you spend

Independent guidance on where your real risk sits, what to fix first, and what not to buy.

NIST CSF 2.0ISO/IEC 27001:2022CIS Controls v8
04Audit
3–5 weeks

Cybersecurity Audit

Do your controls do what you think they do?

Control-by-control audit of your security programme against ISO 27001, NIST CSF, or sector regulator guidance.

ISO/IEC 27001:2022NIST CSF 2.0SWIFT Customer Security Programme
05Testing
1–2 weeks

Vulnerability Assessment

Find it before someone else does

Authenticated and unauthenticated scanning across your estate, with findings validated by hand.

CVSS v4.0OWASPPCI DSS 4.0 req. 11
10Training
Initial programme 2–4 weeks

Cybersecurity Awareness Training

Change behaviour, not just completion rates

Organisation-wide awareness programmes with phishing simulation, measured by behaviour rather than attendance.

NIST SP 800-50r1ISO/IEC 27001:2022 A.6.3
11Engineering
2–5 weeks

AI Security

Securing the systems you are now building with LLMs

Threat modelling and testing for AI features: prompt injection, data leakage, agent permissions, and model supply chain.

OWASP Top 10 for LLM ApplicationsNIST AI RMF 1.0ISO/IEC 42001
19Governance
4–10 weeks

Data Protection & Privacy

Data protection law, handled properly

Compliance with the GDPR and equivalent privacy law: mapping, DPIAs, notices, subject rights, and supervisory authority registration.

GDPRISO/IEC 27701GDPR

Need advice on where your programme should start?

Our principal advisors will review your context in a 30-minute scoping call at no cost.

Sectors

Security shaped by your obligations

Security Readiness by Sector

SELECT YOUR INDUSTRY
MANDATORY OBLIGATIONS AUDITED
PCI-DSS v4.0PSD2 / Open BankingGDPR
PRIMARY THREAT VECTOR

API security flaws, payment gateway fraud, instant breach disclosure deadlines.

RECOMMENDED FIRST ENGAGEMENT

Fintech Security & Application Pentesting

Insights

Recent writing

Intelligence Without Limits

Bring a problem. Leave with a view on what to do about it.

We reply to enquiries within one business day. A direct, confidential scoping call before any engagement — at no cost.

Direct Hotline:+254 740 658 068
NO-OBLIGATION GUARANTEE

What to expect in your scoping call

  • Direct Senior Lead

    You talk to a seasoned cybersecurity consultant, never a sales script.

  • Strict Confidentiality

    We operate under mutual NDA before discussing sensitive architecture.

  • Actionable Next Steps

    Immediate priorities and costed options, whether you engage us or not.

Message Loyca on WhatsApp