Managed IT · Cybersecurity · Fractional CTO — East Africa
Your IT team is 3 people. Your compliance obligations — and your stack — are not.
DT Alpha runs 24×7 managed IT operations across East Africa — for regulated banks and fintechs, for institutions on a data-residency clock, for operators whose stack has outgrown their IT team, and for hospital groups and insurers where uptime means patient safety and claims continuity. Bank-grade NOC from India. Fractional CTO leadership from Nairobi. One rule everywhere: a best practice discovered with one client ships to every client we run.
Auto-plays all four demos in sequence · tap a tab to explore · sound off · data-residency and hospital demos are indicative wireframes
68
bank security controls passed
95%+
transaction success — BOU-licensed PSO
Filed
BOU cyber framework, authored by us
<15 min
SEV-1 response — runbook-backed SLA
Daily
margin & claims views — hospitals & insurers
Self-serve · 90 seconds
Prefer self-serve? Get your IT Readiness Score
Answer 4 quick questions — see your score instantly, before you share anything.
DT Alpha · IT Readiness Score
Know your IT risk in 90 seconds
4 quick questions · Instant teaser score · Full breakdown on unlock
This tool gives you an honest picture of where your organisation stands across operational resilience, compliance readiness, and strategic IT maturity — and routes you to the one next step most relevant to your situation.
Banks · MDIs · SACCOs · PSOsUganda · Kenya · Tanzania · RwandaNigeria · Ghana · SomaliaTelcos · Digital OperatorsHospitals · HealthtechInsurers · Health Schemes
Your teaser score
0/100
Locked in the full report:
—Your three dimension scores — resilience, compliance, maturity
—The one next step matched to your answers — with scope and timeline
—Which regulatory clock applies to your institution
Almost there
Where should we send your personalised readiness summary?
Your details go directly to Venkatram at DT Alpha. No marketing lists. No third parties. One relevant follow-up if your score suggests we can help.
0/100
Indicative self-assessment based on your answers — not a formal audit. Your summary goes directly to Venkatram at DT Alpha; expect one relevant follow-up, nothing more.
01
How We Help You
Banking made us rigorous. That rigor now runs everywhere we work — and every service feeds the others. When a best practice is discovered in a bank NOC, a telco runbook, or a hospital ward system, it ships to every client we run. One playbook, continuously improved, shared by all.
ENTRY · TEST US FIRST
Compliance IT Pulse
The fastest way to understand where you stand — and where the risk is.
Answers in 5 business days · Fixed fee · Remote · Approvable this week
Ghana's CISD 2026 is in force today. Nigeria's CBN localisation circular lands 1 January 2027. Tanzania's BOT Cloud Guidelines prohibit hosting mission-critical systems offshore, and Rwanda's BNR regulation keeps primary data inside Rwanda. The global hyperscalers operate no local region in most of these markets — so "move to the cloud" and "comply with residency" point in opposite directions unless the architecture is deliberately sovereign. We map every workload and its recovery against your regulator's instrument, build the in-country landing zone, run both environments in parallel under 24/7 NOC watch, and cut over with a rehearsed rollback — then hand your regulator an attestation pack structured for direct submission.
—Data-flow map & workload inventory — 10 days
—Residency gap analysis vs your regulator's instrument
—In-country landing zone + rehearsed rollback
—24/7 dual-run monitoring — Bangalore NOC
—Zero-downtime cutover · DR in-country from day one
—Attestation pack — structured for direct submission
Built for telcos — and it works for any operator whose stack has outgrown its IT team: logistics platforms, manufacturers, distributors, SaaS businesses. Most run 5–15 IT vendors, each owning one slice, with no single vendor accountable for the full picture. DT Alpha takes over L1–L3 IT support on Day 1 — no changes, no promises — then builds a ticket-level heat map over 90 days. The runbooks tell you where the pain is. We tell you how to fix it, and only where the data justifies it. Every runbook pattern proven here started life in a regulated bank environment.
—L1/L2/L3 IT support — Day 1
—Ticket run-rate intelligence — 90 days
—Module heat-map: top 20% driving 80%
—Runbook engineering — from Day 1
—SEV-1 under 15 min, SLA-backed
—Data-driven refactoring advisory
T1 · Try Stack Support
T2 · Trust Run-Rate Intel
T3 · Expand Runbooks
T4 · Scale Refactoring
NEW · FOR HOSPITAL GROUPS, HEALTHTECH & INSURERS
INDICATIVE DEMO ABOVE · TAP "HOSPITALS & INSURANCE"
Hospitals & Insurance — Managed IT & Margin Intelligence
Clinical systems that stay up. Departments that know their margins. Claims desks that keep their evidence.
EMR/HMIS & claims-platform support → department margin dashboards → payer, scheme & IRA compliance desk
Hospitals run on two blind spots: legacy clinical systems nobody dares touch, and department-level P&L nobody can see. We support and modernise your EMR/HMIS estate off legacy dependence, build curated margin dashboards so your COO and every head of department see per-service-line performance daily, and run a payer-compliance desk — claims integrity, insurer and scheme requirements, audit evidence attached by default. Patient-data protection (Kenya DPA 2019, Digital Health Act 2025 and regional equivalents) is built in, not bolted on. For insurers and health schemes, the same desk keeps claims platforms up and produces the cyber-governance evidence the IRA now expects — board-approved cyber strategy, incident reporting within regulated windows, audit trail attached to every material event. The discipline is the same one we apply where a central bank is watching — because in your world, patient safety and policyholder trust are.
Across the region, regulators now require regulated workloads — and their recovery — to live in-country. The global hyperscalers operate no local region in most of these markets, so "move to the cloud" and "comply with residency" now point in opposite directions unless the architecture is deliberately sovereign. The deadline is only the trigger: the migration itself is the risk, and we engineer it for zero downtime.
GHANABoG CISD 2026 — in force
In-country hosting applies to regulated workloads now. Board-level cyber expertise mandated; quarterly penetration testing; FICSOC oversight extends to savings & loans, microfinance and fintechs.
STATUS: LIVE — compliance applies today
NIGERIACBN localisation circular (Jun 2026)
Payment-system data localisation with supervisory sanctions stated. The least visible risk is the transition: migrating live transaction data without disrupting rails millions depend on daily.
DEADLINE: 1 JAN 2027
TANZANIABOT Cloud Guidelines (Feb 2026)
Mission-critical systems must be hosted in-country; outsourcing them to foreign data centres is prohibited. Board-commissioned independent cyber audits are on the way under the draft guidelines.
STATUS: BINDING
RWANDABNR cybersecurity regulation
Banks must maintain primary data inside Rwanda and run a documented cybersecurity programme — with the new national instant-payment era raising the bar on integration evidence.
STATUS: IN FORCE
Evidence is the deliverable
A workload physically in-country without a data-flow map, DR-in-country proof and an attestation pack still fails examination. We build the evidence in from day one — the same audit-trail discipline behind our filed BOU cybersecurity framework.
Dual-run economics, made budgetable
The parallel-running window — old and new environments live simultaneously — is where most residency programmes stall. We model it up front, and our Bangalore NOC monitors both environments 24/7 until cutover sign-off.
In-country capacity is an engineering decision
Local data centres and sovereign-cloud regions exist across these markets, with widely varying tiers, connectivity and managed-service depth. Selection belongs in an options paper, priced and risk-profiled — before anything moves.
R0Assess10 BUSINESS DAYS · FIXED SCOPE
✓Full data-flow map and workload inventory
✓Residency gap analysis against your regulator's instrument
✓In-country hosting options paper with cost posture per option
✓Dual-run budget model and board scorecard
✓Read-only discovery — approvable at CIO discretion
R1MigratePER WORKLOAD CLUSTER · 6–10 WEEKS
✓In-country landing zone designed and built
✓Migration runbook with rehearsed rollback
✓24/7 dual-run monitoring by our Bangalore NOC
✓Zero-downtime cutover discipline
✓DR designed in-country from day one
R2Evidence2 WEEKS · BUNDLEABLE INTO R1
✓Regulator-mapped residency attestation pack
✓Hosting attestations and DR-in-country proof
✓Audit-trail format, structured for direct submission
✓Board sign-off deck
✓Hands over into our Compliance Ops Desk for ongoing evidence
Fast to answers. Proven under a regulator's gaze.
DAY 10 · board-ready residency scorecard in your hands
WEEK 6–10 · first workload cluster live in-country
00:00 · customer-visible downtime across the cutover window
95%+ transaction success held live through migration-grade change — on Bank of Uganda-licensed payment infrastructure serving a 50+ institution network, under a completed contract with a penalty-backed SLA.
Where does your institution start? One 15-minute conversation places you on the clock — your regulator, your stack, and a first fixed-scope step you can approve at CIO discretion this week. Every engagement is scoped in that conversation, precisely for your estate and your cutover constraints.
The regulatory clock is running. Institutions that move first choose their cutover window; institutions that wait have one chosen for them. One conversation is all it takes to know which side of that line you are on.
15 minutes this week is enough to place your institution on the clock.
03
Our Proof
DT Alpha served as Fractional CTO and managed IT partner to a Bank of Uganda licensed Payment System Operator — a full production engagement across platform operations, security, and regulatory compliance, serving a 50+ institution network across Uganda.
That discipline travels. The runbooks written for payment switches now run telco and platform stacks, and the same NOC standard extends to hospital EMR and clinical systems. Wherever a best practice is discovered — a bank, a platform, a ward system — it ships to every client we run. Banking is where the rigor comes from; it is not the only place it goes.
68
bank security controls passed (TPSA)
95%+
transaction success — BOU-licensed PSO
Filed
BOU cyber framework — authored by us
<15 min
SEV-1 response — runbook-backed, contracted
24/7
clinical-systems cover — same NOC, same SLA
Cybersecurity Solutions Suite
A regulator-aligned security stack — deployed and operated by us
Regulated institutions are measured on evidence. Through our channel partnership with EVAD, a cybersecurity value-added distributor, and the BluScout security-operations platform, we deploy and run a complete security technology stack — selected to satisfy BOU, BOT, BNR, CBK, CBN and BoG cyber mandates, and operated from our 24/7 NOC with board-ready audit trails.
Unified visibility across logs, network traffic and endpoints, with correlation-driven detection. Deployed in your own cloud VPC or fully on-premise — including air-gapped — so data residency stays within your jurisdiction. RBAC, audit trails and retention controls built in.
Maps to: data-residency & continuous monitoring — BNR residency, BOU FHC local accountability, Ghana CISD, CBN localisation
BluScout
02
Privileged Access Management
Control, broker and record every privileged session with just-in-time access and full session recording. The credential vault and the evidence trail your auditors ask for — provisioned and operated as a managed control.
Maps to: privileged-access control & session evidence — a core requirement of every central-bank cyber framework
SeguraRevBits
03
Identity & Access Management
Single sign-on, adaptive multi-factor authentication and full identity lifecycle governance across your applications. Least-privilege access enforced and evidenced, from joiner to leaver.
Persistent file-level encryption and information-rights management, OS-level screen watermarking, and zero-trust file sharing across cloud and on-premise. Sensitive customer data stays protected, traceable and revocable wherever it travels.
Maps to: customer-data confidentiality & exfiltration control — FATF AML evidence, BOT / BOU data-handling obligations
DataPatrolSealPathFileOrbis
05
Threat Detection & Response
Endpoint detection and response, AI-powered malware and deep-file analysis, an AI-assisted SOC command layer, and continuous internet-exposure visibility. Detect, investigate and contain — with the incident evidence pack ready for the regulator's reporting window.
Breach-and-attack simulation across the MITRE ATT&CK matrix, agentless vulnerability and patch management, application security testing, and asset-exposure management. Proof that your controls actually work — with remediation prioritised by real risk.
Selected to your regulator, deployed by certified engineers, and monitored around the clock from our NOC.
Partnerships & Alliances
Named, on-record partnerships you can diligence
Every platform we deploy sits on a formal, verifiable relationship — signed distribution agreements, published affiliate status, and named delivery partners. Documentation is available for procurement due diligence on request.
CHANNEL PARTNER · SIGNED 2026
EVAD
Cybersecurity value-added distributor — Dubai & Nairobi. Our signed channel agreement covers the OEM security stack we deploy: SIEM, PAM, IAM, DLP, threat detection and continuous validation.
What it means for you: enterprise-grade security tooling at right-sized regional pricing — with one accountable firm deploying and operating it.
SECURITY OPERATIONS PLATFORM
BluScout
SIEM with native network detection & response and network forensics built into the platform. 100+ MITRE ATT&CK detection rules. Deployable in your cloud or fully on-premise for data-residency mandates.
What it means for you: regulator-aligned monitoring evidence — BOU, CBK, BOT, BNR, BoG CISD — operated around the clock from our NOC.
AFFILIATE PARTNER
We deploy and support Zoho One, Zoho Mail and Zoho CRM as the business-suite backbone for hospital and insurance back-offices, SME operators and growing institutions.
What it means for you: licensed right, configured securely, and run under the same runbook discipline as everything else we operate.
04
Who We Serve
Commercial Banks
Central Bank oversight. High regulatory burden. Legacy platform modernisation. BOU / CBK / BoT compliance filing.
Building on regulated rails. Central bank API integration. Compliance-as-code. Fractional CTO leadership.
RUNBOOK IT
Telcos & Complex-Stack Operators
Telecom, logistics, SaaS, manufacturing — any operator with 5–15 IT vendors and no single owner of the full stack. Runbook IT on Day 1, refactoring only where the ticket data says.
NEW · HOSPITALS & INSURANCE
Hospitals, Healthtech & Insurers
EMR/HMIS uptime is patient safety. Department margins are invisible. Claims desks run on manual evidence — while the IRA tightens cyber-governance oversight for insurers. Margin dashboards, clinical-systems and claims-platform NOC cover, and audit evidence by default — bank-grade discipline, shaped for wards and policy books.
Investment & Impact Advisory
Aarthi Ramasubramanian — Co-Founder — brings deep experience in gender-lens investing, blended finance, ESG portfolio management, and climate-smart advisory across East Africa and emerging markets. Her platform, Setuya Afrika, connects impact investors with operators across East and West Africa.
16+ years in regulated fintech platforms across East Africa, Asia, and global SaaS. Currently serving as Fractional CTO at a Bank of Uganda licensed Payment System Operator. Leads DT Alpha brand, client delivery, and the Managed TechOps Run-Rate Model.
VC & Impact Investing specialist with deep experience in gender-lens investing, blended finance, due diligence, and portfolio management across East Africa and emerging markets. Founder of Setuya Afrika — her independent impact investor network and operator-matching platform.
✓Founder: Setuya Afrika — impact investor–operator network
✓Gender-lens investing and blended finance advisory
✓Climate Smart: green finance, ESG portfolio management
✓Investment & Impact Advisory arm at DT Alpha
06
Get In Touch
For Managed IT, Runbook IT, Hospital IT & Digital Transformation