How Adili Group's CISO Kiprono Rugut builds digital trust

post-title

When it comes to information security, Kiprono Rugut brings both technical depth and business perspective. His more than two-decade career spans financial technology and legal-sector advisory work before cyber investigations brought him to his current role at Adili Group, where he is chief information security officer (CISO).

A conversation with Kiprono Rugut reveals his passion for cybersecurity and especially investigations. To him, investigations require curiosity and discipline, paired with the ability to connect technical evidence to business context. That mindset has shaped key milestones in his career and helped clients through difficult moments.

One early assignment that is still etched in his memory involved a business email compromise affecting a high-value international transaction. At the time, digital forensics and cyber investigations were still emerging areas in the local market, making the assignment especially significant in his professional journey.

“The matter involved payment instructions that were manipulated during an email conversation between a client and a supplier,” he says.

By the time the client realised what had happened, funds had already been diverted to fraudsters posing as the legitimate supplier. The client then sought the help of Kiprono and his team.

“We supported the investigation by reviewing digital evidence, analysing available technical records and helping the client understand how the compromise occurred. That evidence was then considered alongside other interviews and inquiries,” he says.

Incident response and cyber resilience

The assignment was the first of many such projects, with investigations becoming part of Kiprono’s wider work in cyber risk, digital forensics and incident response.

“We are often called in to support incident response. The first priority is to assess the level of impact, contain the threat if it is still active, and help the client move toward recovery. Once operations are stabilised, the investigation can establish what happened and what needs to change,” he explains.

While Adili Group supports clients during active incidents, Kiprono emphasises that prevention and maturity are more sustainable.

“We prefer to engage early and help build mature cyber risk, identity security, cloud security, fraud risk management and resilience programmes. That is a higher-value advisory conversation than responding only after a crisis has occurred,” he says.

When such programmes are done well, they improve risk visibility, strengthen regulatory confidence and help organisations protect trust while continuing to operate.

Tracing the journey

Kiprono's path into technology began more than two decades ago with a diploma in business IT at Strathmore University. It was there that programming, systems and problem-solving first confirmed his interest in computing.

“At Strathmore, we started with programming languages such as Java and C++, then built up into PHP, MySQL and JavaScript,” he recalls.

“When I started working, I decided to take additional courses, especially around networking, because I wanted to deepen my technical foundation. That exposure also connected me with working professionals who were already active in the technology sector,” he says.

Entry into fintech and legal

Through one of those professional connections, Kiprono joined a financial technology company working with Swift-related financial messaging services. As a software developer, he helped build systems that supported secure transaction workflows, strengthened operational efficiency and reduced turnaround times for banking processes.

“We enabled banks to digitise certain confirmations and make them available through electronic workflows. For branch staff, that meant faster access to customer information, improved turnaround times and a better customer experience,” he says.

In 2013, Kiprono moved into the legal sector, taking on a role that expanded his exposure to advisory work, privacy, governance and risk. Much of the work was advisory, especially after the introduction of the Data Protection Act 2019. The Act, together with the establishment of the Office of the Data Protection Commissioner, sharpened his focus on risk assessment, privacy and governance maturity. This prompted his decision to deepen his knowledge of governance, risk and compliance. At the same time, he contributed to the organisation’s journey toward ISO/IEC 27001 and ISO/IEC 27701 certification, which the firm achieved after three years.

“It was an important milestone for the firm and for my own development in information security, privacy and governance,” he says.

After a decade at the law firm, Kiprono broadened his professional scope and joined Adili Group, where his work now covers security leadership, cyber risk advisory and investigations, helping organisations strengthen their security programmes and protect the trust they've built with customers.

Striking a balance

While Kiprono is deeply engaged in cybersecurity and risk conversations, he also finds balance in farming, nature and conservation.

“I have a dairy farm, and I also farm coffee and tea. My long-term dream is to spend more time farming,” he says.

“I grew up around people who cared deeply about conservation and protection of the environment. I went into corporate work, but I have always loved nature and animals,” he says.

His interest in the environment has seen him grow a small forest on his farm, where he's been restoring biodiversity one season at a time. 

Kiprono is also a wide-ranging reader, with a preference for non-fiction and subjects that connect technology, risk, commerce and science.

“I read across many subjects, especially cyber risk, fraud risk, commerce and digital transactions. I also read a lot on science and computer technology,” he says.

For Kiprono, the common thread across technology, investigations, governance and resilience is trust. He builds it by helping institutions prepare, respond and adapt in an increasingly digital operating environment.

Related articles

How AI is arming cybercriminals, according to four tech leaders

AI has not only made work easier for organisations, but it has also added a layer of complexity when dealing with cybersecurity. Across different conversations, Jacqueline Madara, head of ICT at Machakos University, Yuki Ouchi, head of digital products and e-commerce at KFC Kenya, James Kwezi, digital transformation manager at AFR Rwanda, and Alex Siboe Wekunda, CIO at Stanbic Bank Kenya, weigh in on how AI is reshaping the threat on the other side of the firewall.

Erick Ngwiri unpacks why organisations get data wrong 

Erick Ngwiri has spent 17 years helping organizations turn complex, scattered information into decisions they can act on. Within that time he has seen why most organisations still get data wrong, and what it takes to fix it, one clear problem at a time. 

Ecobank Uganda's Juliet Kyomugisha tackles data governance and cybersecurity

As head of technology services at Ecobank Uganda, Juliet Kyomugisha is at the forefront of the bank's digital transformation and cybersecurity efforts. She oversees technology projects, strengthens governance frameworks, and helps the bank stay ahead of evolving cyber threats. She shares how Ecobank leverages data, manages cybersecurity risks, and balances innovation with security.

Clearer data governance frameworks dominate discussions at CITO Summit

When Ecobank Uganda's Juliet Kyomugisha, Nation Media Group's Russell Akuom and AAR Hospital's Ibrahim Juma took to the stage at the CITO East Africa Data and Cybersecurity Summit to report back from the roundtable sessions, the consistent message was that implementation is the hard part of data governance.

CIOs tackle governance and cyber resilience at CITO Summit 

As CIOS weighed in on topics of data access, governance, cyber security and cyber resilience at the CITO East Africa Data and Cyber Security Summit held at Villa Rosa Kempinski Nairobi, it was apparent that human actors have a bigger role to play than the tech. 

Tech leaders explain why people are cybersecurity's weakest link

Cybersecurity remains one of the biggest challenges that tech leaders grapple with on a daily basis. While companies continue to invest in technology to make their systems robust, Bank of Kigali’s CIO Eveque Mutabaruka, Del Monte’s head of IT Kennedy Njenga and Nairobi Water’s head of IT Jimmy Thuo believe that none of this counts for much if the person sitting behind the keyboard does not understand the risks they are exposed to every single day.

Eveque Mutabaruka leads the transformation in African banking

Bank of Kigali’s CIO Eveque Mutabaruka has built his entire career by stewarding transformation programs in different financial institutions, from Rwanda to Botswana and Kenya. In every program, his leadership philosophy is simple: empower first then follow up.

AFR’s digital transformation manager James Kwezi builds cyber resilience in Rwanda

James Kwezi is on a mission to do more than digitalise; he is securing the future of finance in Rwanda. As digital transformation manager at AFR, he is driving responsible innovation, building cyber resilience and leading the charge on ethical AI. He shares how strategy, vigilance and vision are shaping the next chapter of digital development.

Top