When it comes to information security, Kiprono Rugut brings both technical depth and business perspective. His more than two-decade career spans financial technology and legal-sector advisory work before cyber investigations brought him to his current role at Adili Group, where he is chief information security officer (CISO).
A conversation with Kiprono Rugut reveals his passion for cybersecurity and especially investigations. To him, investigations require curiosity and discipline, paired with the ability to connect technical evidence to business context. That mindset has shaped key milestones in his career and helped clients through difficult moments.
One early assignment that is still etched in his memory involved a business email compromise affecting a high-value international transaction. At the time, digital forensics and cyber investigations were still emerging areas in the local market, making the assignment especially significant in his professional journey.
“The matter involved payment instructions that were manipulated during an email conversation between a client and a supplier,” he says.
By the time the client realised what had happened, funds had already been diverted to fraudsters posing as the legitimate supplier. The client then sought the help of Kiprono and his team.
“We supported the investigation by reviewing digital evidence, analysing available technical records and helping the client understand how the compromise occurred. That evidence was then considered alongside other interviews and inquiries,” he says.
Incident response and cyber resilience
The assignment was the first of many such projects, with investigations becoming part of Kiprono’s wider work in cyber risk, digital forensics and incident response.
“We are often called in to support incident response. The first priority is to assess the level of impact, contain the threat if it is still active, and help the client move toward recovery. Once operations are stabilised, the investigation can establish what happened and what needs to change,” he explains.
While Adili Group supports clients during active incidents, Kiprono emphasises that prevention and maturity are more sustainable.
“We prefer to engage early and help build mature cyber risk, identity security, cloud security, fraud risk management and resilience programmes. That is a higher-value advisory conversation than responding only after a crisis has occurred,” he says.
When such programmes are done well, they improve risk visibility, strengthen regulatory confidence and help organisations protect trust while continuing to operate.
Tracing the journey
Kiprono's path into technology began more than two decades ago with a diploma in business IT at Strathmore University. It was there that programming, systems and problem-solving first confirmed his interest in computing.
“At Strathmore, we started with programming languages such as Java and C++, then built up into PHP, MySQL and JavaScript,” he recalls.
“When I started working, I decided to take additional courses, especially around networking, because I wanted to deepen my technical foundation. That exposure also connected me with working professionals who were already active in the technology sector,” he says.
Entry into fintech and legal
Through one of those professional connections, Kiprono joined a financial technology company working with Swift-related financial messaging services. As a software developer, he helped build systems that supported secure transaction workflows, strengthened operational efficiency and reduced turnaround times for banking processes.
“We enabled banks to digitise certain confirmations and make them available through electronic workflows. For branch staff, that meant faster access to customer information, improved turnaround times and a better customer experience,” he says.
In 2013, Kiprono moved into the legal sector, taking on a role that expanded his exposure to advisory work, privacy, governance and risk. Much of the work was advisory, especially after the introduction of the Data Protection Act 2019. The Act, together with the establishment of the Office of the Data Protection Commissioner, sharpened his focus on risk assessment, privacy and governance maturity. This prompted his decision to deepen his knowledge of governance, risk and compliance. At the same time, he contributed to the organisation’s journey toward ISO/IEC 27001 and ISO/IEC 27701 certification, which the firm achieved after three years.
“It was an important milestone for the firm and for my own development in information security, privacy and governance,” he says.
After a decade at the law firm, Kiprono broadened his professional scope and joined Adili Group, where his work now covers security leadership, cyber risk advisory and investigations, helping organisations strengthen their security programmes and protect the trust they've built with customers.
Striking a balance
While Kiprono is deeply engaged in cybersecurity and risk conversations, he also finds balance in farming, nature and conservation.
“I have a dairy farm, and I also farm coffee and tea. My long-term dream is to spend more time farming,” he says.
“I grew up around people who cared deeply about conservation and protection of the environment. I went into corporate work, but I have always loved nature and animals,” he says.
His interest in the environment has seen him grow a small forest on his farm, where he's been restoring biodiversity one season at a time.
Kiprono is also a wide-ranging reader, with a preference for non-fiction and subjects that connect technology, risk, commerce and science.
“I read across many subjects, especially cyber risk, fraud risk, commerce and digital transactions. I also read a lot on science and computer technology,” he says.
For Kiprono, the common thread across technology, investigations, governance and resilience is trust. He builds it by helping institutions prepare, respond and adapt in an increasingly digital operating environment.





