How mobile-money phishing adapts to local languages
A breakdown of regional SMS-phishing kits and the tells that give them away.

Jamii Salama Kidigitali
We protect human rights defenders, journalists, institutions, and governments across the continent from the threats that follow power, data, and ambition.
What We Do

Our analysts track threats targeting African institutions, journalists and civil society, and turn that intelligence into controls you can act on this week.

When something goes wrong, a single desk takes ownership: triage, containment, forensics and recovery, in your language and your time zone.

Security lasts when your people own it. We run cadre-specific training so teams can keep themselves safe long after we leave.
Testing approaches
Full knowledge of systems and source. The deepest coverage, ideal for critical applications and pre-release reviews.
Partial knowledge, such as a user account. A realistic view of what an insider or compromised account could reach.
No inside knowledge. We test as an external attacker would, from the internet inward.
What we deliver
Independent review of policy, process and technical controls.
Continuous discovery, ranking and tracking of weaknesses.
Hands-on help closing the findings that matter most.
Proactive search for attackers already inside your network.
Evidence-grade investigation of devices, accounts and logs.
Round-the-clock detection and alert triage.
Realistic campaigns that measure and improve staff resilience.
Hardening of endpoints, cloud accounts and networks.
Practical security policy that people actually follow.
Plain-language risk reporting for boards and leaders.
Ongoing campaigns that build everyday security habits.
Clear findings with evidence, severity and fix guidance.
Sector expertise
Protecting citizen data, critical services and institutional communications.
Defending payments, agents and customers against fraud and account takeover.
Securing networks, subscriber data and the platforms millions depend on.
Safeguarding defenders, journalists and sources from targeted surveillance.
Managed security
Monitoring and rapid response delivered by our analyst desk.
Senior security leadership on a part-time, predictable basis.
Scoped, safe attack simulation with a clear remediation path.
Architecture, policy and programme advice for your context.
Compliance
Readiness for the Tanzania Personal Data Protection Act and regional equivalents.
Gap analysis and preparation for an information security management system.
Scoping and controls for organisations that handle card payments.
Control design and evidence preparation ahead of an audit.
Assessments
Internal and external infrastructure.
Web, mobile and API testing.
Configuration and identity posture.
Office and field network exposure.
Phishing, vishing and physical pretexts.
Goal-driven, multi-stage adversary simulation.
Hardening of phones and laptops at risk.
Why TDSS
Every decision starts with real threat intelligence on the African landscape, not generic playbooks.
We protect the people behind the systems: defenders, journalists, institutions and teams.
Analysts who know your context, available in your language and your time zone.
We train your people so resilience stays with you long after the engagement ends.
How we work
We map your risks, exposure and the threats most likely to target you.
We harden systems, devices and habits with practical, prioritised controls.
Our incident response desk is on call around the clock when something goes wrong.
We equip your team with the skills to stay secure on their own.
Who We Serve
Surveillance, device compromise, and exposure of your contacts are daily risks. TDSS helps you operate safely in the field.
Learn more →Phishing, insider threats, and weak data-handling policy put citizen data and procurement at risk. TDSS hardens the public sector.
Learn more →Transaction fraud, social engineering, and compliance pressure threaten institutions and their customers alike.
Learn more →Industrial cyber threats, OT security gaps, and espionage risk put operations and IP at stake.
Learn more →Donor-data exposure, partner-communication interception, and grant-related fraud are persistent risks.
Learn more →Source protection, secure drop systems, doxxing prevention, and surveillance defence are mission-critical.
Learn more →Password hygiene, safe browsing, mobile security, and scam awareness keep your money and identity safe.
Learn more →Endpoint security, employee awareness, and incident-response planning protect revenue and reputation.
Learn more →Latest Intelligence
A breakdown of regional SMS-phishing kits and the tells that give them away.
A pre-departure checklist for defenders and journalists crossing borders.
What our 2026 sector assessment found about operational-technology exposure.
Case Studies
In the field
Hands-on workshops that give activists and human rights defenders the skills to stay safe online, delivered together with partners such as AHRN. Includes the May 2024 exchange workshop for digital rights activists from East Africa, held in Dar es Salaam.
Our partners
We work closely with institutions and companies across the region, including:
FAQ
Government bodies, financial institutions, telecoms, media and civil society organisations across Africa.
Yes. Our incident response desk is staffed 24/7. Use the Report incident page and an analyst will pick it up.
Yes. Our services and training are delivered in English, Swahili and French.
With a security assessment. It maps your risks and gives you a prioritised plan you can act on.
Talk to a TDSS analyst and find out where your organisation stands.