Derrick Kyalo
About me
A cybersecurity professional skilled in identifying, exploiting, and reporting security weaknesses across networks, systems, and applications. Uses industry-standard tools and methodologies to simulate real-world cyberattacks, uncover vulnerabilities, and provide actionable remediation steps to strengthen an organization’s overall security posture.
Skills
Work Experience
Education
Projects
Mobile Banking Application – Security Assessment
Performed a comprehensive security assessment of an Android-based mobile banking application, evaluating authentication mechanisms, data handling, API communication, and overall security architecture. Assessed the application against OWASP Mobile Top 10 and Web/API Top 10 standards, identifying vulnerabilities related to insecure communication, improper platform usage, and insufficient input validation. Analyzed potential risks, validated exploitation paths, and provided clear, actionable remediation recommendations to strengthen the application’s security posture and protect sensitive user data.
Ransomware Incident Response Project
Led a full incident response simulation for a large healthcare network hit by a sophisticated ransomware attack affecting three facilities. Identified system encryption, potential exfiltration of 450,000+ patient records, and major operational disruption. Executed containment actions by isolating infected systems, preventing lateral movement, and maintaining critical healthcare operations. Performed eradication by removing ransomware payloads, eliminating persistence mechanisms, and addressing exploited vulnerabilities. Guided recovery efforts through system restoration, validation of EMR integrity, and secure service reactivation. Concluded with actionable lessons learned, recommending improved segmentation, monitoring, access controls, and backup strategies to strengthen organizational resilience.