Skip to content
Nairobi · KenyaFree to read
Technology

Master of Science in Cyber Security

The Master of Science in Cyber Security is a postgraduate programme that prepares professionals for advanced practice in information security, cyber threat management, and digital forensics. The programme combines cyber security theory with practical penetration testing, security architecture, and incident response application.

Core areas include information systems security, network security, software security, digital forensics, penetration testing, security governance, risk management, incident response, cryptography, security policy, research methods, and project. Students engage with both security theory and practical laboratory work through coursework and research.

The programme is offered by Strathmore University as MSc in Information Systems Security through iLabAfrica and the School of Computing and Engineering Sciences, JKUAT through the School of Computing and Information Technology with cyber security courses, and Multimedia University of Kenya as MSc in Computer Science and IT with security content. Public and private universities offer programmes over two academic years through full-time and part-time modes of study.

Students develop competencies in information systems security, network security, software security, digital forensics, penetration testing, security governance, risk management, and incident response. The programme includes coursework, examinations, laboratory work, and a supervised research project.

Strathmore charges approximately KES 704,250/year (KES 1,408,500 total) for information systems security as a private university. JKUAT charges approximately KES 252,500/year (KES 505,000 total) for related computing programmes. Multimedia University charges approximately KES 200,000/year for computer science and IT. Entry requires a Bachelor's degree with First Class or Upper Second Class Honours in computer science, IT, or related disciplines from a recognised university.

Graduates pursue careers as cyber security analysts, penetration testers, security architects, digital forensics examiners, security consultants, and lecturers in cyber security across financial institutions, government agencies, security firms, technology companies, consulting firms, and universities.

Skills Required

  • Information Systems Security and Governance
  • Network Security and Threat Defence
  • Penetration Testing and Vulnerability Assessment
  • Digital Forensics and Incident Response
  • Cryptography and Cryptanalysis
  • Security Risk Management and Compliance
  • Software Security and Secure Coding
  • Security Architecture and Design
  • Research Methods in Cyber Security
  • Academic Writing and Project Research

Key Subjects

  • Information Systems Security and Governance
  • Network Security and Threat Defence
  • Penetration Testing and Vulnerability Assessment
  • Digital Forensics and Incident Response
  • Cryptography and Cryptanalysis
  • Security Risk Management and Compliance
  • Software Security and Secure Coding
  • Security Architecture and Design
  • Research Methods in Cyber Security
  • Project Research

Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)

Specializations

Network Security

Focuses on network security, covering firewalls, IDS/IPS, network defence, secure architecture, and managing network security.

Digital Forensics

Examines digital forensics, covering evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics.

Penetration Testing

Covers penetration testing, covering vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.

Security Governance

Focuses on security governance, covering security policy, compliance, frameworks, ISO 27001, and managing security governance.

Software Security

Examines software security, covering secure coding, application security, SDLC, vulnerability analysis, and managing software security.

Incident Response

Covers incident response, covering incident handling, threat hunting, malware analysis, recovery, and managing security incidents.

Duration
2 years
Public, up to
Ksh 254,100
Private, up to
Ksh 704,250
Job market
Very high

The programme

What you study, how long it takes, and how it is delivered.

Practicalities

Study mode
Full-time, Part-time
Attachment
0 months
Average class
25 students
Award
Masters

What you study

10 subjects
  • Information Systems Security and Governance
  • Network Security and Threat Defence
  • Penetration Testing and Vulnerability Assessment
  • Digital Forensics and Incident Response
  • Cryptography and Cryptanalysis
  • Security Risk Management and Compliance
  • Software Security and Secure Coding
  • Security Architecture and Design
  • Research Methods in Cyber Security
  • Project Research

Modules

12 in the programme
  • Information Systems Security Foundations

    Year 1Semester 13 creditsCore

    Examines security fundamentals, CIA triad, threats, vulnerabilities, risk, security models, and managing information systems security.

  • Network Security and Threat Defence

    Year 1Semester 13 creditsCore

    Covers firewalls, IDS/IPS, network defence, secure architecture, VPNs, and managing network security.

  • Research Methods in Cyber Security

    Year 1Semester 13 creditsCore

    Covers research design, data collection, analysis, security research methods, and conducting cyber security research, preparing students for their project.

  • Cryptography and Cryptanalysis

    Year 1Semester 23 creditsCore

    Examines encryption, decryption, protocols, PKI, key management, cryptanalysis, and managing cryptographic systems.

  • Penetration Testing and Vulnerability Assessment

    Year 1Semester 23 creditsCore

    Covers vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.

  • Digital Forensics and Incident Response

    Year 1Semester 23 creditsCore

    Examines evidence collection, analysis, chain of custody, forensic tools, incident handling, and managing digital forensics and incidents.

  • Software Security and Secure Coding

    Year 1Semester 23 creditsCore

    Covers secure coding, application security, SDLC, vulnerability analysis, OWASP, and managing software security.

  • Security Governance and Risk Management

    Year 2Semester 13 creditsCore

    Examines security governance, policy, frameworks, ISO 27001, compliance, risk assessment, and managing security governance and risk.

  • Security Architecture and Design

    Year 2Semester 13 creditsCore

    Covers security design, defence in depth, zero trust, cloud security, enterprise security, and managing security architecture.

  • Cloud Security and Virtualisation

    Year 2Semester 13 creditsCore

    Examines cloud security models, IaaS, PaaS, SaaS security, virtualisation security, container security, and managing cloud security.

  • Malware Analysis and Threat Intelligence

    Year 2Semester 13 creditsCore

    Covers malware analysis, reverse engineering, threat intelligence, IOCs, threat hunting, and managing malware and threat intelligence.

  • Research Project

    Year 2Semester 26 creditsCore

    Original supervised research project on a cyber security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.

Specialisations

  • Network Security

    Focuses on network security, covering firewalls, IDS/IPS, network defence, secure architecture, and managing network security.

  • Digital Forensics

    Examines digital forensics, covering evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics.

  • Penetration Testing

    Covers penetration testing, covering vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.

  • Security Governance

    Focuses on security governance, covering security policy, compliance, frameworks, ISO 27001, and managing security governance.

  • Software Security

    Examines software security, covering secure coding, application security, SDLC, vulnerability analysis, and managing software security.

  • Incident Response

    Covers incident response, covering incident handling, threat hunting, malware analysis, recovery, and managing security incidents.

A day as a student

A typical day during the MSc in Cyber Security programme combines lectures, laboratory sessions, practical workshops, seminars, and independent study. Sessions cover information systems security, network security, penetration testing, and digital forensics. Information systems security sessions examine security governance, policy, frameworks, ISO 27001, risk management, and managing security governance. Network security sessions cover firewalls, IDS/IPS, network defence, secure architecture, VPNs, and managing network security. Penetration testing sessions cover vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing. Digital forensics sessions cover evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics. Cryptography sessions cover encryption, decryption, protocols, PKI, key management, and managing cryptographic systems. Software security sessions cover secure coding, application security, SDLC, vulnerability analysis, and managing software security. Incident response sessions cover incident handling, threat hunting, malware analysis, recovery, and managing security incidents. Security architecture sessions cover security design, defence in depth, zero trust, cloud security, and managing security architecture. Risk management sessions cover risk assessment, threat modelling, compliance, audit, and managing security risk. Research methods sessions prepare students for their project, covering research design, data collection, and analysis. Laboratory sessions provide hands-on experience with security tools, penetration testing frameworks, forensic software, and network security appliances. Practical workshops provide hands-on experience with Kali Linux, Metasploit, Wireshark, EnCase, and security assessment tools. Seminars and discussion groups provide opportunities for debating current issues in cyber security and emerging threats. Guest lectures from experienced security professionals, ethical hackers, and forensic experts provide practical insights. The programme culminates in a supervised research project on a cyber security topic.

The trade offs

In its favour

  • Very high demand for cyber security professionals with Kenya's digital transformation, fintech growth, cyber threats, and regulatory requirements.
  • Strathmore's MSc ISS is developed with global and local IT security industry key players, providing industry-relevant curriculum.
  • Graduates are eligible for CISSP and CEH professional certifications, enhancing global career prospects.
  • JKUAT offers competitive fees at approximately KES 252,500/year (KES 505,000 total) for related computing programmes.

Against it

  • Strathmore (private) charges KES 1,408,500 total, which is significantly higher than public universities.
  • JKUAT and MMU do not offer a dedicated MSc in Cyber Security, only related programmes with security content.
  • MMU specific cyber security fees not independently verified.
  • Programme requires computer science, IT, or related background, which may limit access for non-related graduates.

What it costs

Tuition at both ends of the market, and how to pay for it.

What it costs, and where

Against 191 technology courses
Public130k to 254k
130k at Multimedia University of Kenya254k at Jomo Kenyatta University of Agriculture and Technology
Private704k to 704k
704k at Strathmore University704k at Strathmore University

Annual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.

The fine print

JKUAT ~254K/yr (jkuat.ac.ke). MMU MSc IT ~130K/yr (eafinder 2019). Strathmore MSc ISS 704K/yr.

HELB postgraduate loans are available for Kenyan students. Strathmore University offers financial aid for eligible students. JKUAT may offer postgraduate bursaries. Some technology companies and security firms may sponsor staff for postgraduate study.

Funding options

  • HELB Postgraduate Loan

  • Strathmore University Financial Aid

  • JKUAT Postgraduate Bursary

Scholarships

3 recorded
  • HELB Postgraduate Loan

    LoanKsh 200,000Kenyan

    Kenyan students pursuing postgraduate studies at recognised universities.

  • Strathmore University Financial Aid

    ScholarshipKsh 300,000Kenyan

    Strathmore University offers financial aid for eligible postgraduate students.

  • JKUAT Postgraduate Bursary

    ScholarshipKsh 100,000Kenyan

    JKUAT offers postgraduate bursaries for eligible students.

Getting in

The grades, the alternatives, and who accredits the award.

What you need

KCSE mean grade
N/A (Postgraduate)
Alternative entry
Strathmore requires First Class (GPA 3.45-4.0) or Upper Second Class (GPA 2.85-3.44) in Computer Science or IT with minimum KCSE C+. JKUAT and MMU require computer science, IT, or related background. Applicants may be required to pass an interview. Contact respective universities for specific admission requirements.

How you are assessed

4 components
  • Coursework and Continuous Assessment

    Coursework30% of the mark

    Continuous assessment through coursework assignments, laboratory reports, security exercises, seminar presentations, and class participation.

  • Written Examinations

    Examination70% of the mark

    Written examinations covering information systems security, network security, cryptography, and digital forensics.

  • Practical and Laboratory Assessment

    Practical30% of the mark

    Practical assessment through penetration testing exercises, forensic analysis, security tool configuration, and demonstrating cyber security skills.

  • Research Project

    Research100% of the mark

    Original supervised research project on a cyber security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.

Accreditation

The programme is accredited by the Commission for University Education (CUE). Strathmore University (private) offers MSc in Information Systems Security through iLabAfrica. JKUAT and Multimedia University of Kenya (public) offer related MSc in Computer Systems, Computer Science, or IT with security content. All programmes meet CUE standards for postgraduate training in cyber security. Graduates are eligible for CISSP and CEH professional certifications.

Accredited by

  • Commission for University Education (CUE)

    Academic accreditationRequired

    Programme accredited by CUE. Strathmore University (private) offers MSc in Information Systems Security through iLabAfrica. JKUAT and Multimedia University of Kenya (public) offer related MSc in Computer Systems, Computer Science, or IT with security content. All programmes meet CUE standards for postgraduate training in cyber security. Graduates are eligible for CISSP and CEH professional certifications.

Where it leads

The roles it opens, and what you leave with.

Where graduates go

6 roles
  • Cyber Security Analyst

    Very high demandKsh 150,000 to Ksh 700,000

    Monitors and analyses security, overseeing threats, vulnerabilities, incidents, response, and managing cyber security operations.

  • Penetration Tester

    High demandKsh 160,000 to Ksh 750,000

    Conducts penetration testing, overseeing vulnerability assessment, ethical hacking, reporting, and managing penetration testing.

  • Security Architect

    High demandKsh 180,000 to Ksh 800,000

    Designs security architecture, overseeing security design, infrastructure, frameworks, and managing security architecture.

  • Digital Forensics Examiner

    Moderate demandKsh 150,000 to Ksh 650,000

    Conducts digital forensics, overseeing evidence collection, analysis, reporting, testimony, and managing digital forensics.

  • Security Consultant

    High demandKsh 170,000 to Ksh 750,000

    Provides security consulting, overseeing advisory, assessment, strategy, implementation, and managing security consulting.

  • Cyber Security Lecturer

    Moderate demandKsh 120,000 to Ksh 500,000

    Teaches cyber security at university or college level, overseeing instruction, research, and academic supervision.

Graduate outcomes

Graduates pursue careers as cyber security analysts, penetration testers, security architects, digital forensics examiners, security consultants, and lecturers in cyber security across financial institutions, government agencies, security firms, technology companies, consulting firms, and universities.

Where these fields lead

8 careers

Tools you will learn

  • Kali Linux

    SoftwarePrimary

    Kali Linux for penetration testing, covering ethical hacking, vulnerability assessment, exploit tools, and managing penetration testing.

  • Metasploit

    Software

    Metasploit for exploit development, covering vulnerability exploitation, payload generation, post-exploitation, and managing exploit testing.

  • Wireshark

    Software

    Wireshark for network analysis, covering packet capture, protocol analysis, network troubleshooting, and managing network security analysis.

  • EnCase

    Software

    EnCase for digital forensics, covering evidence collection, analysis, reporting, chain of custody, and managing digital forensics.

Industry links

Common misconceptions

  • Cyber security is just about installing antivirus software.

    Cyber security covers comprehensive governance, network security, penetration testing, forensics, cryptography, incident response, and risk management beyond just antivirus software.

  • This programme is only for hackers.

    Cyber security skills are valuable for security analysts, architects, consultants, managers, auditors, and educators beyond just hackers.

  • Cyber security is purely technical.

    Cyber security covers both technical and managerial aspects including governance, policy, compliance, risk management, and security awareness.

  • Penetration testing is just about breaking into systems.

    Penetration testing covers comprehensive vulnerability assessment, ethical hacking, exploit development, reporting, and remediation recommendations.

  • Digital forensics is just about recovering deleted files.

    Digital forensics covers comprehensive evidence collection, analysis, chain of custody, forensic tools, legal procedures, and expert testimony.

  • Security governance is just about writing policies.

    Security governance covers comprehensive frameworks, compliance, risk management, audit, strategy, and organisational security leadership.

Related courses

Further reading

Keep this

Fees and entry marks for Master of Science in Cyber Security are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.