Master of Science in Cyber Security
The Master of Science in Cyber Security is a postgraduate programme that prepares professionals for advanced practice in information security, cyber threat management, and digital forensics. The programme combines cyber security theory with practical penetration testing, security architecture, and incident response application.
Core areas include information systems security, network security, software security, digital forensics, penetration testing, security governance, risk management, incident response, cryptography, security policy, research methods, and project. Students engage with both security theory and practical laboratory work through coursework and research.
The programme is offered by Strathmore University as MSc in Information Systems Security through iLabAfrica and the School of Computing and Engineering Sciences, JKUAT through the School of Computing and Information Technology with cyber security courses, and Multimedia University of Kenya as MSc in Computer Science and IT with security content. Public and private universities offer programmes over two academic years through full-time and part-time modes of study.
Students develop competencies in information systems security, network security, software security, digital forensics, penetration testing, security governance, risk management, and incident response. The programme includes coursework, examinations, laboratory work, and a supervised research project.
Strathmore charges approximately KES 704,250/year (KES 1,408,500 total) for information systems security as a private university. JKUAT charges approximately KES 252,500/year (KES 505,000 total) for related computing programmes. Multimedia University charges approximately KES 200,000/year for computer science and IT. Entry requires a Bachelor's degree with First Class or Upper Second Class Honours in computer science, IT, or related disciplines from a recognised university.
Graduates pursue careers as cyber security analysts, penetration testers, security architects, digital forensics examiners, security consultants, and lecturers in cyber security across financial institutions, government agencies, security firms, technology companies, consulting firms, and universities.
Skills Required
- Information Systems Security and Governance
- Network Security and Threat Defence
- Penetration Testing and Vulnerability Assessment
- Digital Forensics and Incident Response
- Cryptography and Cryptanalysis
- Security Risk Management and Compliance
- Software Security and Secure Coding
- Security Architecture and Design
- Research Methods in Cyber Security
- Academic Writing and Project Research
Key Subjects
- Information Systems Security and Governance
- Network Security and Threat Defence
- Penetration Testing and Vulnerability Assessment
- Digital Forensics and Incident Response
- Cryptography and Cryptanalysis
- Security Risk Management and Compliance
- Software Security and Secure Coding
- Security Architecture and Design
- Research Methods in Cyber Security
- Project Research
Certifications
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
Specializations
Network Security
Focuses on network security, covering firewalls, IDS/IPS, network defence, secure architecture, and managing network security.
Digital Forensics
Examines digital forensics, covering evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics.
Penetration Testing
Covers penetration testing, covering vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.
Security Governance
Focuses on security governance, covering security policy, compliance, frameworks, ISO 27001, and managing security governance.
Software Security
Examines software security, covering secure coding, application security, SDLC, vulnerability analysis, and managing software security.
Incident Response
Covers incident response, covering incident handling, threat hunting, malware analysis, recovery, and managing security incidents.
- Duration
- 2 years
- Public, up to
- Ksh 254,100
- Private, up to
- Ksh 704,250
- Job market
- Very high
The programme
What you study, how long it takes, and how it is delivered.
Practicalities
- Study mode
- Full-time, Part-time
- Attachment
- 0 months
- Average class
- 25 students
- Award
- Masters
What you study
10 subjects- Information Systems Security and Governance
- Network Security and Threat Defence
- Penetration Testing and Vulnerability Assessment
- Digital Forensics and Incident Response
- Cryptography and Cryptanalysis
- Security Risk Management and Compliance
- Software Security and Secure Coding
- Security Architecture and Design
- Research Methods in Cyber Security
- Project Research
Modules
12 in the programmeInformation Systems Security Foundations
Year 1Semester 13 creditsCore
Examines security fundamentals, CIA triad, threats, vulnerabilities, risk, security models, and managing information systems security.
Network Security and Threat Defence
Year 1Semester 13 creditsCore
Covers firewalls, IDS/IPS, network defence, secure architecture, VPNs, and managing network security.
Research Methods in Cyber Security
Year 1Semester 13 creditsCore
Covers research design, data collection, analysis, security research methods, and conducting cyber security research, preparing students for their project.
Cryptography and Cryptanalysis
Year 1Semester 23 creditsCore
Examines encryption, decryption, protocols, PKI, key management, cryptanalysis, and managing cryptographic systems.
Penetration Testing and Vulnerability Assessment
Year 1Semester 23 creditsCore
Covers vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.
Digital Forensics and Incident Response
Year 1Semester 23 creditsCore
Examines evidence collection, analysis, chain of custody, forensic tools, incident handling, and managing digital forensics and incidents.
Software Security and Secure Coding
Year 1Semester 23 creditsCore
Covers secure coding, application security, SDLC, vulnerability analysis, OWASP, and managing software security.
Security Governance and Risk Management
Year 2Semester 13 creditsCore
Examines security governance, policy, frameworks, ISO 27001, compliance, risk assessment, and managing security governance and risk.
Security Architecture and Design
Year 2Semester 13 creditsCore
Covers security design, defence in depth, zero trust, cloud security, enterprise security, and managing security architecture.
Cloud Security and Virtualisation
Year 2Semester 13 creditsCore
Examines cloud security models, IaaS, PaaS, SaaS security, virtualisation security, container security, and managing cloud security.
Malware Analysis and Threat Intelligence
Year 2Semester 13 creditsCore
Covers malware analysis, reverse engineering, threat intelligence, IOCs, threat hunting, and managing malware and threat intelligence.
Research Project
Year 2Semester 26 creditsCore
Original supervised research project on a cyber security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.
Specialisations
Network Security
Focuses on network security, covering firewalls, IDS/IPS, network defence, secure architecture, and managing network security.
Digital Forensics
Examines digital forensics, covering evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics.
Penetration Testing
Covers penetration testing, covering vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing.
Security Governance
Focuses on security governance, covering security policy, compliance, frameworks, ISO 27001, and managing security governance.
Software Security
Examines software security, covering secure coding, application security, SDLC, vulnerability analysis, and managing software security.
Incident Response
Covers incident response, covering incident handling, threat hunting, malware analysis, recovery, and managing security incidents.
A day as a student
A typical day during the MSc in Cyber Security programme combines lectures, laboratory sessions, practical workshops, seminars, and independent study. Sessions cover information systems security, network security, penetration testing, and digital forensics. Information systems security sessions examine security governance, policy, frameworks, ISO 27001, risk management, and managing security governance. Network security sessions cover firewalls, IDS/IPS, network defence, secure architecture, VPNs, and managing network security. Penetration testing sessions cover vulnerability assessment, ethical hacking, exploit development, reporting, and managing penetration testing. Digital forensics sessions cover evidence collection, analysis, chain of custody, forensic tools, and managing digital forensics. Cryptography sessions cover encryption, decryption, protocols, PKI, key management, and managing cryptographic systems. Software security sessions cover secure coding, application security, SDLC, vulnerability analysis, and managing software security. Incident response sessions cover incident handling, threat hunting, malware analysis, recovery, and managing security incidents. Security architecture sessions cover security design, defence in depth, zero trust, cloud security, and managing security architecture. Risk management sessions cover risk assessment, threat modelling, compliance, audit, and managing security risk. Research methods sessions prepare students for their project, covering research design, data collection, and analysis. Laboratory sessions provide hands-on experience with security tools, penetration testing frameworks, forensic software, and network security appliances. Practical workshops provide hands-on experience with Kali Linux, Metasploit, Wireshark, EnCase, and security assessment tools. Seminars and discussion groups provide opportunities for debating current issues in cyber security and emerging threats. Guest lectures from experienced security professionals, ethical hackers, and forensic experts provide practical insights. The programme culminates in a supervised research project on a cyber security topic.
The trade offs
In its favour
- Very high demand for cyber security professionals with Kenya's digital transformation, fintech growth, cyber threats, and regulatory requirements.
- Strathmore's MSc ISS is developed with global and local IT security industry key players, providing industry-relevant curriculum.
- Graduates are eligible for CISSP and CEH professional certifications, enhancing global career prospects.
- JKUAT offers competitive fees at approximately KES 252,500/year (KES 505,000 total) for related computing programmes.
Against it
- Strathmore (private) charges KES 1,408,500 total, which is significantly higher than public universities.
- JKUAT and MMU do not offer a dedicated MSc in Cyber Security, only related programmes with security content.
- MMU specific cyber security fees not independently verified.
- Programme requires computer science, IT, or related background, which may limit access for non-related graduates.
What it costs
Tuition at both ends of the market, and how to pay for it.
What it costs, and where
Against 191 technology coursesAnnual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.
The fine print
JKUAT ~254K/yr (jkuat.ac.ke). MMU MSc IT ~130K/yr (eafinder 2019). Strathmore MSc ISS 704K/yr.
HELB postgraduate loans are available for Kenyan students. Strathmore University offers financial aid for eligible students. JKUAT may offer postgraduate bursaries. Some technology companies and security firms may sponsor staff for postgraduate study.
Funding options
HELB Postgraduate Loan
Strathmore University Financial Aid
JKUAT Postgraduate Bursary
Scholarships
3 recordedHELB Postgraduate Loan
LoanKsh 200,000Kenyan
Kenyan students pursuing postgraduate studies at recognised universities.
Strathmore University Financial Aid
ScholarshipKsh 300,000Kenyan
Strathmore University offers financial aid for eligible postgraduate students.
JKUAT Postgraduate Bursary
ScholarshipKsh 100,000Kenyan
JKUAT offers postgraduate bursaries for eligible students.
Getting in
The grades, the alternatives, and who accredits the award.
What you need
- KCSE mean grade
- N/A (Postgraduate)
- Alternative entry
- Strathmore requires First Class (GPA 3.45-4.0) or Upper Second Class (GPA 2.85-3.44) in Computer Science or IT with minimum KCSE C+. JKUAT and MMU require computer science, IT, or related background. Applicants may be required to pass an interview. Contact respective universities for specific admission requirements.
How you are assessed
4 componentsCoursework and Continuous Assessment
Coursework30% of the mark
Continuous assessment through coursework assignments, laboratory reports, security exercises, seminar presentations, and class participation.
Written Examinations
Examination70% of the mark
Written examinations covering information systems security, network security, cryptography, and digital forensics.
Practical and Laboratory Assessment
Practical30% of the mark
Practical assessment through penetration testing exercises, forensic analysis, security tool configuration, and demonstrating cyber security skills.
Research Project
Research100% of the mark
Original supervised research project on a cyber security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.
Accreditation
The programme is accredited by the Commission for University Education (CUE). Strathmore University (private) offers MSc in Information Systems Security through iLabAfrica. JKUAT and Multimedia University of Kenya (public) offer related MSc in Computer Systems, Computer Science, or IT with security content. All programmes meet CUE standards for postgraduate training in cyber security. Graduates are eligible for CISSP and CEH professional certifications.
Accredited by
Commission for University Education (CUE)
Academic accreditationRequired
Programme accredited by CUE. Strathmore University (private) offers MSc in Information Systems Security through iLabAfrica. JKUAT and Multimedia University of Kenya (public) offer related MSc in Computer Systems, Computer Science, or IT with security content. All programmes meet CUE standards for postgraduate training in cyber security. Graduates are eligible for CISSP and CEH professional certifications.
Where it leads
The roles it opens, and what you leave with.
Where graduates go
6 rolesCyber Security Analyst
Very high demandKsh 150,000 to Ksh 700,000
Monitors and analyses security, overseeing threats, vulnerabilities, incidents, response, and managing cyber security operations.
Penetration Tester
High demandKsh 160,000 to Ksh 750,000
Conducts penetration testing, overseeing vulnerability assessment, ethical hacking, reporting, and managing penetration testing.
Security Architect
High demandKsh 180,000 to Ksh 800,000
Designs security architecture, overseeing security design, infrastructure, frameworks, and managing security architecture.
Digital Forensics Examiner
Moderate demandKsh 150,000 to Ksh 650,000
Conducts digital forensics, overseeing evidence collection, analysis, reporting, testimony, and managing digital forensics.
Security Consultant
High demandKsh 170,000 to Ksh 750,000
Provides security consulting, overseeing advisory, assessment, strategy, implementation, and managing security consulting.
Cyber Security Lecturer
Moderate demandKsh 120,000 to Ksh 500,000
Teaches cyber security at university or college level, overseeing instruction, research, and academic supervision.
Graduate outcomes
Graduates pursue careers as cyber security analysts, penetration testers, security architects, digital forensics examiners, security consultants, and lecturers in cyber security across financial institutions, government agencies, security firms, technology companies, consulting firms, and universities.
Where these fields lead
8 careers- Career Guidance & Labour Market Information CounselorEducation11Low exposure
- School Guidance CounselorEducation17Low exposure
- CrystallographerScience19Low exposure
- StatisticsScience20Low exposure
- Motor Vehicle MechanicEducation21Low exposure
- MycologistScience21Low exposure
- OceanographerScience21Low exposure
- Computational BiologistScience22Low exposure
Tools you will learn
Kali Linux
SoftwarePrimary
Kali Linux for penetration testing, covering ethical hacking, vulnerability assessment, exploit tools, and managing penetration testing.
Metasploit
Software
Metasploit for exploit development, covering vulnerability exploitation, payload generation, post-exploitation, and managing exploit testing.
Wireshark
Software
Wireshark for network analysis, covering packet capture, protocol analysis, network troubleshooting, and managing network security analysis.
EnCase
Software
EnCase for digital forensics, covering evidence collection, analysis, reporting, chain of custody, and managing digital forensics.
Industry links
Common misconceptions
Cyber security is just about installing antivirus software.
Cyber security covers comprehensive governance, network security, penetration testing, forensics, cryptography, incident response, and risk management beyond just antivirus software.
This programme is only for hackers.
Cyber security skills are valuable for security analysts, architects, consultants, managers, auditors, and educators beyond just hackers.
Cyber security is purely technical.
Cyber security covers both technical and managerial aspects including governance, policy, compliance, risk management, and security awareness.
Penetration testing is just about breaking into systems.
Penetration testing covers comprehensive vulnerability assessment, ethical hacking, exploit development, reporting, and remediation recommendations.
Digital forensics is just about recovering deleted files.
Digital forensics covers comprehensive evidence collection, analysis, chain of custody, forensic tools, legal procedures, and expert testimony.
Security governance is just about writing policies.
Security governance covers comprehensive frameworks, compliance, risk management, audit, strategy, and organisational security leadership.
Related courses
Further reading
- Strathmore University — MSc in Information Systems Security
- JKUAT — School of Computing and IT
- Multimedia University of Kenya — MSc in Computer Science and IT
- Commission for University Education (CUE)
- Communications Authority of Kenya (CA)
- International Information System Security Certification Consortium (ISC2)
Fees and entry marks for Master of Science in Cyber Security are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.