Skip to content
Nairobi · KenyaFree to read
Technology

Master of Science in Information (Cyber) Security

The Master of Science in Information (Cyber) Security is a postgraduate programme that prepares professionals for advanced practice in information security, cybersecurity, digital forensics, and security governance. The programme combines security theory with practical application in threat assessment, cryptographic solutions, and network defence.

Core areas include network security, intrusion detection, cryptography, digital forensics, security auditing, software security, ethical hacking, security governance, research methods, and thesis. Students engage with both theoretical and practical work through coursework, laboratory sessions, projects, and research.

The programme is offered by United States International University Africa as MSc in Information Security through the School of Science and Technology. USIU-Africa is a private university accredited by both CUE in Kenya and WASC in the United States, offering the programme over two to four academic years.

Students develop competencies in threat assessment, forensic auditing, cryptographic implementation, network defence design, and security governance. The programme uses experiential learning to prepare graduates to apply information security knowledge for organisational operations and society.

USIU-Africa charges approximately KES 171,250/semester (KES 513,750/year based on 3 semesters) for Kenyan students. Entry requires a Bachelor's degree in a relevant field from a recognised institution, with the programme designed for penetration testers, security architects, incident responders, and forensic experts.

Graduates pursue careers as cybersecurity analysts, information security managers, ethical hackers, security consultants, chief information security officers, and digital forensics experts across financial institutions, government agencies, defence forces, police service, and private security enterprises.

Skills Required

  • Network Security and Defence
  • Intrusion Detection and Prevention
  • Cryptography and Cryptographic Solutions
  • Digital Forensics and Investigation
  • Security Auditing and Compliance
  • Software Security and Vulnerability Assessment
  • Ethical Hacking and Penetration Testing
  • Information Security Governance and Management
  • Research Methods in Information Security
  • Academic Writing and Thesis Research

Key Subjects

  • Network Security and Management
  • Intrusion Detection and Prevention
  • Cryptography and Cryptographic Solutions
  • Digital Forensics and Investigation
  • Security Auditing and Compliance
  • Software Security and Vulnerability Assessment
  • Information Security Governance and Management
  • Ethical Hacking and Penetration Testing
  • Research Methods in Information Security
  • Thesis Research

Certifications

  • CISSP Certification
  • SANS Security Certification

Specializations

Network Security

Focuses on network security, covering defence, protocols, firewalls, intrusion, and managing network security.

Digital Forensics

Examines digital forensics, covering investigation, evidence, analysis, reporting, and managing digital forensics.

Cryptography

Covers cryptography, covering encryption, protocols, algorithms, keys, and managing cryptographic solutions.

Security Governance

Focuses on security governance, covering policy, management, compliance, risk, and managing security governance.

Penetration Testing

Examines penetration testing, covering vulnerability, assessment, exploitation, reporting, and managing penetration testing.

Cloud Security

Covers cloud security, covering architecture, threats, controls, compliance, and managing cloud security.

Duration
2 years
Public, up to
Ksh 256,200
Private, up to
Ksh 513,750
Job market
Very high

The programme

What you study, how long it takes, and how it is delivered.

Practicalities

Study mode
Full-time, Part-time
Attachment
0 months
Average class
15 students
Award
Masters

What you study

10 subjects
  • Network Security and Management
  • Intrusion Detection and Prevention
  • Cryptography and Cryptographic Solutions
  • Digital Forensics and Investigation
  • Security Auditing and Compliance
  • Software Security and Vulnerability Assessment
  • Information Security Governance and Management
  • Ethical Hacking and Penetration Testing
  • Research Methods in Information Security
  • Thesis Research

Modules

12 in the programme
  • Network Security and Management

    Year 1Semester 13 creditsCore

    Examines defence, protocols, firewalls, intrusion, VPN, and managing network security.

  • Intrusion Detection and Prevention

    Year 1Semester 13 creditsCore

    Covers detection, prevention, IDS, IPS, SIEM, and managing intrusion detection.

  • IT Security Techniques and Incident Handling

    Year 1Semester 13 creditsCore

    Examines techniques, incident, handling, response, recovery, and managing security incidents.

  • Research Methods in Computer Science

    Year 1Semester 13 creditsCore

    Covers research design, data collection, analysis, security research methods, and conducting research, preparing students for their thesis.

  • Software Security

    Year 1Semester 24 creditsCore

    Examines vulnerabilities, secure coding, testing, analysis, DevSecOps, and managing software security.

  • Advanced Cryptography

    Year 1Semester 23 creditsCore

    Covers encryption, protocols, algorithms, keys, PKI, and managing cryptographic solutions.

  • Information Security Auditing and Compliance

    Year 1Semester 23 creditsCore

    Examines standards, compliance, frameworks, assessment, ISO 27001, and managing security auditing.

  • Digital Forensics

    Year 1Semester 24 creditsCore

    Covers investigation, evidence, analysis, tools, reporting, chain of custody, and managing digital forensics.

  • Ethical Issues in Information Security

    Year 2Semester 14 creditsCore

    Examines ethics, privacy, law, professionalism, responsibility, and managing ethical issues in security.

  • Information Security Governance and Management

    Year 2Semester 13 creditsCore

    Covers policy, management, compliance, risk, strategy, and managing security governance.

  • Security Architecture for Cloud Computing

    Year 2Semester 13 creditsCore

    Examines architecture, threats, controls, compliance, models, and managing cloud security.

  • Research Thesis

    Year 2Semester 29 creditsCore

    Original supervised research thesis on an information security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.

Specialisations

  • Network Security

    Focuses on network security, covering defence, protocols, firewalls, intrusion, and managing network security.

  • Digital Forensics

    Examines digital forensics, covering investigation, evidence, analysis, reporting, and managing digital forensics.

  • Cryptography

    Covers cryptography, covering encryption, protocols, algorithms, keys, and managing cryptographic solutions.

  • Security Governance

    Focuses on security governance, covering policy, management, compliance, risk, and managing security governance.

  • Penetration Testing

    Examines penetration testing, covering vulnerability, assessment, exploitation, reporting, and managing penetration testing.

  • Cloud Security

    Covers cloud security, covering architecture, threats, controls, compliance, and managing cloud security.

A day as a student

A typical day during the MSc in Information (Cyber) Security programme combines lectures, laboratory sessions, practical exercises, seminars, and independent study. Sessions cover network security, cryptography, digital forensics, security governance, and ethical hacking. Network security sessions examine defence, protocols, firewalls, intrusion, and managing network security. Cryptography sessions cover encryption, protocols, algorithms, keys, and managing cryptographic solutions. Digital forensics sessions cover investigation, evidence, analysis, tools, reporting, and managing digital forensics. Security auditing sessions cover standards, compliance, frameworks, assessment, and managing security auditing. Software security sessions cover vulnerabilities, secure coding, testing, analysis, and managing software security. Ethical hacking sessions cover vulnerability, assessment, exploitation, reporting, and managing penetration testing. Security governance sessions cover policy, management, compliance, risk, strategy, and managing security governance. Cloud security sessions cover architecture, threats, controls, compliance, and managing cloud security. Research methods sessions prepare students for their thesis, covering research design, data collection, and analysis. Laboratory sessions provide hands-on experience with security tools, forensics software, penetration testing, and network defence. Practical exercises simulate real-world security scenarios including incident response, forensic investigation, and vulnerability assessment. Seminars provide opportunities for presenting research findings and debating current issues in cybersecurity. Guest lectures from experienced security professionals, forensic experts, and industry leaders provide practical insights. The programme culminates in a supervised research thesis on an information security topic.

The trade offs

In its favour

  • Very high demand for cybersecurity professionals with Kenya's growing digital economy and increasing cyber threats.
  • Programme is accredited by both CUE (Kenya) and WASC (United States), providing international recognition.
  • Programme uses experiential learning with practical exercises simulating real-world security scenarios.
  • Graduates are eligible for CISSP and SANS certifications, enhancing global career prospects.

Against it

  • USIU-Africa fees are relatively high at approximately KES 513,750/year.
  • Only one university (USIU-Africa, private) confirmed offering this specific programme.
  • No public university confirmed offering this specific programme.
  • Programme requires relevant computing background, limiting access for non-related graduates.

What it costs

Tuition at both ends of the market, and how to pay for it.

What it costs, and where

Against 191 technology courses
Public254k to 256k
254k at JKUAT256k at Technical University of Kenya
Private514k to 514k
514k at USIU-Africa514k at USIU-Africa

Annual tuition in Kenyan shillings, rounded. The upright tick is the median for this field, so a bar sitting entirely to its right is an expensive programme by the standards of its own subject.

The fine print

JKUAT 254,100/yr (jkuat.ac.ke). TUK 256,200/yr (eafinder.com). USIU 513,750/yr (usiu.ac.ke).

HELB postgraduate loans are available for Kenyan students. USIU-Africa may offer scholarships for eligible students. ISC2 may offer research grants for cybersecurity research. Some financial institutions, government agencies, and security firms may sponsor staff for postgraduate study.

Funding options

  • HELB Postgraduate Loan

  • USIU-Africa Scholarship

  • ISC2 Research Grant

Scholarships

3 recorded
  • HELB Postgraduate Loan

    LoanKsh 200,000Kenyan

    Kenyan students pursuing postgraduate studies at recognised universities.

  • USIU-Africa Scholarship

    ScholarshipKsh 300,000Kenyan

    USIU-Africa offers scholarships for eligible postgraduate students.

  • ISC2 Research Grant

    ScholarshipKsh 300,000

    ISC2 provides research grants for cybersecurity research and training.

Getting in

The grades, the alternatives, and who accredits the award.

What you need

KCSE mean grade
N/A (Postgraduate)
Alternative entry
USIU-Africa requires a Bachelor's degree in a relevant field from a recognised institution. The programme is designed for penetration testers, CIOs, security architects, network security engineers, incident responders, and forensic experts. Contact the university for specific admission requirements.

How you are assessed

4 components
  • Coursework and Continuous Assessment

    Coursework40% of the mark

    Continuous assessment through coursework assignments, laboratory reports, practical exercises, seminar presentations, and class participation.

  • Written Examinations

    Examination60% of the mark

    Written examinations covering network security, cryptography, digital forensics, and security governance.

  • Practical and Laboratory Assessment

    Practical40% of the mark

    Practical assessment through laboratory exercises, penetration testing, forensic investigation, and demonstrating security skills.

  • Research Thesis

    Research100% of the mark

    Original supervised research thesis on an information security topic, demonstrating mastery of research methods and security knowledge, assessed through written submission and oral defence.

Accreditation

The programme is accredited by the Commission for University Education (CUE) in Kenya and the WASC Senior College and University Commission in the United States. USIU-Africa (private) offers MSc in Information Security through the School of Science and Technology. The programme meets CUE standards for postgraduate training in information security. Graduates are eligible for CISSP certification and SANS security certification.

Accredited by

  • Commission for University Education (CUE)

    Academic accreditationRequired

    Programme accredited by CUE in Kenya and WASC Senior College and University Commission in the United States. USIU-Africa (private) offers MSc in Information Security through the School of Science and Technology. The programme meets CUE standards for postgraduate training in information security. Graduates are eligible for CISSP certification and SANS security certification.

Where it leads

The roles it opens, and what you leave with.

Where graduates go

6 roles
  • Cybersecurity Analyst

    Very high demandKsh 120,000 to Ksh 500,000

    Analyses cybersecurity threats, overseeing monitoring, detection, response, and managing cybersecurity.

  • Information Security Manager

    High demandKsh 150,000 to Ksh 600,000

    Manages information security, overseeing policy, governance, compliance, and managing security programmes.

  • Ethical Hacker

    High demandKsh 120,000 to Ksh 500,000

    Conducts penetration testing, overseeing vulnerability, assessment, exploitation, and managing penetration testing.

  • Security Consultant

    High demandKsh 150,000 to Ksh 600,000

    Provides security consulting, overseeing advisory, assessment, strategy, and managing security consulting.

  • Chief Information Security Officer

    Moderate demandKsh 200,000 to Ksh 800,000

    Leads information security, overseeing strategy, governance, risk, and managing organisational security.

  • Digital Forensics Expert

    Moderate demandKsh 120,000 to Ksh 500,000

    Conducts digital forensics, overseeing investigation, evidence, analysis, and managing digital forensics.

Graduate outcomes

Graduates pursue careers as cybersecurity analysts, information security managers, ethical hackers, security consultants, chief information security officers, and digital forensics experts across financial institutions, government agencies, defence forces, police service, and private security enterprises.

Where these fields lead

8 careers

Tools you will learn

  • Wireshark

    SoftwarePrimary

    Wireshark for network analysis, covering monitoring, analysis, troubleshooting, and managing network security.

  • Metasploit

    Software

    Metasploit for penetration testing, covering exploitation, vulnerability, testing, and managing penetration testing.

  • EnCase

    Software

    EnCase for digital forensics, covering investigation, evidence, analysis, and managing digital forensics.

  • Burp Suite

    Software

    Burp Suite for web security testing, covering scanning, testing, vulnerability, and managing web security.

Industry links

Common misconceptions

  • Cybersecurity is just about installing antivirus software.

    Cybersecurity covers comprehensive network defence, cryptography, forensics, governance, and ethical hacking beyond just installing antivirus.

  • This programme is only for IT professionals.

    Cybersecurity skills are valuable for auditors, managers, forensic experts, law enforcement, and consultants beyond just IT professionals.

  • Digital forensics is just about recovering deleted files.

    Digital forensics covers comprehensive investigation, evidence, analysis, reporting, and legal procedures beyond just recovering deleted files.

  • Ethical hacking is just about breaking into systems.

    Ethical hacking covers comprehensive vulnerability assessment, exploitation, reporting, and remediation beyond just breaking into systems.

  • Security governance is just about writing policies.

    Security governance covers comprehensive management, compliance, risk, strategy, and alignment beyond just writing policies.

  • This programme is too expensive for most students.

    While USIU fees are significant, HELB loans, scholarships, and employer sponsorships are available to support students.

Related courses

Further reading

Keep this

Fees and entry marks for Master of Science in Information (Cyber) Security are restated every intake. Save it and the app keeps this version, so you can see what changed when it does.