Offensive security and penetration testing for regulated organisations
OSCP-certified. Serving banks, telecoms, and government agencies across East Africa and South Africa.
Or take our free security score quiz. 3 minutes, instant results
Independent offensive security consultancy, based in Kigali
imizicyber is a registered Rwandan offensive security firm serving banks, government agencies, and enterprises across East Africa and South Africa. We combine hands-on penetration testing with managed security tooling deployment.
Why choose imizicyber
OSCP-certified, in Kigali
OSCP and OSCP+ certified penetration tester physically based in Rwanda. Not remote contractors, not scanner output.
We build custom tooling
Security validation tools in Python, Go, and JavaScript tailored to your specific APIs and systems.
Banking red team experience
Our lead consultant comes from threat-led red team operations at European banks protecting millions of customers.
What we do
Security tooling, testing, and training for East African banks and regulated organisations.
IMIZI Platform
Security tools built for East African banks and regulated organisations. We scan, monitor, and report so you can fix what matters.
Consulting Services
Security Testing & Assessments
Penetration testing, vulnerability assessments, configuration audits, and compliance gap analysis by an OSCP-certified consultant. Web apps, APIs, mobile banking, USSD, network, and IoT.
Learn more →Managed Security
Continuous monitoring, vulnerability management, and cybersecurity advisory as a monthly service. Built for banks and fintechs that need ongoing protection.
Learn more →Training & Workshops
Hands-on cybersecurity training for employees and IT teams. Security awareness, phishing response, and incident handling.
Learn more →How we work
From scoping to remediation, we keep it straightforward.
Scoping call
We understand your environment, compliance needs, and testing objectives
Proposal and SOW
Clear scope, timeline, cost, and rules of engagement within 48 hours
Testing
1 to 6 weeks of manual testing with daily status updates on critical findings
Report and support
Detailed report with remediation guidance and 30 days of free follow-up
From the field
Security insights for regulated organisations in East Africa.
AI Fraud Detection in Banks Is an Attack Surface. Most CISOs Are Not Ready. | imizicyber
AI fraud detection models in East African banks are themselves attack surfaces. How adversaries exploit them and what to do about it.
Read more →BNR Cybersecurity Audit Preparation Guide | imizicyber
Step-by-step BNR cybersecurity audit preparation. Timelines, evidence checklists, common deficiencies, and what inspectors actually look for.
Read more →Supply Chain Attacks on African Banks | imizicyber
How supply chain attacks through local software vendors and integrators compromise African banks. Defense strategies, vendor assessment frameworks, and practical checklists.
Read more →Common questions
Why do banks in Rwanda need penetration testing?
Do you help with BNR cybersecurity compliance?
How much does penetration testing cost in Rwanda?
What is BNR Regulation on cybersecurity?
What certifications does your lead consultant hold?
How often should banks do penetration testing?
What is the difference between VAPT and penetration testing?
Do I need ISO 27001 certification in Rwanda?
Do you offer cybersecurity training for employees?
Do you work with organisations outside Rwanda?
BNR requires regular security assessments. Is your institution compliant?
Your next audit could be weeks away. Get a free 30-minute scoping call to identify compliance gaps before your regulator does.
Get in touch
We respond within 24 hours.