Based in Kigali, working across Africa

Offensive security & penetration testing for Africa's regulated institutions

Manual VAPT for banks, fintechs, telecoms, government and healthcare, with evidence-led reports structured for BNR supervision.

Or take our free 3-minute security score quiz and see your score at once.

The IMIZI Cyber team working on a laptop and notebook in the garden at Norrsken House, Kigali.
Our team at Norrsken House, Kigali

The team behind the testing

Our testing is led by an OSCP-credentialled practitioner, and the person who tests your systems writes your report.

Aristofanis Chionis Koufakos, Lead Penetration Tester

Aristofanis Chionis Koufakos

Lead Penetration Tester

Aristofanis Chionis holds the OSCP, co-presented the open-source Honeyscanner tool at Black Hat Europe 2023 Arsenal, and brings red-team and penetration-testing experience from Nordic and pan-African banking, plus an MSc in Computer Security.

48hFrom scoping call to proposal
By handEvery report, start to finish
KigaliRemote and on-site across Africa

Credentials

  • Certification OSCP Offensive Security
  • Certification PNPT TCM Security
  • Conference talk Black Hat Europe 2023 Arsenal Co-presented Honeyscanner, London
  • Open source Honeyscanner Top contributor, GSoC 2023 with the Honeynet Project
  • Degree Computer Security Technical University of Denmark
  • Degree Informatics & Telecommunications NKUA

Why choose IMIZI Cyber

Manual testing, confirmed by exploitation

We confirm every finding by exploiting it by hand, and we test directly for the business-logic flaws, chained issues and access-control gaps that scanners miss.

Evidence-led reports, written by hand

The person who ran the test writes the findings and the remediation guidance, with reproduction steps your engineers can follow and a summary your management can act on.

Red-team experience from banking

Our lead practitioner comes from threat-led red-team work at a Tier-1 Nordic bank and penetration testing across pan-African banking. We test your systems the same way.

How we work

Four steps, from the first call to the closure letter.

  1. Scoping call

    We map your environment, the rules you answer to and what needs testing

  2. Proposal and SOW

    A fixed price, scope, timeline and rules of engagement, within 48 hours of the call

  3. Testing

    1 to 6 weeks of manual testing with daily status updates on critical findings

  4. Report and support

    A written report with remediation guidance, one re-test round and a closure letter

What clients say

Security engagements, in our clients’ own words.

Its report explained each issue clearly for our technical team and our management, with reproduction steps and practical remediation guidance. IMIZI delivered the report ahead of the agreed deadline, presented the results in person at our offices, and verified all of our fixes in the re-test. We found IMIZI professional, careful with our production environment and data, and easy to work with. We would recommend IMIZI Cyber for penetration testing of financial services platforms.

Chief Technology Officer Fintech company Penetration test and re-test

IMIZI Cyber went above and beyond our expectations: thorough analysis, fantastic reports and follow-ups. I was relieved at how trustworthy they were and how well it all went. We'll surely be using them again.

Peter P. Founder, U.S. legal-tech SaaS Web application penetration test

IMIZI delivered a detailed report covering the identified issues, the business impact … and a prioritised remediation roadmap. The work was carried out professionally and confidentially.

Technology executive Financial services organisation External attack-surface assessment

Common questions

Why do banks in Rwanda need penetration testing?
BNR Regulation N° 50/2022 requires regulated financial institutions to run annual penetration tests and twice-yearly vulnerability assessments as part of their cybersecurity programme, with results filed with the regulator. Penetration testing finds vulnerabilities in your web apps, mobile banking, APIs, and USSD services before attackers do.
Do you help with BNR cybersecurity compliance?
Yes. We help banks, microfinance institutions, and insurance companies meet the testing requirements in BNR Regulation N° 50/2022 through penetration testing, vulnerability assessments, configuration and architecture assessments, and ongoing managed security. We test and assess; a formal audit opinion or certification comes from an independent auditor.
How much does penetration testing cost in Rwanda?
Cost depends on the number of applications, infrastructure complexity, and testing depth. Each engagement has a fixed price, agreed after the scoping call and based on what is in scope. You pay per milestone on acceptance, the re-test round is included, and optional extras such as further re-test rounds are billed at the day rate. Tell us your requirements; we reply within 24 hours, and a fixed-price proposal follows within 48 hours of the scoping call.
What is BNR Regulation on cybersecurity?
BNR Regulation N° 50/2022 requires regulated financial institutions to run a cybersecurity programme that includes annual penetration testing, twice-yearly vulnerability assessments, incident response plans, and security awareness training, with an executive summary of test findings shared with the National Bank of Rwanda. We deliver the testing and the evidence your examiner reviews.
What certifications does your lead practitioner hold?
Our testing is led by Aristofanis Chionis Koufakos: OSCP (Offensive Security Certified Professional), PNPT (TCM Security), and an MSc in Computer Security from the Technical University of Denmark. He co-presented Honeyscanner, an open-source honeypot vulnerability analyser built during Google Summer of Code 2023 with the Honeynet Project, at Black Hat Europe 2023 Arsenal in London.
How often should banks do penetration testing?
BNR Regulation N° 50/2022 requires at least annual penetration testing and twice-yearly vulnerability assessments for supervised institutions. Testing again after a major infrastructure or application change is good practice rather than a BNR mandate, and many institutions test critical systems such as mobile banking and payment APIs more frequently.
What is the difference between VAPT and penetration testing?
VAPT combines automated vulnerability scanning with manual penetration testing. Vulnerability assessment identifies weaknesses using tools. Penetration testing then exploits those weaknesses by hand to show their business impact. We do both.
Do I need ISO 27001 certification in Rwanda?
ISO 27001 is not legally mandatory in Rwanda. BNR encourages ISO 27001 alignment for financial institutions. We help organisations prepare through gap analysis, technical testing evidence, and remediation guidance; certification itself is issued by an independent certification body.
Can you help us get ISO 27001, PCI DSS, or SOC 2 certified?
We handle the readiness side: gap preparation, the technical testing evidence these frameworks require, and remediation guidance until findings close. Certification and attestation are always issued by independent audit and certification firms, and we can introduce you to them. We prepare you for their assessment; we do not certify or audit you ourselves.
How do you handle our data during an engagement?
We sign a non-disclosure agreement before you share any system detail, and testing starts only after you sign a written authorisation and the agreed scope. On request we provide an activity log with our source IP addresses. The full detail is on our data handling page.
Do you offer cybersecurity training for employees?
Yes, in two forms. IMIZI Aware is a managed phishing simulation and awareness programme for all staff, run on a recurring cadence. Our security training service is hands-on workshops for engineering and IT teams (secure coding, hardening, and incident handling) plus executive briefings. Both are available on-site in Kigali or remotely across Africa.
Do you work with organisations outside Rwanda?
Yes. We are based in Kigali and deliver engagements across Africa, on-site or remotely. Where a country licenses security testing providers, we confirm the requirement with you before testing begins. Individual credentials are on our about page.

Scope your next regulatory test, tender or partner security review

Book a free 30-minute call. We map what needs testing against the rule you answer to (BNR, SWIFT CSP, Law N° 058/2021 or a partner's questionnaire) and send a fixed-price proposal within 48 hours of the call.

Get in touch

We respond within 24 hours.

Location
Kigali, Rwanda
Entity
IMIZI Cyber Consulting Ltd

Or send us the details in writing