At a glance
- Legal name
- IMIZI Cyber Consulting Ltd
- Founded
- January 2026, in Kigali
- Office
- Norrsken House, 1 KN 78 St, Kigali, Rwanda
- What we do
- Manual penetration testing (VAPT) of web, API, mobile, network and cloud systems; regulator-aligned testing for BNR Regulation N° 50/2022, SWIFT CSP and Law N° 058/2021; red teaming; managed security with IMIZI Monitor and IMIZI Aware; security training
- Who we serve
- Banks, microfinance institutions, fintechs and payment providers, telecoms, government and healthcare institutions across Africa
- Testing led by
- An OSCP- and PNPT-credentialled lead penetration tester with 50+ engagements across 8 countries
- Data protection
- Registered with the NCSA as a data controller under Law N° 058/2021
- Contact
- info@imizicyber.com, +250 793 146 617
Leadership
Aristofanis Chionis Koufakos
Lead Penetration TesterOffensive-security practitioner and founder of IMIZI Cyber. OSCP credentialled, with an MSc in Computer Security from the Technical University of Denmark. Red-team and penetration-testing experience across Tier-1 Nordic banking, pan-African banking and securities trading, with 50+ engagements across 8 countries; co-presented the open-source Honeyscanner tool at Black Hat Europe 2023 Arsenal. Founded IMIZI Cyber to bring manual, evidence-led VAPT to regulated institutions across Africa.
Public work: Honeyscanner, an open-source honeypot vulnerability analyser, where he is a top contributor. It was built during Google Summer of Code 2023 with the Honeynet Project, and he co-presented it with his co-authors at Black Hat Europe 2023 Arsenal in London.
LinkedInHow engagements run
We run the work end to end: we scope the engagement, test it by hand, and write the report. The person who ran the test writes the findings and the remediation guidance, so the report carries the evidence behind every finding and the reasoning behind every rating. Before any system detail is shared we sign an NDA, and testing starts only after written authorisation and a signed scope; how we handle your data has the detail.
What we deliver
Our focus is manual offensive security: Vulnerability Assessment and Penetration Testing for regulated institutions across Africa. Testing is aligned to BNR supervisory expectations and supplies the technical evidence that PCI DSS, ISO 27001, SOC 2, and SWIFT CSP programmes rely on. Certification and attestation sit with independent assessors; we provide the testing and evidence component that work depends on.
Working with us
Business development and client relationships are handled by a dedicated colleague, so the testing lead's time stays on the testing.
Evalyne Kembabazi
Marketing & Business Development ManagerEvalyne leads business development across Africa: she identifies organisations facing regulatory security pressure, scopes what they need, and runs client relationships from the first conversation to final report delivery. She is usually the first person a prospective client speaks to at IMIZI Cyber.
LinkedInWhy Kigali
Our base is Norrsken House in central Kigali. Banks, mobile-money operators and other regulated institutions across the continent are moving onto digital channels and cloud infrastructure, and they need qualified testers who know the local regulation. We work from Kigali across Rwanda, East and Southern Africa and further afield, on site or remotely.
How we support compliance programmes
We deliver manual VAPT and the preparation work a compliance programme depends on: gap preparation against frameworks such as PCI DSS, ISO 27001, and SOC 2, the technical testing evidence those frameworks call for, and remediation guidance until findings close. When an engagement reaches the audit stage, we can introduce you to independent audit and certification firms; the certificate or attestation always comes from an independent third party.
Work with us
Book a call to discuss your environment. Your VAPT engagement is scoped and reported by the person who does the testing.