Offensive security for Africa's regulated institutions

IMIZI Cyber is an offensive-security company based in Kigali, Rwanda, serving banks, fintechs, telecoms, government, ministries, healthcare and other regulated institutions across Africa. Our testing is led by an OSCP-credentialled practitioner who co-presented the open-source Honeyscanner tool at Black Hat Europe 2023 Arsenal, and we have delivered engagements for regulated financial-services clients. Every report is evidence-led and written by hand. Today we deliver manual Vulnerability Assessment and Penetration Testing, aligned to BNR supervisory expectations.

  • OSCP Offensive Security
  • PNPT TCM Security
  • Black Hat Europe 2023 Arsenalco-presented Honeyscanner, London
  • BNR-supervised engagement contextAfrica-wide
  • Evidence-led reports, written by handby the person who ran the test

At a glance

Legal name
IMIZI Cyber Consulting Ltd
Founded
January 2026, in Kigali
Office
Norrsken House, 1 KN 78 St, Kigali, Rwanda
What we do
Manual penetration testing (VAPT) of web, API, mobile, network and cloud systems; regulator-aligned testing for BNR Regulation N° 50/2022, SWIFT CSP and Law N° 058/2021; red teaming; managed security with IMIZI Monitor and IMIZI Aware; security training
Who we serve
Banks, microfinance institutions, fintechs and payment providers, telecoms, government and healthcare institutions across Africa
Testing led by
An OSCP- and PNPT-credentialled lead penetration tester with 50+ engagements across 8 countries
Data protection
Registered with the NCSA as a data controller under Law N° 058/2021
Contact
info@imizicyber.com, +250 793 146 617

Leadership

Aristofanis Chionis Koufakos

Aristofanis Chionis Koufakos

Lead Penetration Tester
OSCP, PNPT, Black Hat Europe Arsenal

Offensive-security practitioner and founder of IMIZI Cyber. OSCP credentialled, with an MSc in Computer Security from the Technical University of Denmark. Red-team and penetration-testing experience across Tier-1 Nordic banking, pan-African banking and securities trading, with 50+ engagements across 8 countries; co-presented the open-source Honeyscanner tool at Black Hat Europe 2023 Arsenal. Founded IMIZI Cyber to bring manual, evidence-led VAPT to regulated institutions across Africa.

Public work: Honeyscanner, an open-source honeypot vulnerability analyser, where he is a top contributor. It was built during Google Summer of Code 2023 with the Honeynet Project, and he co-presented it with his co-authors at Black Hat Europe 2023 Arsenal in London.

LinkedIn

How engagements run

We run the work end to end: we scope the engagement, test it by hand, and write the report. The person who ran the test writes the findings and the remediation guidance, so the report carries the evidence behind every finding and the reasoning behind every rating. Before any system detail is shared we sign an NDA, and testing starts only after written authorisation and a signed scope; how we handle your data has the detail.

What we deliver

Our focus is manual offensive security: Vulnerability Assessment and Penetration Testing for regulated institutions across Africa. Testing is aligned to BNR supervisory expectations and supplies the technical evidence that PCI DSS, ISO 27001, SOC 2, and SWIFT CSP programmes rely on. Certification and attestation sit with independent assessors; we provide the testing and evidence component that work depends on.

Working with us

Business development and client relationships are handled by a dedicated colleague, so the testing lead's time stays on the testing.

Evalyne Kembabazi

Evalyne Kembabazi

Marketing & Business Development Manager

Evalyne leads business development across Africa: she identifies organisations facing regulatory security pressure, scopes what they need, and runs client relationships from the first conversation to final report delivery. She is usually the first person a prospective client speaks to at IMIZI Cyber.

LinkedIn

Why Kigali

Our base is Norrsken House in central Kigali. Banks, mobile-money operators and other regulated institutions across the continent are moving onto digital channels and cloud infrastructure, and they need qualified testers who know the local regulation. We work from Kigali across Rwanda, East and Southern Africa and further afield, on site or remotely.

How we support compliance programmes

We deliver manual VAPT and the preparation work a compliance programme depends on: gap preparation against frameworks such as PCI DSS, ISO 27001, and SOC 2, the technical testing evidence those frameworks call for, and remediation guidance until findings close. When an engagement reaches the audit stage, we can introduce you to independent audit and certification firms; the certificate or attestation always comes from an independent third party.

Work with us

Book a call to discuss your environment. Your VAPT engagement is scoped and reported by the person who does the testing.