IMIZI Monitor

Managed external attack-surface monitoring, mapped to your regulator

We scan your internet-facing systems every day, the way attackers do.

Exposed services, weak configurations and forgotten subdomains are common entry points for attackers. IMIZI Monitor is a managed service: we watch your external attack surface daily, map findings to regulatory frameworks, and alert you when something new appears.

5 Regulatory frameworks mapped
Daily Automated external scans
A to F Security grading per domain
IMIZI Monitor: watch, alert, report, continuously A continuous loop around your external attack surface. Watch: daily external scans. Alert: WhatsApp and email notifications when something changes. Report: monthly board-ready PDF reports mapped to your regulator's frameworks. Then back to watching. Your external attack surface Watch Daily external scans Alert WhatsApp and email, when something changes Report Monthly, mapped to your regulator

Regulators across Africa now enforce cybersecurity rules

Cybersecurity obligations are now written into supervisory rules, and supervisors check them.

Rwanda (BNR and NCSA)

BNR Regulation N° 50/2022 sets board-level cybersecurity accountability and a dedicated IT security function. BNR Regulation N°49/2022 treats cloud services as outsourcing (Art. 20) and requires BNR's prior approval for material outsourcing (Art. 21). Law N°058/2021 (Art. 50) requires personal data to be stored in Rwanda unless NCSA has issued a registration certificate authorising storage abroad.

CBK (Kenya)

The Central Bank of Kenya's Guidance Note on Cybersecurity (2017) sets incident-reporting timelines for banks, and in 2025 CBK launched the Banking Sector Cybersecurity Operations Centre to coordinate threat intelligence and incident response across the sector. Weak controls now draw direct supervisory scrutiny.

BOU (Uganda)

The Bank of Uganda's Cyber Risk Management Guidelines took effect 1 December 2024, making cybersecurity and technology risk management requirements mandatory for all supervised financial institutions.

The talent gap

Africa carries one of the widest cybersecurity workforce shortages of any region (ISC2 Cybersecurity Workforce Study), and demand far outstrips the pool of qualified practitioners. Few institutions can hire enough in-house staff to watch their perimeter every day.

What IMIZI Monitor does

External attack surface scanning

Subdomain discovery, port scanning, TLS/SSL analysis, DNS security checks, HTTP headers, cloud storage exposure and domain health monitoring, scanned automatically every day.

Regulatory compliance mapping

Findings are mapped to the applicable controls in BNR Regulation N° 50/2022, CBK Cybersecurity Guidance, BOU Cyber Risk Guidelines, PCI DSS v4.0, and the applicable ISO 27001:2022 Annex A controls, with a compliance percentage tracked per framework.

Executive PDF reports

Monthly compliance-ready reports with security grades, finding summaries, remediation priorities, and regulatory status. Designed for board meeting packs and regulator submissions.

Real-time alerts

WhatsApp and email notifications when critical findings appear, SSL certificates are expiring, security grades drop, or new assets surface.

Security grading (A to F)

A security grade for each domain that you can track over time and compare against compliance benchmarks.

Dark web intelligence

Credential leak monitoring, brand impersonation detection, and threat actor mention tracking, so you know when your data or brand appears where it should not.

Add-on

From your domain list to a live dashboard

  1. Connect your domains

    Tell us which domains to monitor; we handle the rest. First scan results typically follow within a day or two, and your dashboard is set up during kickoff.

  2. Automated daily scans

    Our scanning engine checks your entire external attack surface every day, with no agents to install and nothing to configure on your systems.

  3. Dashboard, reports, alerts

    View findings in your compliance dashboard, receive alerts when something changes, and download board-ready PDF reports monthly.

Run for you, mapped to African regulation

Global attack-surface tools rarely map findings to BNR, CBK or BOU expectations out of the box, and most give you a dashboard to run yourself. IMIZI Monitor is a managed engagement, mapped to the rules you are examined against.

Managed monitoring mapped to African compliance

Findings are mapped to the applicable controls in BNR Regulation N° 50/2022, CBK Cybersecurity Guidance, and BOU Cyber Risk Guidelines. Global tools' compliance packs centre on NIST CSF and SOC 2; we map findings to the frameworks your supervisor examines against.

Based in Kigali, in your timezone

The service is led by an OSCP-credentialled practitioner, with direct support on WhatsApp and quarterly security reviews in person. When your regulator calls, you can reach our team directly.

Safe for production systems

Non-destructive, rate-limited TCP connect scans only, run with your written authorisation, on banking platforms, government portals, insurance systems and any other public-facing infrastructure.

Costs less than a breach

Cybercrime costs African economies hundreds of millions of dollars each year (INTERPOL African Cyberthreat Assessment). A single missed subdomain, expired certificate or exposed service can lead to a breach that costs far more than monitoring.

Get IMIZI Monitor priced for your organisation

Pricing depends on the domains and assets in scope. Book a call and we will send you a quote.

Questions and answers

Is scanning safe for our systems?
Yes. IMIZI Monitor uses non-destructive, rate-limited TCP connect scans only, which suit banking platforms, government portals, insurance systems and any other public-facing infrastructure. We look at your systems from the outside, as an attacker would, with no agents installed and no credentials needed.
What compliance frameworks do you cover?
BNR Regulation N° 50/2022 (Rwanda), CBK Cybersecurity Guidance (Kenya), BOU Cyber Risk Guidelines (Uganda), PCI DSS v4.0, and ISO 27001:2022. Findings are mapped to the applicable controls in each framework, giving you evidence for your board and your regulator.
Who is IMIZI Monitor for?
Any regulated organisation across Africa with external-facing digital infrastructure. Banks, microfinance institutions, insurance companies, pension funds, payment processors, government agencies, ministries, and hospitals. It suits organisations with public domains and services and a regulator asking about their security posture.
How quickly can we get started?
Tell us your domains. First scan results typically follow within a day or two, and your dashboard is set up during kickoff.
What do we receive when onboarding starts?
Onboarding begins with a baseline assessment of your external attack surface: a branded report covering your current security grade, top findings, and compliance gaps, using your own data. Your live monitoring dashboard is set up during kickoff.
Do you replace our annual penetration test?
No. Penetration testing and continuous monitoring serve different purposes. A pentest is a deep manual assessment at a point in time. IMIZI Monitor watches your attack surface every day and catches changes between pentests: new subdomains, expiring certificates, configuration drift, exposed services. We recommend both.
Where is IMIZI Monitor hosted?
Hosting is set out in your contract and agreed during onboarding, against your regulator's rules and Law N° 058/2021. Monitor works from externally visible information about your internet-facing assets; no agents or credentials are installed on your systems.

Find out what attackers already know about you

Continuous external monitoring grades your attack surface daily and maps it to BNR, PCI DSS, and ISO 27001, the evidence your regulator expects to see. Tell us your domains and we will scope a monitoring engagement.