Cybersecurity services in Rwanda and across Africa
Manual VAPT, regulator-aligned assessments, red teaming, managed monitoring and training for banks, fintechs, telecoms, government, healthcare and other regulated institutions. Find what prompted your search below; each route leads to the service that answers it.
Start from what prompted the search
Most engagements start because a regulator, a partner or the board asked for one. Find your situation, then the service that answers it.
-
A BNR filing is due
Banks, microfinance institutions and payment service providers supervised by the National Bank of Rwanda.
- BNR-compliant penetration testing
The annual penetration test and twice-yearly vulnerability assessments BNR Regulation N° 50/2022 requires, with the report your examiner expects.
- BNR-compliant penetration testing
-
Your SWIFT attestation needs an independent assessment
Institutions on the SWIFT network with an annual CSP attestation to support.
- SWIFT CSP independent assessment
Hands-on testing of your in-scope SWIFT CSP controls by an external assessor, with the evidence your 31 December attestation needs.
- SWIFT CSP independent assessment
-
Law N° 058/2021 applies to the data you hold
Any organisation in Rwanda that holds personal data: government, healthcare, telecoms, fintech and more.
- Data protection and NCSA compliance testing
Testing that evidences the “appropriate technical and organisational measures” Law N° 058/2021 requires of anyone holding personal data.
- Data protection and NCSA compliance testing
-
A partner, investor or customer asked for a pentest
Due diligence, vendor onboarding, a product launch or a tender requirement. Start with the scope they asked for.
- Penetration testing (VAPT)
Manual testing of networks, web applications, mobile apps, APIs and cloud, with an evidence-led report written by hand.
- Web application penetration testing
Authentication, access control, sessions, injection and business logic, tested against the OWASP Top 10 and the OWASP WSTG.
- API penetration testing
REST, GraphQL and mobile-backend APIs tested by hand against the OWASP API Security Top 10.
- Mobile app penetration testing
Android and iOS apps tested against OWASP MASVS and MASTG, together with the APIs and USSD rails behind them.
- Penetration testing (VAPT)
-
You want to know whether your team would detect an attack
For organisations that want to test their detection and response as well as their systems. If a penetration test is the better first step, we say so.
- Red team services
Objective-based adversary simulation that measures whether your detection and response catch a realistic attack.
- Red team services
-
You need a configuration or architecture review
Before a migration, ahead of an audit, or when you need a clear view of your posture.
- Security assessments
Configuration audit, cloud and architecture review, source code review and compliance gap analysis, every finding validated by hand.
- Security assessments
-
You want cover between annual tests
Your attack surface changes with every release, and an annual test sees it on one day.
- Managed security retainer
Recurring vulnerability management, external perimeter review and security advisory on a monthly retainer.
- IMIZI Monitor
A managed service that watches your external attack surface daily and maps findings to the frameworks your regulator uses.
- IMIZI Aware
A managed programme of phishing simulation and short training, with click and report rates your board can read.
- Managed security retainer
-
Your people need training
Staff, IT teams and management, with evidence your regulator can review.
- Security training
Awareness sessions and workshops built on regional attack scenarios, delivered on site or live online.
- IMIZI Aware
A managed programme of phishing simulation and short training, with click and report rates your board can read.
- Security training
-
Your team needs tooling built for your stack
Security checks in your pipeline, or scanners that understand your business logic.
- Custom security tooling
Pipeline security testing, custom scanners and security automation, built around your stack by the people who test it.
- Custom security tooling
How an engagement works
The same six steps for every testing engagement, from the first call to the closure letter.
-
Scoping call
A free call about the systems, the deadline and who is asking for the test. Book it directly, or write to us and we reply within 24 hours. If scoping needs system detail, we sign an NDA first.
-
Fixed-price proposal
Scope, method, timeline and a fixed price, within 48 hours of the call.
-
NDA and authorisation
An NDA before any system detail is shared, then written authorisation and a signed scope before testing starts. The authorisation names the people who will carry out the testing.
-
Testing
Manual testing inside the agreed scope and window, with a timestamped log of every action, shared on request.
-
Report and debrief
An evidence-led report written by hand, presented to your technical team and management, in person where possible.
-
Re-test and closure letter
One re-test round is included: every Critical and High finding, plus any Medium fixed by the re-test date. A closure letter records the result.
How pricing works
- Fixed price per engagement. We quote after the scoping call, so the price reflects your actual scope.
- Paid per milestone. Each payment falls due when you accept the milestone it covers.
- Re-test included. The re-test round and closure letter are part of the price.
- Extras at the day rate. Anything outside the agreed scope is optional and charged at the day rate.
We do not publish a rate card: two tests with the same name can differ widely in scope.
Your data stays confidential
An NDA is signed before any system detail is shared. Test evidence is encrypted at rest and destroyed on a date we agree with you. We never name a client publicly without written permission.
Let us help you choose the right engagement
Book a free call. We will tell you which engagement answers your trigger, including when a smaller one is the better first step.