Managed security services for regulated institutions

Ongoing security advice and testing on a monthly retainer.

Recurring vulnerability management, continuous external monitoring and security advice for banks, fintechs, telecoms, government, ministries and healthcare across Africa, with the same practitioner working with you between engagements.

What we deliver

External perimeter review

Recurring review of your external attack surface: domain and subdomain discovery, exposed-service detection, certificate tracking and prioritised alerts on new exposures each cycle.

Vulnerability management

Monthly authenticated vulnerability scanning of all in-scope assets, with findings prioritised by exploitability and business impact, patch tracking and fix verification.

Cybersecurity advisory

Risk briefings, regulatory guidance and practical technical advice for leadership teams between engagements. We advise; we do not act as your in-house CISO.

SAST / DAST integration

We add static and dynamic application security testing to your development pipeline, raise findings in your existing ticketing system and send weekly reports to your developers.

Security reporting & compliance

A monthly executive dashboard, BNR-aligned compliance reporting, evidence packages for ISO 27001 and SWIFT CSP audits, and a board summary each quarter.

Threat context

Threat briefings relevant to African financial institutions, with early warning of new vulnerabilities in your technology stack and credential-leak checks each reporting cycle.

What a retainer adds to annual testing

An annual penetration test shows your security posture on the day of the test. Your attack surface changes with every software release, configuration change and new deployment, and new findings appear between tests.

A managed-security retainer keeps the same practitioner engaged between projects:

  • New vulnerabilities are found each cycle
  • Your board gets regular cybersecurity posture briefings between engagements
  • Your security posture is reviewed on a recurring cadence
  • Compliance reporting stays current between inspections
  • You have a named practitioner you can call, without the recruitment cost of a full-time hire

On scope: this is an advisory retainer. We do not run a staffed 24/7 SOC or act as a vCISO. We deliver recurring assessment, continuous external monitoring and security advice.

For BNR-supervised institutions: A managed-security retainer supports BNR's requirements for ongoing vulnerability management and security review. We provide the evidence-led compliance documentation your inspection team needs.

Service tiers

The tiers below show example scopes. We size every retainer to your environment and agree cadence and depth with you before any quote.

Essentials

Baseline

Illustrative scope for SMEs and early-stage fintechs
  • Recurring vulnerability scanning
  • External asset review each cycle
  • Written security report each cycle
  • Email/WhatsApp point of contact
  • Periodic security posture review
  • Annual pentest (included)
Professional

Protect

Illustrative scope for banks, MFIs, and growing fintechs
  • Everything in Essentials
  • Recurring perimeter review
  • Scheduled penetration testing
  • SAST/DAST setup and findings review
  • Cybersecurity advisory session each cycle
  • BNR compliance evidence package
  • Executive report each cycle
  • Direct practitioner point of contact
Extended

Defend

Illustrative scope for larger or multi-country operations
  • Everything in Professional
  • Board-level advisory each cycle
  • Threat-context briefings each cycle
  • Credential-leak checks each cycle
  • On-site reviews by arrangement
  • SWIFT CSP technical-testing support
  • ISO 27001 evidence support
  • Custom scope and cadence

All tiers include a kickoff assessment, asset discovery and onboarding. We quote a fixed monthly fee after scoping your environment.

Who we work with

Retainer engagements are built for banks and MFIs supervised by BNR, payment service providers, mobile money operators, telecoms, insurers, government bodies, ministries, healthcare institutions, fintechs, and technology companies serving the financial sector across Africa. We are based in Kigali and available for on-site work when required.

Compliance alignment

Ongoing vulnerability management and security review feature in the frameworks that govern financial institutions in Rwanda and across Africa. A managed-security retainer supports your compliance with these frameworks by supplying recurring assessment and evidence-led documentation. Where a control covers incident response, logging, or continuous monitoring, that obligation sits with you; our retainer does not deliver it.

  • BNR Regulation N° 50/2022 on cyber security: requires supervised institutions to implement ongoing vulnerability management and security review. A managed-security retainer supplies the recurring assessment and evidence that support these obligations (incident response and forensics are outside the retainer's scope)
  • PCI DSS v4.0: Requirement 11.3 (vulnerability scanning) is the area a managed-security retainer directly supports. Requirement 5 (anti-malware) and Requirement 10 (logging and monitoring of access) remain your operational obligation
  • ISO 27001:2022: Control 8.8 (Management of technical vulnerabilities) is the control a managed-security retainer directly supports. Control 8.16 (Monitoring activities) and Control 5.24 (Incident management planning) are your obligation; our retainer watches your external attack surface but does not provide internal network monitoring or incident response
  • Rwanda Data Protection Law N° 058/2021: Article 47 requires data controllers and processors to adopt appropriate technical measures to ensure the security of personal data. Recurring vulnerability assessment supports this obligation

Related services: penetration testing and security awareness training. For the full picture of what we cover, see our guide to penetration testing in Rwanda.

Frequently asked questions

What does a managed security retainer include?
Recurring vulnerability assessment of your in-scope assets, continuous external monitoring of your perimeter, and security advisory between engagements, delivered on a monthly retainer with BNR-aligned reporting. It is an advisory retainer: we do not run a staffed 24/7 SOC or act as a vCISO.
How is a retainer different from a one-off penetration test?
An annual penetration test shows your security on the day of the test, and your attack surface changes with every software release, configuration change and new deployment. A retainer keeps the same practitioner engaged between projects, finding new vulnerabilities each cycle and keeping your compliance evidence current between inspections.
Who is managed security for?
Retainer engagements are built for banks and MFIs supervised by BNR, payment service providers, mobile money operators, telecoms, insurers, government bodies, ministries, healthcare institutions, and fintechs across Africa. It suits organisations that need ongoing security review without the recruitment cost of a full-time in-house team.
How does continuous external monitoring fit into the retainer?
Continuous external monitoring is part of every retainer and runs on IMIZI Monitor: domain and subdomain discovery, exposed service detection, certificate tracking, and prioritised alerting on new exposures, alongside the scheduled vulnerability assessment work. Where staff awareness is in scope, the phishing simulation programme runs on IMIZI Aware.
Does a managed security retainer support BNR compliance?
Yes. BNR Regulation N° 50/2022 on cyber security requires supervised institutions to implement ongoing vulnerability management and security review. A retainer supplies the recurring assessment and evidence-led documentation your inspection team needs. Incident response and forensics are outside the scope of the retainer.
How do we get started?
Every retainer begins with a kickoff assessment, asset discovery, and onboarding. Tell us about your environment and we reply within 24 hours; a proposal with a fixed monthly fee, agreed after the scoping call, follows within 48 hours of that call. Optional extras outside the agreed scope are billed at the day rate.

Get a managed security quote

Tell us about your environment. We reply within 24 hours, and a scoped proposal follows within 48 hours of the scoping call.