What a retainer adds to annual testing
An annual penetration test shows your security posture on the day of the test. Your attack
surface changes with every software release, configuration change and new deployment, and
new findings appear between tests.
A managed-security retainer keeps the same practitioner engaged between projects:
- New vulnerabilities are found each cycle
- Your board gets regular cybersecurity posture briefings between engagements
- Your security posture is reviewed on a recurring cadence
- Compliance reporting stays current between inspections
-
You have a named practitioner you can call, without the recruitment cost of a full-time
hire
On scope: this is an advisory retainer. We do not run a staffed 24/7 SOC or act as a vCISO.
We deliver recurring assessment, continuous external monitoring and security advice.
For BNR-supervised institutions: A managed-security retainer supports BNR's requirements
for ongoing vulnerability management and security review. We provide the evidence-led compliance
documentation your inspection team needs.
Service tiers
The tiers below show example scopes. We size every retainer to your environment and agree
cadence and depth with you before any quote.
All tiers include a kickoff assessment, asset discovery and onboarding. We quote a fixed
monthly fee after scoping your environment.
Who we work with
Retainer engagements are built for banks and MFIs supervised by BNR, payment service providers, mobile money operators, telecoms, insurers, government bodies,
ministries, healthcare institutions, fintechs, and technology companies serving the
financial sector across Africa. We are based in Kigali and available for on-site work when
required.
Compliance alignment
Ongoing vulnerability management and security review feature in the frameworks that govern
financial institutions in Rwanda and across Africa. A managed-security retainer supports
your compliance with these frameworks by supplying recurring assessment and evidence-led
documentation. Where a control covers incident response, logging, or continuous monitoring,
that obligation sits with you; our retainer does not deliver it.
- BNR Regulation N° 50/2022 on cyber security: requires supervised
institutions to implement ongoing vulnerability management and security review. A
managed-security retainer supplies the recurring assessment and evidence that support
these obligations (incident response and forensics are outside the retainer's scope)
- PCI DSS v4.0: Requirement 11.3 (vulnerability scanning) is the area a
managed-security retainer directly supports. Requirement 5 (anti-malware) and Requirement
10 (logging and monitoring of access) remain your operational obligation
- ISO 27001:2022: Control 8.8 (Management of technical vulnerabilities) is
the control a managed-security retainer directly supports. Control 8.16 (Monitoring
activities) and Control 5.24 (Incident management planning) are your obligation; our
retainer watches your external attack surface but does not provide internal network
monitoring or incident response
- Rwanda Data Protection Law N° 058/2021: Article 47 requires data
controllers and processors to adopt appropriate technical measures to ensure the security
of personal data. Recurring vulnerability assessment supports this obligation
Related services: penetration testing and security awareness training. For the full picture of what we cover, see our guide to penetration testing in Rwanda.
Frequently asked questions
What does a managed security retainer include?
Recurring vulnerability assessment of your in-scope assets, continuous external monitoring of your perimeter, and security advisory between engagements, delivered on a monthly retainer with BNR-aligned reporting. It is an advisory retainer: we do not run a staffed 24/7 SOC or act as a vCISO.
How is a retainer different from a one-off penetration test?
An annual penetration test shows your security on the day of the test, and your attack surface changes with every software release, configuration change and new deployment. A retainer keeps the same practitioner engaged between projects, finding new vulnerabilities each cycle and keeping your compliance evidence current between inspections.
Who is managed security for?
Retainer engagements are built for banks and MFIs supervised by BNR, payment service providers, mobile money operators, telecoms, insurers, government bodies, ministries, healthcare institutions, and fintechs across Africa. It suits organisations that need ongoing security review without the recruitment cost of a full-time in-house team.
How does continuous external monitoring fit into the retainer?
Continuous external monitoring is part of every retainer and runs on
IMIZI Monitor: domain and subdomain discovery, exposed service detection, certificate tracking, and prioritised alerting on new exposures, alongside the scheduled vulnerability assessment work. Where staff awareness is in scope, the phishing simulation programme runs on
IMIZI Aware.
Does a managed security retainer support BNR compliance?
Yes. BNR Regulation N° 50/2022 on cyber security requires supervised institutions to implement ongoing vulnerability management and security review. A retainer supplies the recurring assessment and evidence-led documentation your inspection team needs. Incident response and forensics are outside the scope of the retainer.
How do we get started?
Every retainer begins with a kickoff assessment, asset discovery, and onboarding. Tell us about your environment and we reply within 24 hours; a proposal with a fixed monthly fee, agreed after the scoping call, follows within 48 hours of that call. Optional extras outside the agreed scope are billed at the day rate.