Why IMIZI Cyber
Automated scanners find known issues quickly, and we use them for coverage. The vulnerabilities that matter most in a regulated environment are usually the ones a scanner cannot reason about: business logic flaws, authentication bypasses, and attack paths chained across systems.
We run every engagement by hand, using recognised offensive-security methodology and the attacker techniques that matter in BNR-supervised environments. This methodology routinely surfaces the access-control and authentication flaws that scanners miss, such as IDOR and broken object-level authorisation, JWT validation gaps, and privilege-escalation paths chained across networks. Every report is written by hand by the person who ran the engagement.
Banks, fintechs, telecoms, government bodies and healthcare institutions get the same engagement: testing led by an OSCP-credentialled practitioner and a report written to hold up with regulators, boards and counterparties.
How a penetration test works
Every engagement follows the same six stages, and we keep you informed at each one.
Scoping
We define targets, methodology, rules of engagement, and success criteria together. You know exactly what we will test and how.
Reconnaissance
Passive and active information gathering to map your attack surface, the same approach a real adversary would take.
Exploitation
Manual testing and exploitation of the vulnerabilities we find. We chain findings together to show what an attacker could actually reach.
Reporting
A technical report with an executive summary, proof-of-concept evidence, CVSS risk ratings and prioritised remediation guidance.
Debrief
Walkthrough session with your technical team and management. We explain every finding and answer questions.
Re-test
One re-test round is included: we verify every Critical and High finding, and any Medium fixed by the re-test date, then issue a closure letter.
What you receive
Every penetration test produces the following:
- Executive summary: non-technical overview for board and management, with risk ratings and strategic recommendations
- Technical findings report: each vulnerability documented with description, affected system, CVSS v3.1 score, proof-of-concept evidence (screenshots, HTTP requests/responses), and step-by-step reproduction instructions
- Remediation guidance: prioritised fix recommendations for each finding, including specific configuration changes, code patches, or architectural improvements
- Risk heat map: visual summary of findings by severity and affected system for compliance reporting
- Live debrief session: walkthrough with your technical team and management explaining every finding and answering questions
- Re-test report and closure letter: one re-test round is included. We verify every Critical and High finding, and any Medium fixed by the re-test date, then issue a closure letter for your regulator or auditor
Every finding in your report follows this format: severity, CVSS score, the affected system, evidence and the fix, with its status after the re-test. Illustrative example, no client data.
How pricing works
- Fixed price per engagement: agreed after the scoping call and based on what is in scope, with no hourly billing
- Paid per milestone: each milestone is invoiced on your acceptance
- Re-test included: one re-test round is part of every engagement
- Optional extras at the day rate: further re-test rounds or added scope are billed at our day rate
What drives the price, and how to scope a test: penetration testing cost in Rwanda. For the wider buyer's view, read our guide to penetration testing in Rwanda.
Before you sign
- NDA first: we sign a non-disclosure agreement before you share any system detail
- Written authorisation and signed scope: testing starts only after both are signed
- Activity log on request: a log of testing activity, including our source IP addresses, so your team can match it against your own monitoring
The full detail is on how we handle your data.
Who this is for
We test for regulated institutions across Africa, where a breach brings regulatory consequences as well as financial loss.
- Banks and BNR-supervised enterprises: commercial banks, microfinance institutions, and payment service providers working to the annual testing cycle in BNR Regulation N° 50/2022
- Government and ministries: public-sector bodies securing citizen-facing services, registries, and critical infrastructure
- Telecoms and mobile money operators: organisations handling millions of financial transactions daily
- Healthcare and insurance: hospitals and insurers managing sensitive patient and policyholder data under data-protection law
- Fintechs and startups: fast-moving companies that need security validation before launch or fundraising
Compliance alignment
Penetration testing is referenced across several frameworks that apply to regulated institutions in Rwanda and across Africa. Testing is one input to compliance. Our methodology and reporting supply the technical evidence these frameworks call for:
- BNR Regulation N° 50/2022: requires supervised institutions to conduct a penetration test at least annually and vulnerability assessments at least twice a year, with results filed with the National Bank of Rwanda. See our dedicated BNR-compliant penetration testing service for the full mandate, cadence, and reporting detail
- PCI DSS v4.0: Requirement 11.4 mandates external and internal penetration testing at least annually and after significant changes. Requirement 11.3 requires quarterly vulnerability scanning. Requirement 6.2 requires secure development practices and software security testing throughout the development lifecycle
- ISO 27001:2022: Annex A Control 8.8 (Management of technical vulnerabilities) requires timely identification and remediation of vulnerabilities. Control 5.35 (Independent review of information security) mandates independent security reviews. Control 8.34 (Protection of information systems during audit testing) governs how testing is conducted safely in production environments. ISO 27001 does not mandate penetration testing outright; our testing supplies evidence that supports these controls
- SOC 2: examinations against the AICPA Trust Services Criteria are performed by licensed CPA firms. Penetration test reports are among the most common evidence items those auditors request when evaluating the Security criteria; our testing and reporting supply that evidence
- SWIFT CSP: the Customer Security Programme includes controls on vulnerability scanning and security assessment for institutions on the SWIFT network, and requires an independent assessment behind the annual attestation. See our SWIFT CSP independent assessment service
- Rwanda Data Protection Law N° 058/2021: requires data controllers to implement appropriate technical and organisational measures to protect personal data. Penetration testing provides evidence that supports this obligation. See our NCSA & Law N° 058/2021 security testing service
Our reports include the executive summary, technical detail, and remediation evidence that auditors and regulators expect. For institutions working toward PCI DSS, ISO 27001, or SOC 2, we handle the readiness side (gap preparation, testing evidence, remediation guidance) and can introduce you to independent audit and certification firms; the certificate or attestation is always issued by that independent third party. For more on BNR requirements, see our guide on BNR cybersecurity requirements for banks in Rwanda.
Frequently asked questions
How long does a penetration test take?
What certifications should we look for in a penetration testing provider?
Do you perform penetration testing for banks in Rwanda?
What is the difference between penetration testing and vulnerability assessment?
Will testing disrupt our systems?
What do we receive after the test?
How much does penetration testing cost in Rwanda?
Will you sign an NDA before we share system details?
Scope-specific detail: web application, API, and mobile application penetration testing, and red team exercises.
For a configuration and architecture review rather than an attack simulation, see our security assessments service.
If you want to build security testing into your development pipeline, explore our custom security tooling.
IMIZI Cyber went above and beyond our expectations: thorough analysis, fantastic reports and follow-ups. I was relieved at how trustworthy they were and how well it all went. We'll surely be using them again.
Tell us what you need tested
We reply within 24 hours to set up a scoping call, and a fixed-price proposal follows within 48 hours of that call.