Penetration testing and VAPT services in Rwanda

IMIZI Cyber is a penetration testing company in Kigali, Rwanda. We run manual Vulnerability Assessment and Penetration Testing (VAPT) for banks, fintechs, telecoms, government, ministries, healthcare and other regulated institutions in Rwanda and across Africa. Web application, network, mobile, API, and cloud testing, with the methodology set out below so your technical team can evaluate it before the first call. Every report is evidence-led and written by hand.

  • OWASP WSTG and PTES methodology
  • Testing led by an OSCP-credentialled practitioner
  • BNR-aligned reporting
  • Re-test included

What we test

Network penetration testing

Internal and external testing for misconfigurations, exposed services, privilege escalation and lateral movement across your infrastructure.

Web application testing

Authentication, session management, business logic, injection and access-control bypasses, tested against the OWASP Top 10. Web application testing in depth

Mobile app testing

Android and iOS banking apps: local storage, API communications, certificate pinning, tokens, and reverse engineering resistance. Mobile app testing in depth

API security testing

REST and GraphQL APIs: authentication bypasses, IDOR/BOLA, rate limiting, data exposure, and business logic abuse. API testing in depth

Cloud security testing

AWS, Azure, and GCP environments: IAM misconfigurations, exposed storage, network segmentation, and privilege-escalation paths across your cloud footprint.

Adversary simulation

Full-scope adversary simulation that chains exploitation across your web, network, cloud and API attack surface to show what an attacker could reach. Red team services

Why IMIZI Cyber

Automated scanners find known issues quickly, and we use them for coverage. The vulnerabilities that matter most in a regulated environment are usually the ones a scanner cannot reason about: business logic flaws, authentication bypasses, and attack paths chained across systems.

We run every engagement by hand, using recognised offensive-security methodology and the attacker techniques that matter in BNR-supervised environments. This methodology routinely surfaces the access-control and authentication flaws that scanners miss, such as IDOR and broken object-level authorisation, JWT validation gaps, and privilege-escalation paths chained across networks. Every report is written by hand by the person who ran the engagement.

Banks, fintechs, telecoms, government bodies and healthcare institutions get the same engagement: testing led by an OSCP-credentialled practitioner and a report written to hold up with regulators, boards and counterparties.

How a penetration test works

Every engagement follows the same six stages, and we keep you informed at each one.

How a penetration test runs, in six steps Before testing: scoping. Testing: reconnaissance, then exploitation. After testing: reporting, a debrief with your team, and a re-test that ends in a closure letter. Before testing Testing After testing 01 Scoping Targets and rules agreed 02 Reconnaissance Attack surface mapped 03 Exploitation Findings chained by hand 04 Reporting Evidence and CVSS ratings 05 Debrief With your team 06 Re-test Closure letter How a penetration test runs, in six steps Before testing: scoping. Testing: reconnaissance, then exploitation. After testing: reporting, a debrief with your team, and a re-test that ends in a closure letter. Before testing 01 Scoping Targets and rules agreed Testing 02 Reconnaissance Attack surface mapped 03 Exploitation Findings chained by hand After testing 04 Reporting Evidence and CVSS ratings 05 Debrief With your team 06 Re-test Closure letter

Scoping

We define targets, methodology, rules of engagement, and success criteria together. You know exactly what we will test and how.

Reconnaissance

Passive and active information gathering to map your attack surface, the same approach a real adversary would take.

Exploitation

Manual testing and exploitation of the vulnerabilities we find. We chain findings together to show what an attacker could actually reach.

Reporting

A technical report with an executive summary, proof-of-concept evidence, CVSS risk ratings and prioritised remediation guidance.

Debrief

Walkthrough session with your technical team and management. We explain every finding and answer questions.

Re-test

One re-test round is included: we verify every Critical and High finding, and any Medium fixed by the re-test date, then issue a closure letter.

What you receive

Every penetration test produces the following:

Every finding in your report follows this format: severity, CVSS score, the affected system, evidence and the fix, with its status after the re-test. Illustrative example, no client data.

How pricing works

What drives the price, and how to scope a test: penetration testing cost in Rwanda. For the wider buyer's view, read our guide to penetration testing in Rwanda.

Before you sign

The full detail is on how we handle your data.

Who this is for

We test for regulated institutions across Africa, where a breach brings regulatory consequences as well as financial loss.

Compliance alignment

Penetration testing is referenced across several frameworks that apply to regulated institutions in Rwanda and across Africa. Testing is one input to compliance. Our methodology and reporting supply the technical evidence these frameworks call for:

Our reports include the executive summary, technical detail, and remediation evidence that auditors and regulators expect. For institutions working toward PCI DSS, ISO 27001, or SOC 2, we handle the readiness side (gap preparation, testing evidence, remediation guidance) and can introduce you to independent audit and certification firms; the certificate or attestation is always issued by that independent third party. For more on BNR requirements, see our guide on BNR cybersecurity requirements for banks in Rwanda.

Frequently asked questions

How long does a penetration test take?
Typical engagements run 1 to 6 weeks depending on scope. A focused web application test may take 3 to 5 business days, while a full network and application engagement for a regulated enterprise can take several weeks.
What certifications should we look for in a penetration testing provider?
For technical depth, look for hands-on offensive-security certifications such as OSCP and PNPT, alongside a demonstrable track record inside regulated environments. Our testing is led by an OSCP-credentialled practitioner, follows recognised offensive-security methodology, and is BNR-aligned; every report is written by hand by the person who ran the engagement. Individual credentials are listed on our about page.
Do you perform penetration testing for banks in Rwanda?
Yes. IMIZI Cyber delivers manual VAPT for BNR-supervised financial institutions including commercial banks, MFIs, and payment providers across Rwanda and the wider African market. Testing is BNR-aligned and supplies the technical evidence that PCI DSS, ISO 27001, and SOC 2 programmes require. Certification and attestation are issued by independent third parties; we provide the testing and evidence component.
What is the difference between penetration testing and vulnerability assessment?
A vulnerability assessment uses automated scanners to identify known weaknesses. Penetration testing goes further: we exploit vulnerabilities by hand to show their business impact, chaining findings together the way an attacker would. We provide both, but recommend manual penetration testing for regulated organisations.
Will testing disrupt our systems?
Testing is scoped and scheduled in advance, and we stay in contact with your team throughout the engagement. On production systems we use non-destructive techniques and can test outside peak hours. If anything unexpected happens, we stop and agree the next step with your team.
What do we receive after the test?
An evidence-led report including an executive summary for management, detailed technical findings with proof-of-concept evidence, CVSS risk ratings, and prioritised remediation guidance, followed by a live debrief session. One re-test round is included: we verify every Critical and High finding, and any Medium fixed by the re-test date, then issue a closure letter.
How much does penetration testing cost in Rwanda?
Cost depends on the number of applications, infrastructure complexity, and testing depth. Each engagement has a fixed price, agreed after the scoping call and based on what is in scope. You pay per milestone on acceptance, the re-test round is included, and optional extras such as further re-test rounds are billed at the day rate. Tell us your requirements; we reply within 24 hours, and a fixed-price proposal follows within 48 hours of the scoping call.
Will you sign an NDA before we share system details?
Yes. We sign a non-disclosure agreement before you share any system detail, and testing starts only after you sign a written authorisation and the agreed scope. See how we handle your data.

Scope-specific detail: web application, API, and mobile application penetration testing, and red team exercises.

For a configuration and architecture review rather than an attack simulation, see our security assessments service.

If you want to build security testing into your development pipeline, explore our custom security tooling.

IMIZI Cyber went above and beyond our expectations: thorough analysis, fantastic reports and follow-ups. I was relieved at how trustworthy they were and how well it all went. We'll surely be using them again.

Peter P. Founder, U.S. legal-tech SaaS

Tell us what you need tested

We reply within 24 hours to set up a scoping call, and a fixed-price proposal follows within 48 hours of that call.