Manual security assessments for regulated institutions across Africa

Manual security assessments for banks, fintechs, telecoms, government, ministries, healthcare and other regulated institutions across Africa. We review how your systems are built and configured (servers, network devices, databases, cloud estates, architecture, and code) against security benchmarks, with findings mapped to the frameworks your auditors test against. Every report is evidence-led and written by hand.

  • Configuration and architecture review
  • CIS benchmarks and vendor hardening guides
  • Findings mapped to BNR, PCI DSS and ISO 27001
  • Re-test included

What we assess

Vulnerability assessment

We identify security weaknesses across your infrastructure and applications and validate each one by hand, so false positives never reach your report.

Configuration audit

Review of server, network, database and application configurations against security benchmarks and vendor hardening guides.

Cloud security assessment

AWS, Azure, and GCP environment reviews covering IAM, network security, storage permissions, logging, and compliance with CIS benchmarks.

Compliance gap analysis

Map your current security controls against BNR, PCI DSS, ISO 27001, SOC 2, and Rwanda Data Protection Law requirements, so you can close gaps before the audit.

Source code review

Manual code analysis for security vulnerabilities including injection flaws, insecure authentication, hardcoded credentials, and business logic errors.

Architecture review

Evaluate your system architecture for security weaknesses: network segmentation, data flows, trust boundaries, and defence-in-depth design.

Why IMIZI Cyber

We review configurations line by line against CIS benchmarks and vendor hardening guides: server builds, network devices, databases, and the IAM, storage and logging posture of your AWS, Azure or GCP estate. Every finding records what we checked, what we found, and the exact setting or control that needs to change.

We use automated tools for discovery and validate every finding by hand, so your team fixes real weaknesses instead of triaging false positives. Findings are mapped to the BNR, PCI DSS, ISO 27001, SOC 2 and Rwanda Data Protection Law controls they affect, so the report also serves as audit evidence.

Banks, fintechs, telecoms, government bodies and healthcare institutions get a report on their own environment that holds up with regulators, boards and auditors. For organisations that also need adversarial testing, we recommend combining assessments with our penetration testing service.

How a security assessment works

Every engagement follows the same six stages.

Scoping

We define the assessment scope, objectives, and success criteria together. You know exactly what will be assessed, which frameworks apply, and what deliverables to expect.

Asset discovery

Full mapping of your systems, applications, network segments, and data flows. We identify assets you may not know are exposed.

Assessment

Manual and tool-assisted evaluation of each asset against security benchmarks and compliance requirements. We validate every finding by hand.

Analysis

Correlation of findings across systems to identify systemic issues, attack paths, and risk patterns, with each weakness mapped to its business impact.

Reporting

A report with an executive summary, technical findings with evidence, risk ratings, compliance mapping and prioritised remediation guidance.

Remediation support

Debrief session with your team. We walk through every finding and support you as you implement fixes. One re-test round is included: we verify every Critical and High finding, and any Medium fixed by the re-test date, then issue a closure letter.

Who this is for

We assess regulated institutions across Africa, where a breach brings regulatory consequences as well as financial loss.

Compliance alignment

Security assessments are referenced across several frameworks that apply to regulated institutions in Rwanda and across Africa. Assessment is one input to compliance. Our methodology and reporting supply the technical evidence these frameworks call for:

Our reports include the executive summary, technical detail, and remediation evidence that auditors and regulators expect. For institutions working toward PCI DSS, ISO 27001, or SOC 2, we handle the readiness side (gap preparation, testing evidence, remediation guidance) and can introduce you to independent audit and certification firms; the certificate or attestation is always issued by that independent third party. For more on BNR requirements, see our guide on BNR cybersecurity requirements for banks in Rwanda.

Frequently asked questions

How long does a security assessment take?
Timelines vary by scope. A focused vulnerability assessment may take 3 to 5 business days, while a full assessment covering infrastructure, applications and compliance gaps typically takes 2 to 4 weeks. You get a detailed timeline at scoping.
What certifications should we look for in a security assessment provider?
For technical depth, look for hands-on offensive-security certifications such as OSCP and PNPT, alongside a demonstrable track record inside regulated environments. Our assessments are led by an OSCP-credentialled practitioner, follow recognised offensive-security methodology, and are BNR-aligned; every report is written by hand by the person who ran the engagement. Individual credentials are listed on our about page.
What is the difference between a security assessment and a penetration test?
A security assessment reviews how your systems are built and configured: server, network and database configurations, cloud posture, architecture, and code, checked against security benchmarks and framework controls. A penetration test is a focused adversarial simulation that exploits specific vulnerabilities to demonstrate impact. We often recommend both as complementary engagements. Learn more in our article on penetration testing vs vulnerability assessment for banks.
How much does a security assessment cost in Rwanda?
Every engagement is scoped individually based on the number of systems, assessment depth, and compliance requirements. Each engagement has a fixed price, agreed after the scoping call and based on what is in scope. You pay per milestone on acceptance, the re-test round is included, and optional extras such as further re-test rounds are billed at the day rate. Contact us with your requirements; we reply within 24 hours, and a fixed-price proposal follows within 48 hours of the scoping call.
What do we receive after the assessment?
An evidence-led report including an executive summary for management, detailed technical findings with evidence, risk ratings, compliance mapping against relevant frameworks, prioritised remediation guidance, a live debrief session, and ongoing support during remediation.
Do you assess cloud environments?
Yes. We assess AWS, Azure, and GCP environments including IAM configurations, network security, storage permissions, logging, and compliance with cloud security benchmarks such as CIS. Cloud assessments can be conducted independently or as part of a broader security review.
Can you help us prepare for a compliance audit?
Yes. Our gap analysis maps your controls against BNR, PCI DSS, ISO 27001, SOC 2, and Rwanda Data Protection Law requirements before your audit, giving you time to remediate and build evidence. We provide a prioritised roadmap, supply the technical testing evidence auditors request, and can introduce you to independent audit and certification firms. Certification and attestation are always issued by those independent firms.

Tell us what you need assessed

We reply within 24 hours to set up a scoping call, and a fixed-price proposal follows within 48 hours of that call.