Penetration testing and managed security for regulated organisations
OSCP-certified. Built for banks, telecoms, and government agencies across East Africa.
OSCP-certified, in Kigali
The only OSCP-certified penetration tester physically based in Rwanda. Not remote contractors, not scanner output.
We build custom tooling
Security validation tools in Python, Go, and JavaScript tailored to your specific APIs and systems.
Banking red team experience
Our consultants come from threat-led red team operations at European banks protecting millions of customers.
Three ways to work with us
Ongoing protection, targeted assessments, or training for your team.
Continuous Security
We deploy and manage security tooling across your environment and deliver monthly reports. An outsourced security function without the headcount.
Penetration Testing
Manual security assessments by an OSCP-certified consultant. For compliance, product launches, or regulatory sign-off.
Security Awareness Training
Hands-on cybersecurity training for employees and IT teams. From executive awareness to technical workshops for developers and security staff.
How we work
From scoping to remediation, we keep it straightforward.
Scoping call
We understand your environment, compliance needs, and testing objectives
Proposal and SOW
Clear scope, timeline, cost, and rules of engagement within 48 hours
Testing
1-3 weeks of manual testing with daily status updates on critical findings
Report and support
Detailed report with remediation guidance and 30 days of free follow-up
Independent offensive security consultancy, based in Kigali
imizicyber is a registered Rwandan security firm serving banks, government agencies, and enterprises across East Africa. We combine hands-on penetration testing with managed security tooling deployment.
From the field
Security insights for regulated organisations in East Africa.
BNR cybersecurity requirements: what banks in Rwanda need to know
A practical breakdown of the National Bank of Rwanda's cybersecurity regulation and what it means for your institution's security program.
Read more →How much does penetration testing cost in Rwanda?
Transparent pricing guide with real market ranges, from single web app assessments to full enterprise engagements.
Read more →VAPT in Rwanda: what organisations need to know
Complete guide to Vulnerability Assessment and Penetration Testing. Who needs it, what it covers, and how to choose a provider.
Read more →Penetration testing vs vulnerability scanning
Understanding the difference between automated scanning and manual penetration testing, and when you need each.
Read more →Why USSD banking services need security testing
USSD remains critical for financial inclusion in East Africa. Here is why *182# services need dedicated security assessments.
Read more →Common questions
Why do banks in Rwanda need penetration testing?
Do you help with BNR cybersecurity compliance?
How much does penetration testing cost in Rwanda?
What is BNR Regulation on cybersecurity?
What certifications do your consultants hold?
How often should banks do penetration testing?
What is the difference between VAPT and penetration testing?
Do I need ISO 27001 certification in Rwanda?
Do you offer cybersecurity training for employees?
Do you work with organisations outside Rwanda?
BNR requires regular security assessments. Is your institution compliant?
Get a free 30-minute scoping call to understand your compliance gaps.
Get in touch
We respond within 24 hours.