Skip to content
CyberSmithSECURE
Under Attack

CERT-In Empanelled Security Auditor

Penetration Testing That Doesn’t End With a PDF.

Continuous, expert-led penetration testing across Web, API, Mobile, Network, Cloud and Active Directory — with remediation guidance, revalidation and continuous visibility into your security posture.

No-obligation scoping. Tell us what you need tested and we’ll help define the right assessment.

Why it matters

72%

Data leakage or loss

Industry figures on the most common causes of security incidents. A single unaddressed vulnerability in a network-attached device is enough for a material loss.

Unauthorised access to company data and systems
56%Unauthorised access to company data and systems
Users downloading unsafe apps or content
54%Users downloading unsafe apps or content
Malware
52%Malware

Services

Every engagement produces a technical report and an executive summary — the two audiences need different documents, not the same one twice.

GRC

Twenty services, one consistent way of thinking about assurance: understand the requirement, understand the risk, implement the control, and prove that it works.

GRC

Standards (ISO/IEC 27001, 27701, 42001), privacy and data protection (GDPR, DPDPA, PIA/DPIA), security frameworks (NIST CSF, NIST SP 800-53, SOC 2, PCI DSS, HIPAA), assurance and risk services, business resilience, and security leadership.

What this involves

VAPT

A comprehensive testing approach that identifies vulnerabilities and actively exploits them to assess real security posture.

VAPT

Testing covers web and mobile applications, APIs, networks, thick clients, Active Directory, cloud platforms and OT environments. Findings arrive with proof, business impact and a remediation path, not just a scanner list.

What this involves

Configuration Review

Identifying optimal configurations against CIS benchmarks, because most breaches trace back to misconfiguration rather than an unknown flaw.

Configuration Review

Reviews cover firewalls, endpoints, switches, Microsoft 365, Google Workspace, MDM, DLP, backup, Active Directory, PAM, IAM, CASB, SASE and SAP.

What this involves

Red Teaming

Simulating real-world attack scenarios to test whether security measures hold under an adversary who is trying, not a checklist.

Red Teaming

Engagements run against cloud, infrastructure and people, and increasingly against AI systems — LLM applications, agent tooling and the trust boundaries between them.

What this involves

Phishing Simulation & Awareness

The human layer is the largest attack surface. We measure it, then improve it.

Phishing Simulation & Awareness

Campaigns run as a baseline, followed by targeted training and a repeat campaign, so the result is a trend rather than a single score.

What this involves

Incident Response & Ransomware Recovery

When an incident is live, the priority is containment and getting the business back — analysis comes after.

Incident Response & Ransomware Recovery

Containment, eradication, recovery and forensic analysis, following the NIST SP 800-61 lifecycle. Ransomware work includes backup validation, decryption feasibility and clean rebuild guidance.

What this involves

Vulnerability Fixation

Finding vulnerabilities is the easy part. Most assessments produce a backlog rather than a fix.

Vulnerability Fixation

Validation, prioritisation and remediation carried out with your teams or directly, then verified by retest so closure is evidenced rather than assumed.

What this involves

Frameworks

Mapped to the standards you already use

Testing is aligned to OWASP, PTES, NIST SP 800-115 and CIS benchmarks. Red team work is mapped to MITRE ATT&CK, and to MITRE ATLAS for AI systems.

  • OWASP
  • CIS Benchmarks
  • PTES
  • NIST SP 800-115
  • CERT-In
  • MITRE ATT&CK
  • MITRE ATLAS
  • NIST SP 800-61
  • ISO/IEC 27001

Our approach

The same sequence whether it is one application or a full network. Nothing starts until scope is agreed in writing.

  1. STEP 01

    Scope & Risk Analysis

    Agree what is in scope, what it is worth, and what would hurt.

  2. STEP 02

    Security Architecture Analysis

    Understand how the environment is built before trying to break it.

  3. STEP 03

    Threat Modeling

    Work out who would attack this, and how they would go about it.

  4. STEP 04

    Test Plan & Preparation

    A written plan, agreed in advance. No surprises during execution.

  5. STEP 05

    Test Execution

    Controlled testing against the agreed scope, evidenced as it goes.

  6. STEP 06

    Document & Report Findings

    Proof, business impact and severity — not a scanner dump.

  7. STEP 07

    Recommend Remediation

    What to fix, in what order, and how to confirm it is fixed.

Near zero

Reduced security defects

5×

Faster threat detection

Trusted by

  • Swiggy
  • ICICI Lombard
  • Ather
  • SLK Global
  • NSDL
  • Capita
  • SpotOn Logistics
  • MitKat Advisory
  • CyberFrat
  • Prime
  • Cogknit Semantics
  • BYJU'S
  • Delhivery
  • Coforge
  • redBus
  • WhiteHat Jr
  • Mahanagar Gas
  • Brigade
  • DB Corp
  • Prudent
  • Technovert
  • keka
  • Advantage Go
  • Go-MMT
  • MakeMyTrip
  • Goibibo
  • TripMoney
  • Bharat Petroleum
  • Arjas Steel
  • African Industries Group
  • Samara Capital
  • Molbio
  • Aegis
  • BYJU'S Future School
  • Cycle Agarbathi
  • Paradise Biryani
  • Computer Society of India
  • ISAC
  • upGrad
  • Uno.ai
  • Ashwin Sheth Group
  • Invesco Mutual Fund
  • ICICI Prudential Mutual Fund
  • Nippon India Mutual Fund
  • Enterpret

Who we work with

Most engagements are confidential. Sector and scale is what we can say about the rest.

$1B

Insurance & Fintech

$200B

Private Equity

$739M

Automobile

$200M

Health & Pharma

$25M

SaaS & e-Commerce

Capability statementWho we work with, what they say, the six service lines and 54 capabilities, and anonymised engagement evidence.
Download PDF3.4 MB

In their words

Reproduced as published, from CyberSmithSECURE’s capability statement and from recommendations left on the record.

I had the privilege of working closely with Smith Gonsalves and his team during their engagement for Vulnerability Assessments, Penetration Testing, Red Teaming etc. Smith's expertise and meticulous approach to cybersecurity were instrumental in ensuring our systems remained robust and resilient against potential threats.
AMArup MandalVP — IT, Infosec & Data Privacy · Ather Energy
CyberSmithSECURE has helped us very much in strengthening our defensive as well as offensive capabilities in terms of cyber security. Smith has come through and exceeded all our expectations.
SJSneha JoshiHead of Information Security · Capita
It was a pleasure working with CyberSmithSECURE team who we recommend as the best in managed security services. The Team is very professional and they are dedicated to ensuring 360 degree cyber safety for an organization.
RKRajesh KapaseDirector IT · Delhivery
Smith has an eye for detail and a nose to sniff out the more surreptitious vulnerabilities on the network or the system, and his impeccable investigative skills are noteworthy. CyberSmithSECURE services has always added value to SLK Global solutions.
SNSanil NadkarniCISO & VP · SLK Global
CyberSmithSECURE is one of the most reliable organisations in cyber security consulting arena, we have come across. They are specialized in Red teaming & Penetration testing. They have built up a dedicated team who are innovative and passionate. Their work speaks for themselves.
SBSudipta BiswaCISO & VP · INFOSERV

Dealing with a live incident?

Call us. No form, no queue, no ticket — the number reaches a person.

+91 98231 01337