About
Art of cyber security, perfected
A CERT-In empanelled security firm working with organisations that have something worth protecting and a regulator asking about it.
How we work
In a connected estate the threat surface grows with every system, network and device you add. Testing exists to find what that growth introduced before somebody else does.
Reporting is deliberately split in two. A technical assessment carries reproduction steps and evidence. An executive summary carries risk in business terms. Most vendors produce one and let the other audience make do.
- Reduced security defects
- Near zeroReduced security defects
- Faster threat detection
- 5×Faster threat detection
Method
The same seven steps, every time
Consistency is the point. A repeatable sequence is what makes one engagement comparable to the next, and what makes a retest meaningful.
- 01
Scope & Risk Analysis
Agree what is in scope, what it is worth, and what would hurt.
- 02
Security Architecture Analysis
Understand how the environment is built before trying to break it.
- 03
Threat Modeling
Work out who would attack this, and how they would go about it.
- 04
Test Plan & Preparation
A written plan, agreed in advance. No surprises during execution.
- 05
Test Execution
Controlled testing against the agreed scope, evidenced as it goes.
- 06
Document & Report Findings
Proof, business impact and severity — not a scanner dump.
- 07
Recommend Remediation
What to fix, in what order, and how to confirm it is fixed.
Founder
Dr. Smith Gonsalves
Director & CEO, CyberSmithSECURE
Began as an ethical hacker and forensic investigator, assisting law enforcement and nodal agencies, and has since served as Chief Information Security Officer and security advisor to boards across SaaS, logistics, financial services and manufacturing.
He still practises. Formally a red team architect, he breaches companies and breaks products — which is what keeps the advice grounded in what actually works rather than in what a framework recommends.
“Evaluating a product by controls and price is not going to stop the breach that is bound to happen.”
- Red team architect
- Virtual CISO
Education & published
- PhD, Cyber Security
- Counter-Adversarial Simulations of Defensive and Offensive Systems Using Stochastic Games: Markov Models and Game Theory. Pacific Academy of Higher Education & Research University, Udaipur.
- Master's, Cyber Security
- University of Mumbai.
- Reviewing author
- Mastering Defensive Security, Packt Publishing. Columnist, “The War Is On”, FORCE Magazine.
Certifications
- OSCPOffensive Security Certified ProfessionalCleared at 19
- CISACertified Information Systems Auditor · ISACA
- CERT-In Empanelled AuditorGovt. of India
- CCSKCertificate of Cloud Security Knowledge · CSA
- TOGAFEnterprise Architecture · The Open Group
- CEHCertified Ethical Hacker · EC-CouncilCleared at 15
- CHFIComputer Hacking Forensic Investigator · EC-Council
Recognition
- Global 30 Under 30 in CybersecurityTop Cyber News Magazine, France · 2026
- CIO1000 APAC AwardEnterprise IT World
- Award of Excellence, Cyber Risk MitigationFuture Crime Research Foundation Summit · 2024
- India's Cyber SoldiersCyberFrat, Cyber Warfare Symposium
- Outstanding Young Cyber Security ProfessionalComputer Society of India, Mumbai Chapter
On the record
Colleagues, clients and mentors
Recommendations left publicly by people who managed him, hired him, or worked alongside him. Reproduced as published.
His technical virtuosity is such that he can sniff out the vulnerability time and again. Beyond a shadow of doubt, I will recommend him any time anywhere.
Smith Gonsalves is one of the youngest cyber security evangelists and an ethical hacker of great repute. He is a great asset to my organisation, and destined for great glory and success.
Smith is an assiduous champ, open minded, having plethora of knowledge. There is not a single question which Smith has not got an answer for.
Mr Smith Gonsalves is a very passionate and dedicated person who has a tremendous ability to relay his knowledge to others. I highly recommend Mr Smith to everyone looking for Cyber Security stuff.
Smith is a very hard-working person. He is one of the youngest Infosec professional around. Smith has good knowledge about the infosec domain.
Smith is energetic and very patriotic. I wish to see him as a Cyber Icon of India.
Presence
Where we are
Engagements run remotely by default. These are where the paperwork lives and where we can meet in person.
India
Mumbai
511, Ascot CentreMumbai 400099India
Virar (HQ)
Nanaji Apartment, UmbergothanVirar (W) 401301USA
New Jersey
381 Blair RoadAvenel, NJ 07001Canada
Ontario
Suite 750, 2 Robert Speck PkwyMississauga, ON L4Z 1H8UK
Glasgow
50 Mossbank DriveGlasgow G33 1LSKSA
Al Khobar
Al Khobar 31952P.O. Box 4607UAE
Dubai
308 Indigo Tower, Cluster DJLT, Dubai, P.O. Box 112965Wherever the estate is. Testing is remote by default, so the office list is about paperwork and meetings, not coverage.
Talk to us