General Services
8 questionsCyberSec provides a comprehensive suite of cybersecurity services including Penetration Testing, Attack Surface Management, Data Exposure Monitoring, Source Code Review, Cyber Investigation, and Zero Trust Architecture consulting.
We also offer broader technology services: Game Development (2D/3D, Unity, NFT), AI-driven solutions, Satellite Communications, PCB Development, Cloud Architecture, and Software Development.
We work with organizations of all sizes — from startups and SMEs to multinational enterprises and government agencies. Our service packages and engagement models are flexible to suit different budgets and risk profiles.
Smaller organizations often benefit from our automated security testing and compliance readiness services as cost-effective entry points. Larger clients typically engage us for full red team operations and managed security programs.
Getting started is straightforward. The typical process looks like this:
- Submit an enquiry via our contact form or email us directly
- We schedule a discovery call (30–60 minutes) to understand your environment and objectives
- Our team prepares a tailored scope and proposal within 2–3 business days
- Upon agreement and onboarding, we begin within your preferred timeframe
We offer both. Point-in-time assessments (penetration tests, code reviews, audits) are available as standalone engagements. We also offer continuous monitoring programs including Attack Surface Management and continuous penetration testing that provide ongoing visibility.
Retainer-based arrangements are available for clients requiring regular testing cadences or advisory access to our security team throughout the year.
Yes. Our security team holds industry-recognized certifications including:
- OSCP (Offensive Security Certified Professional)
- CEH (Certified Ethical Hacker)
- CISSP (Certified Information Systems Security Professional)
- CISA and CISM (ISACA certifications)
- CompTIA Security+, PenTest+, and CySA+
- Cloud security certifications: AWS Security Specialty, Azure Security Engineer
We have deep expertise across several regulated and high-risk industries including financial services, healthcare, government & defense, technology, e-commerce, telecommunications, and critical infrastructure.
Each industry brings unique compliance requirements and threat profiles — our team understands these nuances and tailors assessments accordingly.
Yes. Every assessment includes a remediation consultation session at no additional cost — we walk through findings, prioritize fixes, and answer your team's questions. For clients requiring hands-on remediation support, we offer dedicated remediation engagements and follow-up retesting to verify fixes are effective.
Absolutely. We routinely execute mutual NDAs before any discovery calls or information sharing. Confidentiality is foundational to our practice — your systems, vulnerabilities, and business information are never disclosed to third parties.
Pricing & Billing
5 questionsPricing is scope-based and depends on several factors: number of targets (IPs, URLs, applications), testing methodology (automated vs. manual), engagement duration, complexity of the environment, and required compliance deliverables.
We provide fixed-fee proposals — no surprise overages. Use our Cost Calculator for an instant estimate, or request a formal quote tailored to your exact requirements.
Yes. For larger engagements we typically structure billing as a 50% deposit upon contract signing and 50% upon report delivery. Multi-phase projects may have milestone-based payment schedules. Speak with our accounts team for arrangements that work for your organization.
We accept payments in USD, EUR, GBP, and several other major currencies. Payment methods include bank transfer (preferred), major credit cards, and for enterprise clients, purchase order arrangements. All transactions are processed securely through PCI-DSS compliant channels.
We offer a free 30-minute security consultation to discuss your environment and risks. For new enterprise clients, we sometimes offer a limited-scope proof-of-concept assessment at a reduced rate to demonstrate methodology and report quality before committing to a full engagement. Contact us to discuss.
If you cancel an engagement before work has commenced, your deposit is fully refundable within 5 business days. Once testing or development work has begun, fees are non-refundable for completed work phases. We are committed to delivering to the agreed scope — if we fall short, we make it right. Please see our Terms & Conditions for full details.
Legal & Compliance
5 questionsYes. Our reports include a compliance mapping appendix that cross-references identified findings against applicable frameworks. We currently support mapping to PCI-DSS v4.0, ISO/IEC 27001:2022, SOC 2 (Security TSC), HIPAA, GDPR, and NIST CSF.
We can also provide a letter of attestation confirming the scope, methodology, and completion of the assessment for your auditors.
Any sensitive data encountered during testing (PII, payment card data, credentials) is handled per our strict data handling policy: it is not accessed beyond what is necessary to demonstrate the vulnerability, never exfiltrated from your environment in real form, and all test artifacts are securely destroyed within 30 days of report delivery.
Yes. As a data processor for our clients, we operate under a Data Processing Agreement (DPA) that meets GDPR requirements. We process only the minimum personal data necessary for service delivery, maintain appropriate technical and organizational measures, and support your rights as a data controller including breach notification obligations.
Yes. CyberSec carries professional indemnity (errors & omissions) insurance and cyber liability insurance. Certificates of insurance can be provided upon request during the contract stage. Coverage details are available to enterprise clients on request.
Before any testing commences, we require: a signed Statement of Work (SOW) or Letter of Authorization (LoA), an agreed Rules of Engagement document, and for cloud environments, written confirmation from the cloud provider where required (e.g., AWS requires notification for some test types).
If third-party systems are in scope (e.g., a SaaS platform you use), authorization from those system owners must also be obtained. Our team guides you through this process.
Technical Questions
5 questionsOur methodology is framework-driven, following OWASP Testing Guide, PTES (Penetration Testing Execution Standard), NIST SP 800-115, and MITRE ATT&CK. We use a combination of commercial tools (Burp Suite Pro, Nessus, Cobalt Strike) and proprietary tooling developed in-house.
We never rely solely on automated scanners — every engagement involves significant manual testing effort to catch logic flaws and business-specific vulnerabilities that tools miss.
Yes. We conduct cloud security assessments across all three major platforms. This includes IAM configuration review, misconfiguration analysis, network security group auditing, serverless function security, container and Kubernetes security, and cloud-specific penetration testing.
For AWS and Azure, certain test types require advance notification to the cloud provider — we handle this process on your behalf.
Yes — and combining both yields the best results. Source Code Review (Static Analysis) surfaces vulnerabilities at the code level that may not be exploitable externally but represent latent risk. Combined with dynamic penetration testing, you get comprehensive coverage of both the "inside view" and the "attacker's view" of your application's security posture.
Our team has expertise across a broad range of languages and frameworks including Python, JavaScript/TypeScript (Node.js, React), Java, C/C++, C#/.NET, PHP, Go, Ruby on Rails, Swift, Kotlin, and Rust. We can review microservices, monoliths, mobile backends, and infrastructure-as-code (Terraform, CloudFormation).
Code can be shared via a private, encrypted repository (we provision a dedicated instance), secure file transfer, or by granting read-only access to your existing repository with scoped credentials. All code is stored in encrypted environments, accessed only by the assigned reviewers, and permanently deleted upon delivery of the final report.
No matching questions found
Try different keywords or ask us directly.