>
Help Center

Frequently Asked Questions

Answers to the questions we hear most. Can't find what you're looking for? Our team responds within one business day.

60+
Questions Answered
7
Topic Categories
<1d
Support Response

General Services

8 questions
What types of cybersecurity services does CyberSec offer?

CyberSec provides a comprehensive suite of cybersecurity services including Penetration Testing, Attack Surface Management, Data Exposure Monitoring, Source Code Review, Cyber Investigation, and Zero Trust Architecture consulting.

We also offer broader technology services: Game Development (2D/3D, Unity, NFT), AI-driven solutions, Satellite Communications, PCB Development, Cloud Architecture, and Software Development.

Not sure which service fits your needs? Request a free consultation and we'll map your risks to the right solution.
Do you work with small businesses or only large enterprises?

We work with organizations of all sizes — from startups and SMEs to multinational enterprises and government agencies. Our service packages and engagement models are flexible to suit different budgets and risk profiles.

Smaller organizations often benefit from our automated security testing and compliance readiness services as cost-effective entry points. Larger clients typically engage us for full red team operations and managed security programs.

How do I get started with a security assessment?

Getting started is straightforward. The typical process looks like this:

  • Submit an enquiry via our contact form or email us directly
  • We schedule a discovery call (30–60 minutes) to understand your environment and objectives
  • Our team prepares a tailored scope and proposal within 2–3 business days
  • Upon agreement and onboarding, we begin within your preferred timeframe
Most engagements can begin within 1–2 weeks of contract execution. Urgent assessments can often be expedited.
Do you offer ongoing managed security services or only one-time assessments?

We offer both. Point-in-time assessments (penetration tests, code reviews, audits) are available as standalone engagements. We also offer continuous monitoring programs including Attack Surface Management and continuous penetration testing that provide ongoing visibility.

Retainer-based arrangements are available for clients requiring regular testing cadences or advisory access to our security team throughout the year.

Are your security consultants certified?

Yes. Our security team holds industry-recognized certifications including:

  • OSCP (Offensive Security Certified Professional)
  • CEH (Certified Ethical Hacker)
  • CISSP (Certified Information Systems Security Professional)
  • CISA and CISM (ISACA certifications)
  • CompTIA Security+, PenTest+, and CySA+
  • Cloud security certifications: AWS Security Specialty, Azure Security Engineer
What industries do you specialize in?

We have deep expertise across several regulated and high-risk industries including financial services, healthcare, government & defense, technology, e-commerce, telecommunications, and critical infrastructure.

Each industry brings unique compliance requirements and threat profiles — our team understands these nuances and tailors assessments accordingly.

Do you provide post-assessment remediation support?

Yes. Every assessment includes a remediation consultation session at no additional cost — we walk through findings, prioritize fixes, and answer your team's questions. For clients requiring hands-on remediation support, we offer dedicated remediation engagements and follow-up retesting to verify fixes are effective.

Can you sign an NDA before the engagement begins?

Absolutely. We routinely execute mutual NDAs before any discovery calls or information sharing. Confidentiality is foundational to our practice — your systems, vulnerabilities, and business information are never disclosed to third parties.

Pricing & Billing

5 questions
How is pricing determined for security assessments?

Pricing is scope-based and depends on several factors: number of targets (IPs, URLs, applications), testing methodology (automated vs. manual), engagement duration, complexity of the environment, and required compliance deliverables.

We provide fixed-fee proposals — no surprise overages. Use our Cost Calculator for an instant estimate, or request a formal quote tailored to your exact requirements.

Do you offer payment plans or deferred billing?

Yes. For larger engagements we typically structure billing as a 50% deposit upon contract signing and 50% upon report delivery. Multi-phase projects may have milestone-based payment schedules. Speak with our accounts team for arrangements that work for your organization.

What currencies and payment methods do you accept?

We accept payments in USD, EUR, GBP, and several other major currencies. Payment methods include bank transfer (preferred), major credit cards, and for enterprise clients, purchase order arrangements. All transactions are processed securely through PCI-DSS compliant channels.

Is there a free trial or proof-of-concept engagement available?

We offer a free 30-minute security consultation to discuss your environment and risks. For new enterprise clients, we sometimes offer a limited-scope proof-of-concept assessment at a reduced rate to demonstrate methodology and report quality before committing to a full engagement. Contact us to discuss.

What is your refund policy?

If you cancel an engagement before work has commenced, your deposit is fully refundable within 5 business days. Once testing or development work has begun, fees are non-refundable for completed work phases. We are committed to delivering to the agreed scope — if we fall short, we make it right. Please see our Terms & Conditions for full details.

Technical Questions

5 questions
What tools and methodologies do you use for testing?

Our methodology is framework-driven, following OWASP Testing Guide, PTES (Penetration Testing Execution Standard), NIST SP 800-115, and MITRE ATT&CK. We use a combination of commercial tools (Burp Suite Pro, Nessus, Cobalt Strike) and proprietary tooling developed in-house.

We never rely solely on automated scanners — every engagement involves significant manual testing effort to catch logic flaws and business-specific vulnerabilities that tools miss.

Can you test our cloud infrastructure on AWS, Azure, or GCP?

Yes. We conduct cloud security assessments across all three major platforms. This includes IAM configuration review, misconfiguration analysis, network security group auditing, serverless function security, container and Kubernetes security, and cloud-specific penetration testing.

For AWS and Azure, certain test types require advance notification to the cloud provider — we handle this process on your behalf.

Do you provide source code review alongside penetration testing?

Yes — and combining both yields the best results. Source Code Review (Static Analysis) surfaces vulnerabilities at the code level that may not be exploitable externally but represent latent risk. Combined with dynamic penetration testing, you get comprehensive coverage of both the "inside view" and the "attacker's view" of your application's security posture.

What programming languages do you support for source code review?

Our team has expertise across a broad range of languages and frameworks including Python, JavaScript/TypeScript (Node.js, React), Java, C/C++, C#/.NET, PHP, Go, Ruby on Rails, Swift, Kotlin, and Rust. We can review microservices, monoliths, mobile backends, and infrastructure-as-code (Terraform, CloudFormation).

How do you securely handle our codebase during a source code review?

Code can be shared via a private, encrypted repository (we provision a dedicated instance), secure file transfer, or by granting read-only access to your existing repository with scoped credentials. All code is stored in encrypted environments, accessed only by the assigned reviewers, and permanently deleted upon delivery of the final report.

We can conduct the review entirely within your infrastructure (air-gapped environment) if required by your data classification policy.

No matching questions found

Try different keywords or ask us directly.

Didn't Find Your Answer?

Our team of experts is ready — reach out and we'll respond within one business day.