Structure Behind Every Engagement

Every service we deliver follows a documented, repeatable process, built on industry standards, refined through real engagements, and adapted to your specific environment. No black-box guesswork. No one-size-fits-all checklists.

All security assessments are point-in-time evaluations based on the scope and access available during the engagement. They do not guarantee the absence of all vulnerabilities. See our Terms for full details.

Both Co-founders on Every Engagement

Every Cybersecify deliverable has two layers: technical depth and business translation. Both layers matter, and neither works alone. A pentest report that's just a list of CVEs doesn't help a CEO decide what to fix. A compliance assessment that skips technical validation won't survive an auditor. The offensive and compliance work we deliver genuinely requires both layers, which is why both co-founders are actively involved in every engagement we run.

Rathnakara GN

Technical depth

OSCP-certified co-founder. M.Sc Cyber Security. Rathnakara handles the hands-on technical work: penetration testing, security architecture review, technical threat analysis, control validation, and incident response. This is the technical foundation every engagement is built on.

Ashok S Kamat

Business translation & client context

Semi-technical by design. Ashok understands the technology well enough to scope pentest engagements accurately and translate technical findings for business audiences. His focus is client relationship, scoping, business impact framing, compliance alignment, executive and board communication, and long-term program improvement.

Joint delivery in practice

One of us is usually the primary client contact, depending on the engagement type. Pentest buyers typically work with Rathnakara. Audit & Compliance buyers typically work with Ashok. But the primary contact is not the sole worker. Both co-founders contribute to every deliverable.

  • Pentest reports: Rathnakara writes the technical findings and remediation steps. Ashok refines the executive summary and frames the business impact for CEO, board, and investor audiences.
  • Audit & Compliance deliverables: Ashok handles policy, process, and management artifacts. Rathnakara handles technical attestation and control validation.
  • Incident response: Rathnakara leads the technical response. Ashok handles client communication and stakeholder coordination.

Most small security firms either stretch one person across technical work and business communication (one side is always weaker) or use a sales-to-engineer handoff where scope and execution disconnect. We have two co-founders whose skills are genuinely complementary, and both show up on every engagement. You never get a weak version of either layer.

No handoffs outside the founders. No BDRs, no junior analysts, no offshore teams. If you are talking to Cybersecify, you are talking to one of the two co-founders directly, and the other is in the room on the work.

Methodology by Service Area

Structured approaches across penetration testing and compliance audit readiness.

Our 6-Step Pentest Process

Every pentest engagement (web, API, mobile, cloud, IoT, or AI) follows this structured process, adapted to the specific scope.

OWASP

Open Web Application Security Project

Comprehensive OWASP coverage across every application type we test: web (Top 10, WSTG, ASVS), API (Top 10), mobile (Top 10, MASTG, MASVS), IoT (Top 10), cloud-native, LLM, and AI Exchange. SAMM for SDLC maturity mapping where relevant.

Top 10:2025WSTG v4.2API Top 10 (2023)Mobile Top 10 (2024)MASTGMASVSIoT Top 10 (2018)Cloud-Native Top 10LLM Top 10AI ExchangeASVS 5.0.0SAMM
PTES

Penetration Testing Execution Standard

Our engagement lifecycle follows PTES, from pre-engagement and intelligence gathering through exploitation, post-exploitation, and formal reporting.

Pre-EngagementIntel GatheringThreat ModellingExploitationPost-ExploitationReporting
Testing Approach

Grey-Box by Default

We work with authenticated access using both standard-user and admin-role credentials. This simulates external attacker scenarios (credential compromise, account takeover) AND insider threat scenarios (malicious or compromised employee) in a single engagement. Black-box (zero prior knowledge) and white-box (full source access) approaches available on request when the engagement requires.

STEP 01

Scoping & Planning

Define scope, testing objectives, rules of engagement, and communication protocols. Identify target systems, testing windows, and escalation contacts.

STEP 02

Reconnaissance

Map the attack surface, identify technologies and endpoints, discover hidden assets, and understand application business logic and data flows.

STEP 03

Vulnerability Discovery

Automated scanning combined with manual testing to find vulnerabilities, with emphasis on business logic flaws, chained attacks, and issues scanners miss.

STEP 04

Exploitation & Validation

Safely exploit findings to validate real-world impact. This demonstrates actual business risk rather than theoretical severity, so you can prioritise accurately.

STEP 05

Reporting

Executive summary, detailed findings with dual-scored CVSS v3.1 (NVD / CISA KEV parity) and CVSS v4.0 (current FIRST standard since November 2023) including documented vectors for reproducibility, proof-of-concept evidence, and developer-friendly remediation guidance for every vulnerability. Growth plan reports include SOC 2 + ISO 27001 control mapping per finding (Startup plan reports use identical structure without compliance mapping).

STEP 06

Retest & Verification

Free retest within one month of the report. We verify fixes are effective and issue an updated report confirming remediated issues and any remaining risk. Reports are versioned: Initial Report v1.0 at delivery, Final Report v2.x after retest confirms remediations.

From Gap to Audit-Ready

We take you from "we need ISO 27001 or SOC 2" to "we're audit-ready", combining technical controls testing with documentation, evidence collection, and management reporting.

STEP 01

Scope & Framework Selection

Identify applicable standards based on your industry, customer requirements, and geography. ISO 27001, SOC 2 Type 1/2, or multiple frameworks.

STEP 02

Current State Assessment

Review existing policies, controls, technical configurations, and documentation to understand your baseline compliance posture.

STEP 03

Gap Analysis & Risk Mapping

Map identified gaps to framework controls with risk-based prioritisation. Highlight critical findings that could impact external audit outcomes.

STEP 04

Remediation & Documentation

Guide your team through control implementation, policy creation, and evidence collection to address all identified gaps before the external audit.

STEP 05

Internal Audit Execution

Structured internal audits with evidence review, control testing, and stakeholder interviews to validate compliance readiness from an auditor's perspective.

STEP 06

Audit Readiness Report

Detailed audit report with findings, evidence gaps, and a compliance roadmap. Includes support for the external audit and ongoing readiness maintenance.

Standards we work with: ISO 27001SOC 2 Type 1SOC 2 Type 2NIST CSF

Security Testing Arsenal

Industry-standard tools guided by expert manual testing, across all service areas.

Web & API
Burp Suite Pro, OWASP ZAP, Nuclei, SQLMap, ffuf, Postman, custom Python scripts (IDOR enumeration, token lifecycle, chained exploit automation)
Mobile
Frida, Objection, MobSF, jadx, Hopper, SSL Kill Switch
Cloud & Infra
ScoutSuite, Prowler, Pacu, CloudMapper, Nmap, Nessus

What You Can Expect From Us

Four commitments we make on every engagement. Standard for enterprise and regulated buyers, useful for any startup CTO before signing a contract. Reference these at /methodology/#commitments when you need them in writing.

Manual testing where it matters

Automated tooling for surface mapping and reconnaissance only. Manual testing for authentication, authorization, business logic, and chained-exploit analysis. We do not ship scanner output as a pentest report.

Synthetic data only, no PII in evidence

We use synthetic test accounts and data for all testing. Customer PII never appears in screenshots, evidence, or the final report. If your application requires testing with real-looking data, we coordinate synthetic-data generation before kick-off.

Out of scope by default

DoS, load and stress testing, social engineering, third-party systems, and physical access are explicitly out of scope unless you request and authorize them in writing. We do not test what we are not authorized to test.

Named team with verifiable credentials

OSCP held by Rathnakara (co-founder, technical lead). Senior team adds CISSP, CEH, and ISO 27001 Lead Auditor. Credentials verifiable via Credly. No anonymous "our experts" claims.

Reporting Standard

Every engagement concludes with a detailed report designed for both technical teams and business stakeholders. No generic templates. Written for your context.

  • Executive summary with business risk context
  • Technical findings with CVSS v3.1 risk ratings
  • Proof-of-concept screenshots and reproduction steps
  • Developer-friendly remediation guidance
  • Compliance mapping (ISO 27001, SOC 2)
  • Free retest or re-assessment within one month

30-Day Free Retest

Every pentest engagement includes a complimentary retest within one month of initial report delivery.

01
Fix Vulnerabilities
Your team remediates findings using our guidance
02
Request Retest
Notify us when fixes are deployed
03
Verification Report
We verify fixes and issue an updated report

Frequently Asked Questions

What frameworks and standards do your penetration tests follow?

Our pentests follow the OWASP testing standards and PTES, the Penetration Testing Execution Standard. Web testing uses the OWASP Top 10 and OWASP WSTG v4.2, APIs use the OWASP API Security Top 10, and mobile uses OWASP MASTG and MASVS. The engagement lifecycle follows PTES across six stages: scoping, reconnaissance, vulnerability discovery, exploitation and validation, reporting, and retest. Findings are scored with CVSS v3.1 and CVSS v4.0.

Do you do manual testing or just run automated scanners?

We use automated tooling for surface mapping and reconnaissance only. Authentication, authorization, business logic, and chained-exploit analysis are tested manually. We do not ship scanner output as a penetration test report. Manual testing is where the findings that scanners miss come from.

What testing approach do you use: black-box, grey-box, or white-box?

Grey-box is our default. We test with authenticated access using both standard-user and admin-role credentials, which covers external attacker scenarios such as credential compromise and account takeover as well as insider-threat scenarios in a single engagement. Black-box (zero prior knowledge) and white-box (full source access) approaches are available on request when the scope calls for them.

What do you deliver at the end of a penetration test?

Every engagement concludes with a detailed report written for both technical teams and business stakeholders. It includes an executive summary with business-risk context, technical findings scored with CVSS v3.1 and CVSS v4.0, proof-of-concept evidence and reproduction steps, and developer-friendly remediation guidance for every finding. Growth plan reports add SOC 2 and ISO 27001 control mapping per finding and a Letter of Attestation signed by our lead penetration tester. The initial report is delivered as v1.0.

How does the free retest work?

Every pentest engagement includes one free retest within one month of the v1.0 report. Your team remediates the findings using our guidance, notifies us when the fixes are deployed, and we re-check every original finding. The retest takes 1 to 3 business days and produces a v2.0 report confirming which findings are remediated and noting any remaining risk.

Who runs the engagement?

Both co-founders are on every engagement. Rathnakara GN (OSCP, M.Sc Cyber Security) leads the hands-on technical work: penetration testing, architecture review, and control validation. Ashok S Kamat handles scoping, business-impact framing, and executive communication. There are no BDRs, junior analysts, or offshore teams. Senior team members hold certifications including CISSP, CEH, and ISO 27001 Lead Auditor.

Now that you've seen how we work

Take the next step at your own pace. No sales call required to look around.