Offensive security agency

We find the weak spot first.

Moscow 55°45′ N · 37°37′ E MSK 00:00:00
For large and
mid-size business

We test your company’s defences the way real attackers would. You learn about the weak spots before they do and have time to close them.

Scroll ↓

(01) Agency

SMK-RK is a team of engineers who test corporate defences with real attacks. We look for vulnerabilities the way attackers do: we find ways into your systems, confirm them in practice and help close the critical gaps before anyone can use them.

ExperienceA
10

years of practice in the financial and industrial sectors

ProjectsB
40+

completed projects for large and mid-size companies

TeamC
18

in-house engineers, no subcontractors

TrustD
0

client data leaks in our entire history

(02) Services

Five services.
Equal weight, one team.

Order any service on its own or combine them into an annual programme

  1. 01

    Penetration test

    Penetration testing of the external and internal perimeter, web and mobile applications. Clear scope, measurable results.

    Perimeter / Internal network / Applications

    2–6 wks
  2. 02

    Red team

    A long-running, agreed operation against the whole organisation: people, processes and technology. We measure how quickly your security team spots an attack and how it responds.

    Threat-model scenario / Detection and response / Staff awareness

    2–4 mos
  3. 03

    Device and software testing

    Security assessment of hardware platforms, embedded systems and software products before market launch and before deployment.

    Embedded systems / Code review / Certification readiness

    By scope
  4. 04

    Security audit

    We review your processes, infrastructure and security controls. We identify weak spots, assess their business impact and decide what to fix first.

    Preparing for GOST R 57580 assessment / 152-FZ / 187-FZ / ISO 27001

    4–8 wks
  5. 05

    Infrastructure optimisation

    We rebuild the architecture based on test findings: segmentation, access management, monitoring. The smaller the attack surface, the cheaper it is to defend.

    Architecture / Segmentation / Configuration hardening / Monitoring

    Roadmap

(03) Method

A predictable process
for unpredictable work.

  1. I / Scope

    Goals, boundaries and rules

    We agree on the target, permitted actions and lines of communication. Written authorisation is signed before any work begins.

  2. II / Model

    Threat profile

    We determine who might want to attack your company specifically, and why. The test scenario is built around that profile.

  3. III / Execution

    Under your control

    Regular progress updates, critical findings reported immediately. You can stop the test at any moment.

  4. IV / Outcome

    Report and remediation plan

    An executive summary and a technical report with findings ranked by risk. We walk through the results with your team.

(04) Sectors

Sectors where a mistake costs the most.

(05) Principles

Three rules we never bend.

Rule 01

No action without written authorisation and agreed boundaries.

Rule 02

Client data never leaves the agreed perimeter, during the engagement or after it.

Rule 03

Every finding comes with a recommendation you can act on.

(06) Contact

Let’s
talk.

Tell us what needs testing and we will suggest how to approach the work.

Email info@smk-rk.ru Write →
Phone +7 926 864 13 72 Call →

We handle data from emails and calls under our personal data policy (in Russian)

  1. 01

    You write or call

    A couple of lines about the task is enough. We reply within one business day.

  2. 02

    We sign an NDA

    Before you share any details about your infrastructure.

  3. 03

    We propose a plan

    After a meeting in person or by video call, we send the scope, timeline and cost.