We find the weak spot first.
mid-size business
We test your company’s defences the way real attackers would. You learn about the weak spots before they do and have time to close them.
Scroll ↓(01) Agency
SMK-RK is a team of engineers who test corporate defences with real attacks. We look for vulnerabilities the way attackers do: we find ways into your systems, confirm them in practice and help close the critical gaps before anyone can use them.
years of practice in the financial and industrial sectors
completed projects for large and mid-size companies
in-house engineers, no subcontractors
client data leaks in our entire history
(02) Services
Five services.
Equal weight, one team.
Order any service on its own or combine them into an annual programme
-
01
Penetration test
Penetration testing of the external and internal perimeter, web and mobile applications. Clear scope, measurable results.
-
02
Red team
A long-running, agreed operation against the whole organisation: people, processes and technology. We measure how quickly your security team spots an attack and how it responds.
-
03
Device and software testing
Security assessment of hardware platforms, embedded systems and software products before market launch and before deployment.
-
04
Security audit
We review your processes, infrastructure and security controls. We identify weak spots, assess their business impact and decide what to fix first.
-
05
Infrastructure optimisation
We rebuild the architecture based on test findings: segmentation, access management, monitoring. The smaller the attack surface, the cheaper it is to defend.
(03) Method
A predictable process
for unpredictable work.
-
I / Scope
Goals, boundaries and rules
We agree on the target, permitted actions and lines of communication. Written authorisation is signed before any work begins.
-
II / Model
Threat profile
We determine who might want to attack your company specifically, and why. The test scenario is built around that profile.
-
III / Execution
Under your control
Regular progress updates, critical findings reported immediately. You can stop the test at any moment.
-
IV / Outcome
Report and remediation plan
An executive summary and a technical report with findings ranked by risk. We walk through the results with your team.
(04) Sectors
Sectors where a mistake costs the most.
- A
Banking and fintech
GOST R 57580 · Bank of Russia requirements · Payment infrastructure
- B
Industry
Industrial control systems · Energy · Critical infrastructure
- C
Telecom
Operator networks · Billing · Communications infrastructure
- D
Public sector
State information systems · FSTEC requirements · Domestic platforms
(05) Principles
Three rules we never bend.
No action without written authorisation and agreed boundaries.
Client data never leaves the agreed perimeter, during the engagement or after it.
Every finding comes with a recommendation you can act on.
(06) Contact
Let’s
talk.
Tell us what needs testing and we will suggest how to approach the work.
We handle data from emails and calls under our personal data policy (in Russian)
- 01
You write or call
A couple of lines about the task is enough. We reply within one business day.
- 02
We sign an NDA
Before you share any details about your infrastructure.
- 03
We propose a plan
After a meeting in person or by video call, we send the scope, timeline and cost.