Here you can find answers to the most common questions regarding cybersecurity, the SMC model, and our services. You can also send us your own question.

Send us a question. You do not need to provide your name or contact information to submit a question. If you would like a response via email, you can provide your email address.

Cybersecurity refers to the protection of data, systems, services, and digital operations from cyber threats.
Cybersecurity includes activities such as identifying risks, protecting systems and access rights, detecting threats, responding to incidents, and recovering operations after disruptions.
It is not just about technology. People, operational procedures, management, and continuous improvement are also part of cybersecurity.
Source: NIST Cybersecurity Framework 2.0

Risks can include, for example, data breaches, malware, phishing, ransomware, vulnerabilities, credential leaks, excessive access rights, vendor dependencies, and human error.
The significance of a risk depends on factors such as the likelihood of the event and the impact it would have on the company's operations, data, and finances.
Source: NIST Cybersecurity Glossary / Risk

SM Cybersecurity helps organizations identify the cybersecurity risks that have the greatest impact on their operations.
Risks can be caused by factors such as data breaches, malware, phishing, vulnerabilities, excessive access rights, vendor dependencies, and human error. The significance of a risk depends on the likelihood of the event and the magnitude of its impact on the company.
An employee's credentials are stolen in a phishing attack. The attacker gains access to the company's email and can attempt to use that access to reach other systems or data.
Source: NIST Cybersecurity Glossary / Risk

SM Cybersecurity's cybersecurity audit assesses the current state of an organization's cybersecurity, identifies significant weaknesses and risks, and establishes a foundation for remediation.
The audit examines areas such as systems, networks, operational procedures, access rights, and security measures. The goal is to identify practical areas for improvement and determine what should be fixed and in what order.
Source: NIST SP 800-115, Technical Guide to Information Security

Penetration testing is a form of security testing where controlled attack simulations are performed against an organization's systems, applications, or networks. The goal is to determine whether their security features can be bypassed and vulnerabilities exploited.
In penetration testing, testers mimic the actions of a real attacker within an agreed-upon scope. The testing can, for example, determine whether a specific vulnerability can be used to gain access to a system, data, or other resources. The results allow an organization to identify actual weaknesses and target corrective measures effectively.
Source: NIST SP 800-115 – Technical Guide to Information Security Testing and Assessment.

SM Cybersecurity's experts actively monitor the latest cybersecurity news, CVE releases, security communities, GitHub, LinkedIn, and other industry sources. In addition, our experts track new vulnerabilities, participate in training, and share knowledge with one another. This ensures that current threats and new attack methods are taken into account in client projects.
Cyber threats are constantly evolving, so expertise cannot be maintained through one-off training alone. Experts must monitor developments such as new CVE vulnerabilities and security news, study new attack techniques, and continuously update their skills. In practice, this may involve researching a new vulnerability, assessing its impact, and verifying whether the same risk applies to a client's environment.
Source: NIST Cybersecurity Framework (CSF), MITRE ATT&CK, CVE database, and OWASP publications.