Cyber Security Division · Est. 2019

Cyber Security Agency

Cyber Security Agency is a Ukrainian cybersecurity company focused on Application Security, Cloud security, Security Awareness and Penetration Testing.

Cyber Security Agency works hard to assess your most significant vulnerabilities (information security assessment), put a plan together for managing those risks (information security roadmap), and helps you execute that plan (information security program development).

Purple Team Pentest OSINT DevSecOps SZBI / ISMS
pentest-session.sh
$ nmap -sV --script vuln target.corp
Starting Nmap 7.94 scan...
PORT 443 — HTTPS — nginx/1.18
CVE-2023-44487 (HTTP/2 RapidReset)
CVE-2021-41773 — Path traversal
Auth bypass — admin panel exposed
$ python exploit.py --target admin
[+] Access gained — CVSS 9.1 CRITICAL
$
17+
Real-world projects completed
15
Active professional certifications
10+
Security domains covered
5+
Expert specialists on the team

Cyber Security Services

🌐
Application Security Testing
The purpose of the application security assessment (or pentest) is to identify security vulnerabilities that may be exploited by malicious hackers or malevolent users to compromise application business logic or sensitive data.
OWASP Top 10 Burp Suite Manual
🔌
Initial consultation on security management
  • Assignment of a personal meeting.
  • Individual approach to solving a problem.
Recon Phishing Sim SE
🔍
Cloud security
Security-as-a-Service (SECaaS) is the IT Security solution hosted in the cloud. All actions are performed on the level of cloud service SaaS provider with the use of API. SECaaS guarantees full range of protection functions – ATP, Zero-day, Data Leak Prevention, encryption, account theft protection, web-server security, DDoS protection, etc.
Nmap Metasploit Post-Exploit
🔬
Security management
Security management is a solution for analyzing, collecting and storing data on company’s activities in the field of cybersecurity. After the unification into a single complex, personnel will have access to IT security overview, which is crucial for decision-making process based on current and future risks.
CVE / CVSS Patching Risk Matrix
🏛
Audit and protection of databases
Database Security Solution is designed to protect sensitive data in different databases. It provides comprehensive visibility into usage, permissions and vulnerabilities. Database Security reflect all aspects of the database security requirements and safety standards by using audit mechanisms and prevent attacks in real time without impacting performance and availability database. Layered architecture allows you to scale security solution for large database installations.
ISO 27001 SZBI Audit
⚙️
Security of network infrastructure
A set of solutions to protect the network IT infrastructure identifies information that indicates malicious, viral activity and penetration attempts and discovers an earlier penetration into the network.
CI/CD Docker AWS SAST/DAST
🧬
Cybersecurity Penetration Test
Penetration Test may be the most widely known type of cybersecurity services out there for it is mandated by many industrial regulations. It is often used for measurement of the overall efficiency of a cybersecurity program.
Forensics Malware Timeline
🎓
Security Awareness Workshop
Protecting the organization against modern cyberthreats might be hard without showing the executive management and employees at positions of trust how to combat modern cybersecurity threats. We have developed a program of cybersecurity awareness workshop that covers the most critical and impactful threats. We train the audience to detect attack attempts, to protect themselves and their employers against malicious hackers, and to share this knowledge with their co-workers.
Workshops Phishing Awareness
🔐
Incident Analysis and Digital Forensics
We conduct cybersecurity incident investigations using modern Digital Forensics and Incident Response methodologies. Our experts analyze memory, file systems, network connections, security logs, and Windows/Linux artifacts, identify Indicators of Compromise (IOCs), build detailed event timelines (Timeline Analysis), and determine the root cause of the security breach.
Memory Disk IOC Timeline
🌐
OSINT and Cyber Threat Intelligence
We collect, correlate, and analyze data from open sources to identify an organization's external digital footprint. Our assessments include domain infrastructure, IP addresses, ASNs, DNS records, SSL/TLS certificates, cloud services, exposed credentials, public code repositories, document metadata, and other artifacts that help evaluate the organization's potential attack surface.
OSINT Maltego SpiderFoot Recon

Our team and certificates

eJPT
2 professionals
The Junior Penetration Tester (eJPT) is a thoughtfully crafted certification designed to test you on every phase of the penetration life cycle from assessment methodologies, to host and network auditing, host and network penetration testing, and web application penetration testing. This browser-based, hands-on, exam mirrors real world junior penetration tasks using a methodological approach. Not only does our exam environment feature modern infrastructure, operating systems, and current versions of software, but it also uses innovative technology to make each user’s testing experience unique.
eCPPT
2 professionals
Certified Professional Penetration Tester (eCPPT) certification – The certification involves in-depth penetration testing that simulates a real world scenario, requires you to prove your analytical skills with a thorough security write-up, and is hand-graded by a security professional. This intermediate level certification proves to employers and superiors alike that you have the knowledge necessary to run point on a host of penetration testing engagements.
eWPT
1 professional
The Web Application Penetration Tester certification assesses a cyber security professional’s web application penetration testing skills. The exam is a skills-based test that requires candidates to perform a real-world web app pentesting simulation.
PORP
1 professional
Practical OSINT Research Professional (PORP) is a certification that validates practical skills in gathering and analyzing information from open sources (OSINT). The exam includes practical tasks involving research across social media platforms, public records, online databases, and other publicly available sources. The certification demonstrates the ability to identify relevant information, analyze and correlate data from multiple sources, draw well-founded conclusions, and present research findings in a professional report.

8 Years in Business

20 satisfied clients

30 successful projects

Find out the cost of protecting your property

🌐
📧
📍
Address
49000, Ukraine, Dnepr
it’s opening time
Mon – Fri: 9:00 AM – 6:00 PM, Sat – Sun: Closed