Penetration testing that ends with fixes you can verify.

Rosec Cyber tests web applications, APIs, and networks, then writes findings that developers and decision-makers can both act on. When you fix something, we test it again and tell you whether the fix holds.

Request a consultation See services

Sample finding from a report (illustrative)

Password reset token still works after it is used

High
Affected
POST /api/account/reset
What we saw
A reset link can be replayed after the password has already been changed, so anyone who sees the link later can take over the account.
Evidence
Request 1: 200 OK, password changed
Request 2, same token: 200 OK, password changed
Fix
Invalidate the token on first use and expire unused tokens after 15 minutes.
Retest
Fixed and verified. Second request now returns 400.

Services

Penetration testing
Web applications, APIs, and networks, tested within a scope and rules of engagement you approve in writing. Manual testing comes first and tooling supports it.
Application security
Review of how your software is designed and built, with attention to authentication, authorization, and how data is handled. Recommendations are written for the developers who will make the change.
Security awareness training
Phishing simulations, tailgating tests, and physical intrusion assessments, followed by short training built from what happened at your site.
Retesting
After you remediate, we test the same issues again and report which fixes hold and which need more work.

How an engagement runs

  1. Scope

    We agree on targets, dates, and rules of engagement in writing before any testing starts.

  2. Recon

    We map what is exposed, starting with passive sources and moving to active checks inside scope.

  3. Test

    We probe for weaknesses and confirm each one with evidence, so every finding is reproducible.

  4. Report

    You get a plain-language summary for leadership and technical detail with fixes for your engineers.

  5. Retest

    Once you have fixed findings, we verify them and update the report.

About

Rosec Cyber is led by Cody Smith, a security consultant in Georgia with more than 15 years in IT operations and systems management. That operations background shapes the reports: they are written for the people who have to schedule, fund, and ship the fixes, as well as the engineers who write them.

Cody also does bug bounty research and builds open security tooling, which keeps the testing current with how real attackers work.

Certifications

  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Essentials (GSEC)
  • GIAC Foundational Cybersecurity Technologies (GFACT)
  • ISC2 Certified in Cybersecurity (CC)

Writing

Graybox is our newsletter on security for small and mid-sized organizations. It covers what happened, why it matters, and what a sensible response looks like, without the hype.

Read Graybox on Substack

Check out my GitHub projects

Visit me on LinkedIn

Contact

Tell us what you want tested and by when. We will reply with questions and a proposed scope.

contact@roseccyber.net

Found a vulnerability in our site? Our security contact explains how to report it.