Find out how your network fails before someone else does.
RCF Security is an offensive and defensive security firm, specializing in offensive security assessments. We attack your network, your Active Directory, and your applications the way a real adversary would, then stay to help you harden what we broke.
Both sides of the same practice
Offensive work is the specialty, and it is what most clients hire us for. Defensive work is what makes the offensive findings worth paying for, because a list of holes nobody closes is just an expensive document.
Offensive, the specialty
External and internal penetration testing, Active Directory, web applications and APIs, and external threat assessments. Real exploitation inside agreed rules of engagement, not a scanner report with a logo on it.
Defensive, the follow through
Risk assessments that answer to the business, and findings turned into a hardening plan sequenced so the changes that close the most attack paths come first. Written by the person who proved the path.
Defensive, the upkeep
Microsoft 365 and Entra ID audited against the CIS benchmarks, vulnerability scanning that is triaged rather than forwarded, dark web monitoring for credentials already circulating, and identity posture watched so the gaps you closed stay closed.
How an engagement works
Four steps, no surprises on the invoice or in the schedule.
-
Scope
We agree on targets, timing, and limits in writing, and you sign an authorization before any traffic is sent. Scope drives the price, and the price does not move once it is set.
-
Test
We work the engagement to the PTES methodology. Anything critical is reported the day it is found rather than held for the report.
-
Report
You get an executive summary for the owners and a technical section for the people doing the work, with CVSS 3.1 scoring, CWE identifiers, OWASP mapping, and reproduction steps.
-
Retest
After your team remediates, we verify the fixes and issue a closure letter you can hand to an auditor, a client, or an insurer.
What one phished password actually costs you
This is the path we walk on almost every internal engagement. Each step is ordinary. The damage is in how few of them there are.
Straight answers about risk
Most firms your size are not breached by anything exotic. They are breached through a forgotten service on the edge, a password that survived a merger, or a domain account with more rights than anyone remembers granting. Those are the things we look for, and they are the things we tell you how to fix.
We report what we proved, we label what we only observed, and we say plainly when something is out of scope. A report that overstates your security is worse than no report at all.
Where most people start
We have never had a penetration test. What should we do first?
An external test. It is the cheapest way to find out what the internet can already reach, it needs nothing from your team beyond permission, and it usually resets the conversation about what to fix first.
A client or insurer is asking us for a test. Is that different?
Send us what they asked for. The requirement is usually narrower than it sounds, and the scope should match the question being asked rather than the largest test we could sell you.
We already run a vulnerability scanner. Is that the same thing?
No. A scanner lists what might be wrong. A test proves what an attacker can actually do with it, which is a much shorter list and a far more useful one.
How much does it cost?
Scope decides it, and scoping is free. You get a fixed price in writing before anything starts, and it does not change unless you change the scope.