The person doing the work is the person you hired.
RCF Security is an offensive and defensive security firm specializing in offensive security assessments. It is led by Ryan Fangers, Founder and CEO, with more than ten years in penetration testing and security architecture. Your engagement is not handed to a junior analyst running a scan template.
Background
Ten years of offensive work across external and internal network testing, Active Directory, web applications and APIs, and malware analysis, alongside the defensive side of the job: designing and reviewing the controls that are supposed to stop all of it, auditing Microsoft environments against recognized baselines, and managing identity posture. Offensive work is the specialty and it comes first, because you cannot sensibly defend what you have never seen attacked.
Clients are usually businesses without a full security team. An owner has a question from a client, an insurer, or an auditor. An IT lead already suspects half the answer and needs the evidence to act on it. Both get the same report, written so each of them can use their half of it.
- Practice
- Offensive and defensive, specializing in offensive assessments
- Methodology
- PTES, CVSS 3.1, CWE, OWASP
- Engagement model
- Fixed scope, fixed price, retest included
How we work
The person doing the work is the person you hired. Your engagement is not handed to a junior analyst running a scan template, and the report is not assembled by a tool. You talk to the tester, during the engagement and after it.
Plain language. Reports are written to be read by the owner and used by the engineer. No filler, no vendor marketing, and no severity inflation to make an invoice look better.
Fixed scope and fixed price. Agreed in writing before work starts. If something found mid engagement warrants going further, we tell you and you decide, rather than discovering it on the bill.
Small by design. Engagements are accepted in the number that can be run properly. If we cannot do the work in the window you need, we say so during scoping instead of stretching the schedule.
Your findings are yours. We do not publish client names without written permission and we do not use client findings as marketing material. The only security writing on this site is about this site.
This site, as a worked example
This site runs no JavaScript, loads nothing from a third party, sets no cookies, and serves a content security policy that denies every resource class by default. It is built that way because the same reasoning drives the advice we give you: remove the thing rather than defend it, and what is not there cannot be exploited.
Look at it closely. The reporting policy is published in security.txt, and a report about this site gets a same day reply. We hold ourselves to the rule we hold clients to: nobody tests anything without written authorization, including us, and including this site.