RCF Security

Services

Two halves of one practice. Offensive assessments prove where you are exposed, and they are what we specialize in. Defensive work closes what they find and keeps it closed.

Offensive security assessments

The specialty. Everything below is adversarial work: we act as the attacker, inside rules you set, and prove what is reachable rather than listing what might be.

External penetration testing

We attack your internet facing footprint the way an outsider would: everything published under your domains and address space, including the services nobody meant to expose. Authentication, patch level, exposed management interfaces, and credential reuse all get tested, not just scanned.

Answers: what can someone reach and exploit from the internet today, with no access and no inside help.

External threat assessment

The reconnaissance half of an attack, without the exploitation. We build the picture an attacker builds before deciding whether you are worth the effort: domains and subdomains you forgot you own, exposed services and their versions, remote access and management interfaces, cloud tenants and storage, technologies in use, staff footprint useful for phishing, credentials already circulating from third party breaches, and lookalike domains registered against your brand. Nothing is touched beyond what a stranger can already see, so it needs no test window and no downtime.

Answers: what an attacker knows about you before they start, and which of it should not be public.

Internal network and Active Directory testing

We start from the position of a compromised workstation or a visitor on your network and work toward domain privilege. That means credential capture, Kerberos and delegation abuse, share and permission sprawl, lateral movement, and the escalation paths that connect a helpdesk account to a domain administrator.

Answers: how far one phished user or one plugged-in laptop actually gets inside your business.

Web application and API testing

Manual testing against the OWASP Top 10 and past it, with authenticated roles so we can test the logic that scanners never see: access control between accounts, injection, session handling, file handling, and business logic that assumes the client behaves.

Answers: whether one customer can reach another customer's data, and what an authenticated attacker can do with your application.

Retesting and remediation validation

After your team works the findings, we retest each one and confirm it is closed rather than moved. The result is a closure letter listing every finding, its final state, and the evidence behind that conclusion.

Answers: whether the money you spent on remediation actually bought you the fix.

Defensive security and hardening

What you do with the findings. Defensive work is priced and delivered separately, and you are never obligated to buy it from the firm that found the problem.

Risk assessment

The business view rather than the technical one. We inventory what actually matters to the operation, name the threats that realistically apply to a business your size and shape, record the controls already in place, and rate each risk on likelihood and impact. The output is a risk register with an owner and a treatment decision against every line: reduce it, transfer it, accept it in writing, or avoid it. Mapped to a recognized framework such as the NIST Cybersecurity Framework or the CIS Controls, so it answers the questionnaire an insurer, auditor, or enterprise client sends you.

Answers: where the money should go first, and what you are knowingly choosing to live with.

Posture review and hardening plan

A review of how your environment is built rather than a hunt for individual bugs: segmentation, administrative access, identity and multi-factor coverage, logging, backup isolation, and endpoint controls. You get a sequenced plan where the first item closes the most attack paths for the least disruption, so a small team can start on Monday.

Answers: what to change, in what order, and what each change is worth against real attacks.

Auditing and identity posture

Defensive work on a recurring cycle, for the environments that drift fastest.

Testing tells you what an attacker can do today. Auditing tells you why it was possible, and posture management stops the gap from reopening next quarter. Most of what we find in Microsoft environments is not a missing product. It is a default nobody revisited and an identity nobody retired.

Microsoft 365 and Entra ID audit

Your tenant measured against the CIS benchmarks and Microsoft's own security baselines, control by control. Conditional access and multi-factor coverage, legacy authentication, administrative roles and their standing assignments, guest and external sharing, mailbox delegation and forwarding rules, audit logging and retention, and the Defender and Purview settings that are licensed but never switched on. You get the gap list, the configuration change for each one, and the order to apply them in.

Answers: how far your tenant sits from a defensible baseline, and which settings close the most risk for the least disruption.

Vulnerability scanning and reporting

Recurring authenticated and unauthenticated scanning across your external footprint and internal estate, with the output triaged rather than forwarded. Raw scanner results are noise: false positives, duplicates, and criticals that cannot be reached from anywhere. We validate what matters, drop what does not, and report on the trend so you can see whether remediation is outpacing new exposure.

Answers: what is actually exploitable in your estate this month, and whether last month's fixes held.

Dark web scanning and reporting

Recurring monitoring for your domains, executive and staff addresses, and brand terms across breach corpora, paste sites, credential markets, and criminal forums. Each report names what surfaced, where it came from, how old it is, and the action it calls for: a password rotation, a session revocation, a conditional access change, or nothing at all when the hit is stale and already handled. Exposed credentials are cross checked against whether that account still exists and still has access, because the finding that matters is the one still usable today.

Answers: which of your credentials are already in someone else's hands, and which of them still work.

A quiet report is not proof of safety. It means nothing surfaced in the sources we can see, and those sources are a fraction of what exists.

Identity Security Posture Management

Identity is the perimeter now, and it drifts continuously. ISPM watches the things that turn one account into a tenant-wide compromise: privileged accounts without multi-factor, standing global administrator rights, stale and orphaned accounts, service principals and app registrations with excessive consent, risky sign-in patterns, and the hybrid seam between on-premises Active Directory and Entra ID where synchronization mistakes become privilege escalation. Findings arrive as attack paths with the single change that breaks each one.

Answers: which identities would end the argument if they were compromised, and what to change before that happens.

Auditing is a measurement, not a product sale. If your existing licensing already covers a control we recommend, we say so and show you where to switch it on.

Questions people ask before signing

Will testing take our systems down?

It should not, and the limits are agreed before we start. Where a finding can only be proven by an action that risks availability, we stop at proof of access and tell you exactly what was demonstrated and what was not. Denial of service testing is never run unless you ask for it in writing.

How long does an engagement take?

Scope decides it. A single external perimeter is usually a week from kickoff to report. An internal and Active Directory test runs longer because the interesting work happens after the first foothold. You get the schedule in writing with the quote, and the report date is part of the agreement.

What do we get at the end?

An executive summary written for owners, a technical section written for engineers, CVSS 3.1 scoring with CWE identifiers and OWASP mapping, evidence and reproduction steps for every finding, and a walkthrough call. After your team remediates, the retest produces a closure letter you can hand to an auditor, a client, or an insurer.

Do you need our passwords or admin access?

Not for an external test, which starts from nothing. Internal and application testing usually starts from a standard user account, because that reflects the real threat and it finds more in less time. Any credential you issue is used only inside the agreed window and destroyed at the end.

Are you going to phish our staff?

Only if social engineering is in the scope you signed. It is never a surprise, and the rules around it, including who is told in advance, are set by you.

What happens if you find something critical mid test?

You hear about it that day, by phone, before it goes anywhere near the report. If it is being actively exploited by someone else, we stop testing and help you respond.