Competence

Expertise in identifying, protecting, monitoring, and continuously improving cybersecurity

Risk Management
- Cybersecurity maturity assessment
- Risk identification and prioritization
- Vulnerability assessment and management
- Attack surface / asset discovery
- Security reporting and executive situational awareness

Cybersecurity experts

Offensive Security
- Penetration testing
- Offensive security
- Red teaming
- Attack simulation
- Web application, API, and mobile application testing

Cybersecurity experts

Infrastructure Security
- Network and infrastructure security
- Cloud security
- Security architecture
- Zero Trust
- Firewalls and VPNs
- Network traffic protection

Cybersecurity experts

Threat Intelligence
- Threat intelligence
- Cyber threat analysis
- Monitoring of threat actors and attack campaigns
- Dark Web and data leak monitoring
- Monitoring of leaked credentials and data
- Monitoring of new vulnerabilities

Cybersecurity experts

Security Operations
- Security Operations
- Continuous security monitoring
- Analysis of logs and security events
- Incident response
- Identification and handling of security incidents

Cybersecurity experts

Automation & AI
- Leveraging AI in cybersecurity
- Security automation
- Automated threat detection
- Streamlining security processes
- Continuous monitoring and development
- Integrating various security functions

Cybersecurity experts

Ask about this

Partners

Reliable partners and expert networks support the overall cybersecurity framework by complementing expertise, technology, and services according to the client's needs.

Client cases

In the future, this section will showcase completed client cases and describe how cybersecurity challenges have been identified, solved, and developed in collaboration with clients.

  • Findings

    No client-oriented findings are available for publication yet. In the future, anonymized and publishable observations can be compiled here.

  • Measures taken

    The first client-specific measures and their descriptions will be added here in the future.

  • Outcome

    No client-specific results are available for publication yet. In the future, measurable and verifiable results will be compiled here.

Expertise

The client's feedback on the expertise received during the collaboration would go here
Client name here
Company name here

Collaboration

This is where the client's testimonial regarding the ease of collaboration, communication, and service would go.
Client name here
Company name here

Results

This is where the client's testimonial regarding the results of the work and the benefits achieved would go.
Client name here
Company name here

Confidence

This is where the client's testimonial on how SM Cybersecurity has strengthened their confidence in their cybersecurity would go.
Client name here
Company name here

Certificates and qualifications

Certificates and qualifications are presented here.
Current status: the currently listed certificates and qualifications are indicative. For some, we have a strong foundation for achieving them, and for others, they may be pursued in the future.

ISO/IEC 27001

Information Security Management System certificate
Issuer
---
Holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Valid until further notice
Lifetime
Credential ID
---

ISO/IEC 27701

Privacy Information Management System certificate
Issuer
---
Holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

Certified Information Systems Security Professional (CISSP)

Professional certification
Issuer
---
Credential holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

Offensive Security Certified Professional (OSCP)

Professional certification
Issuer
---
Credential holder name
---
Credential scope
---
Validity:
Active
Expires [date]
No expiration date
Lifetime
Credential ID
---

Fortinet NSE 4

Technology and vendor certification
Issuer
---
Holder name
---
Credential scope
---
Validity:
Active
Valid until [date]
No expiration date
Lifetime
Credential ID
---

Burp Suite Certified Practitioner (BSCP)

Professional certification
Issuer
---
Holder name
---
Scope of qualification
---
Validity:
Active
Valid until [date]
Valid until further notice
Lifetime
Credential ID
---

Certified Ethical Hacker (CEH) - Training

Education and additional qualification
Issuer
---
Holder name
---
Scope of qualification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

ISO/IEC 27001

Information Security Management System Certificate
Issuer
---
Credential holder
---
Scope of certification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

ISO/IEC 27701

Privacy Information Management System certificate
Issuing organization
---
Credential holder name
---
Credential area
---
Validity:
Active
Expires [date]
No expiration date
Lifetime
Credential ID
---

Certified Information Systems Security Professional (CISSP)

Professional certification
Issuer
---
Holder name
---
Area of expertise
---
Validity:
Active
Valid until [date]
Valid until further notice
Lifetime
Credential ID
---

Offensive Security Certified Professional (OSCP)

Professional certification
Issuer
---
Holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Valid until further notice
Lifetime
Credential ID
---

Fortinet NSE 4

Technology and vendor certification
Issuer
---
Holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

Burp Suite Certified Practitioner (BSCP)

Professional certification
Issuer
---
Holder name
---
Scope of certification
---
Validity:
Active
Valid until [date]
Ongoing
Lifetime
Credential ID
---

Certified Ethical Hacker (CEH) - Training

Training and supplementary qualifications
Issuer
---
Holder name
---
Scope of competence
---
Validity:
Active
Valid until [date]
Valid until further notice
Lifetime
Credential ID
---
SM Cybersecurity Oy / SMC Model

Standards and frameworks

Internationally recognized standards, frameworks, and methodological guidelines that support cybersecurity assessment, risk management, protection, and continuous improvement within SM Cybersecurity's SMC model.

05
Standards
06
Frameworks
03
Methodological guidelines
Standards

Internationally recognized standards for information security and risk management.

ISO/IEC 27001
Recommended standard - Implementation in progress

Requirements for an information security management system. Supports risk-based information security management, goal setting, control management, and continuous improvement.

In SMC: information security management and continuous improvement.

The standard is being implemented as part of the organization's information security management. The goal is ISO/IEC 27001 certification.
ISO/IEC 27002
Recommended standard - Implementation in progress

A standard supporting the practical implementation of information security controls, providing guidance on the selection and application of necessary security measures.

In SMC: definition and implementation of protective measures and security controls.

The standard is being implemented as part of the organization's information security management. The goal is ISO/IEC 27001 certification.
ISO/IEC 27005
Recommended standard - Implementation in progress

A standard for information security risk management that supports the identification, assessment, treatment, and monitoring of risks as part of an organization's information security management.

In SMC: identifying, assessing, prioritizing, and treating cybersecurity risks.

The standard is being implemented as part of the organization's information security management. The goal is ISO/IEC 27001 certification.
ISO 31000
Recommended standard - Implementation in progress

A standard for comprehensive risk management that supports the identification, assessment, treatment, monitoring, and communication of risks across the entire organization.

In SMC: integrating cybersecurity risks with business and organizational risks as part of comprehensive risk management.

The standard is being implemented as part of the organization's information security management. The goal is ISO/IEC 27001 certification.
ISO/IEC 27701
Recommended standard - Implementation in progress

A standard for a privacy information management system that supports the management of personal data processing and data protection within an organization's operations.

In SMC: developing data protection and personal data processing management as part of cybersecurity.

The standard is being implemented as part of the organization's information security management. The goal is ISO/IEC 27001 certification.
Frameworks

Internationally recognized frameworks and models for cybersecurity and application security.

NIST CSF 2.0
Recommended SMC framework

A cybersecurity risk management framework that helps organizations structure, assess, prioritize, and communicate cybersecurity risks.

In SMC: structuring the overall cybersecurity posture and risk-based development.

Recommended SMC framework
CIS Controls v8.1
Recommended SMC framework

A prioritized set of practical cybersecurity defense measures and controls.

In SMC: prioritizing and implementing concrete security measures.

Recommended SMC framework
MITRE ATT&CK
Recommended framework

A knowledge-based framework that organizes the tactics, techniques, and procedures used by cyber attackers.

In SMC: threat intelligence, attack simulation, and security validation.

Recommended framework
OWASP Top 10
Used as needed

A framework that compiles the key and critical security risks for web applications.

In SMC: application security assessment and penetration testing.

Used in necessary application security assessments
OWASP API Security Top 10
In use

A framework that compiles the key security risks of APIs, used to support API security assessment and testing.

In SMC: for API security assessment and testing.

In use
OWASP ASVS
Recommended methodology

A framework for assessing and verifying application security requirements and technical controls.

In SMC: supporting application security requirements, assessment, and technical verification.

Recommended methodology
Methodology guides

Methodology guides supporting cybersecurity assessment, testing, incident preparedness, and architecture.

NIST SP 800-115
Recommended methodology

A methodology guide for planning, executing, and analyzing technical security tests and assessments, as well as supporting remediation efforts.

In SMC: for cybersecurity auditing, vulnerability assessment, and VAPT testing.

Recommended methodology
NIST SP 800-61 Rev.3
Recommended methodology

A methodology guide supporting the handling of security incidents and the development of incident response operations.

In SMC: for preparing for, responding to, and improving operations during incidents and anomalies.

Recommended methodology
NIST SP 800-207
Recommended methodology

A framework for designing and implementing a Zero Trust architecture.

At SMC: for developing the security of identity, access management, and protected resources.

Recommended methodology