The SMC model is a cybersecurity framework developed by SM Cybersecurity.
Cybersecurity is not built through a single action. In the SMC model, the current state is determined, the most significant risks are identified and prioritized, necessary measures are implemented, and the state of cybersecurity is continuously improved.
The SMC model includes two core principles:
1. Risk-based approach: Cybersecurity measures are targeted and prioritized based on the significance of identified risks.
2. Continuous improvement model: Cybersecurity is continuously assessed, monitored, tested, and developed based on new threats, findings, changes, and risks.

Through our audit, we assess your organization's current cybersecurity status, identify key risks and vulnerabilities, and determine how well your organization can withstand cyber threats.
We assess your organization's current cybersecurity status, key risks, vulnerabilities, and the effectiveness of your security measures. The assessment identifies gaps and areas for improvement, providing a comprehensive view of your organization's cybersecurity posture.
Short: 2-4 days / Medium: 5-10 days / Extensive: 10-20 days
We build a comprehensive overview of your organization's current cybersecurity status, security level, key strengths, and areas for improvement. The assessment examines your organization's practices, processes, technical solutions, and governance in relation to selected security requirements and objectives. Based on the results, we identify gaps between the current and target states, as well as key development priorities.
Short: 2-4 days / Medium: 5-10 days / Extensive: 10-20 days
We identify the organization's externally and internally visible digital assets and attack surface interfaces, such as domains, subdomains, IP addresses, APIs, cloud services, applications, and other outward-facing services. The mapping provides a comprehensive view of the points from which an attacker could attempt to access the organization's systems, influence them, or gain access to data.
Short: 1-2 days / Medium: 3-5 days / Extensive: 5-10 days
We identify technical vulnerabilities in systems and networks, such as outdated software, missing patches, and misconfigurations, and evaluate the impact of these findings on the organization's cybersecurity. The results are used to create a report with prioritized remediation recommendations.
Short: 1-2 days / Medium: 3-5 days / Extensive: 5-10 days
We combine vulnerability identification with controlled penetration testing to assess whether discovered weaknesses can be exploited. We identify vulnerabilities in systems, networks, services, and applications, and evaluate their impact and risks. The results are used to form recommendations for corrective actions to improve security.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-20 days
Test how your organization withstands a real-world cyberattack. The attack simulation mimics the actions of an actual threat actor in accordance with the MITRE ATT&CK framework and evaluates the organization's ability to prevent, detect, and respond to attacks.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-20 days
We evaluate API authentication, access rights, data handling, and potential vulnerabilities, as well as identify attack vectors. The assessment is based on the OWASP API Security Top 10 framework and risk-based testing.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-15 days
We evaluate the security of web and mobile applications, including authentication, authorization, session management, application logic, and technical vulnerabilities. The assessment utilizes OWASP application security requirements and testing methodologies.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-20 days
We evaluate the protection, configurations, access rights, security settings, and potential attack vectors of cloud environments. The assessment identifies risks and deficiencies and determines the measures required to remediate them.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-15 days
We evaluate the security of networks, services, and firewalls, and identify potential vulnerabilities and attack vectors. The assessment utilizes network reconnaissance, port and service identification, and vulnerability scanning. If necessary, findings are validated through penetration testing.
Short: 2-3 days / Medium: 4-7 days / Extensive: 8-15 days
We evaluate the management and security of user accounts, access rights, and authentication. The assessment reviews aspects such as the appropriateness of access rights, the principle of least privilege, MFA, administrative rights, user account lifecycle management, and regular access reviews. The assessment is based on NIST identity and access management controls and their assessment methods.
Short: 1-2 days / Medium: 3-5 days / Extensive: 5-10 days
We assess compliance through documentation, interviews, and testing. We identify gaps between the current state and the required target state, document our findings, and establish a foundation for prioritizing corrective actions.
Short: 1-3 days / Medium: 4-7 days / Extensive: 8-15 days
We assess how cybersecurity risks can affect the organization's critical business functions, finances, operational continuity, data confidentiality, integrity, and availability, as well as reputation. The assessment identifies the most critical impacts and the risks to be prioritized based on them.
Short: 1-2 days / Medium: 3-5 days / Extensive: 6-15 days
We identify the current state of the organization's information security, compare it against goals and requirements, and determine key deficiencies and the measures needed to correct them. The analysis is based on the NIST CSF 2.0 Current Profile–Target Profile approach and risk-based prioritization.
Short: 7-14 days / Medium: 21-28 days / Extensive: 35-42 days
We identify the organization's external attack surface, internet-exposed resources, services, and vulnerabilities, and assess the risk they pose. The assessment combines technical findings, threats, probability, and business impact.
Short: 1-3 days / Medium: 4-7 days / Extensive: 8-15 days
SM Cybersecurity turns identified cybersecurity risks into concrete improvements. We systematically develop the organization's technical solutions, operating models, and security management to strengthen the level of protection and ensure cybersecurity evolves continuously alongside the business.
We prioritize identified risks based on their impact and business criticality, define appropriate handling and corrective measures, and plan their implementation, responsibilities, and goals. The impact of these measures is monitored, and the risk level is reassessed to ensure continuous improvement.
Short: 1-3 days / Medium: 3-7 days / Extensive: 7-15 days
Based on the current and target state, we build a prioritized development plan that defines the most important development actions, their goals, responsibilities, resources, and progress. The plan can be structured, for example, as 30, 60, and 90-day blocks to establish a clear implementation order and trackable progress.
Short: 1-2 days / Medium: 3-5 days / Extensive: 5-10 days
We implement identified cybersecurity deficiencies and vulnerabilities in a controlled manner. We define the necessary technical and organizational corrective measures, implement them in order of priority, and ensure their functionality through testing and monitoring.
Short: 3-5 days / Medium: 5-15 days / Extensive: 15-30 days
We review and test that the implemented corrective measures have eliminated the observed deficiencies and are functioning as intended. Verification may involve repeating original tests, assessing the achieved security outcome, and identifying any remaining risk.
Short: 1-2 days / Medium: 3-5 days / Extensive: 5-10 days
We develop the secure structure of systems, networks, cloud environments, and other technical solutions based on identified risks and security requirements. The design takes into account interconnections, interfaces, security solutions, and the implementation of security and resilience as part of the architecture.
Short: 3-5 days / Medium: 5-15 days / Extensive: 15-30 days
We strengthen system and infrastructure security settings, configurations, and protection mechanisms based on identified risks. Current settings are compared against a secure target configuration, after which identified deviations are corrected and the impact of the changes is verified.
Short: 2-5 days / Medium: 5-15 days / Extensive: 15-30 days
We assess and develop an organization's management of user, device, and service identities and access rights. We identify unnecessary and excessive privileges, evaluate the adequacy of authentication and MFA, and specifically strengthen protection for administrative and remote access. We also develop access monitoring and continuous oversight.
Short: 2-5 days / Medium: 5-10 days / Extensive: 10-20 days
We develop network and firewall protection, network traffic management, and network segmentation, while strengthening secure configurations, management, and monitoring.
Short: 2-3 days / Medium: 4-7 days / Extensive: 8-15 days
We develop application security based on identified risks. The work may include assessing security requirements and design, secure coding, dependency checking, developing security configurations, as well as application security testing and verifying the remediation of findings.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-20 days
We implement API security improvements by identifying and fixing risks related to authentication, access rights, input handling, and traffic management. We ensure proper validation of API requests and responses, rate limiting, and secure integration with other services.
Short: 3-5 days / Medium: 5-10 days / Extensive: 10-15 days
We develop cloud environment configurations, access rights, and security architecture. The work considers the cloud model, Zero Trust principles, inter-service connections, security baselines, and consistency across multi-cloud environments. Identified misconfigurations, vulnerabilities, and other exposures are prioritized and remediated.
Short: 1-3 days / Medium: 4-10 days / Extensive: 10-20 days
We identify and prioritize an organization's vulnerabilities based on risk, threat context, and business criticality. We implement necessary patches or mitigations, verify their impact through rescanning, and continuously monitor for risk elimination.
Short: 1-3 days / Medium: 4-10 days / Extensive: 10-20 days
We develop an organization's security processes, practices, and policies by defining the current and target state, identifying areas for improvement, and clarifying roles, responsibilities, monitoring, and prioritized actions. The work is based on the principles of continuous improvement and risk-based management.
Short: 1-3 days / Medium: 4-8 days / Extensive: 8-15 days
We develop a cybersecurity governance model by defining roles, responsibilities, policies, processes, and operating procedures, along with their monitoring and development. The work considers incident preparedness, supplier responsibilities, training, incident response, and business continuity.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We develop an organization's readiness for incidents by defining operating models, roles, responsibilities, and communication practices, while ensuring technical visibility and staff operational readiness. Readiness is tested through exercises, and identified gaps are continuously addressed.
Short: 1-3 days / Medium: 4-8 days / Extensive: 8-15 days
We support cybersecurity decision-making by assessing risks, prioritizing measures, and defining responsibilities, schedules, and monitoring. The work utilizes current and target state assessments as well as risk-based decision-making.
Short: 1-2 days / Medium: 3-5 days / Extensive: 6-10 days
We support the maintenance of the organization's cybersecurity requirements by monitoring the status of requirements, controls, and risks, assessing implementation and evidence, and reporting identified gaps and development actions. The work utilizes continuous monitoring, control assessment, and documented tracking.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We develop the organization's cybersecurity learning program by defining training needs for personnel groups and roles, implementing awareness and role-based training and exercises, and measuring the impact of training on behavior. The program is continuously evaluated and developed based on risks and observations.
Short: 1-2 days / Medium: 3-7 days / Extensive: 8-15 days
SM Cybersecurity protects an organization's critical data, systems, and infrastructure with active technical defenses, threat intelligence, and continuous monitoring – so that cyber threats can be prevented before they cause harm to the business.
We protect network infrastructure by managing traffic with firewall rules, network segmentation, and access restrictions, as well as by monitoring traffic, logs, and configuration changes. The effectiveness of rules is tested, and firewall settings and security are maintained continuously.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We identify and analyze cyber threats and utilize threat intelligence, such as IOC and TTP data, to detect malicious activity, develop detection rules, and prevent attacks. The work utilizes, for example, IDPS, SIEM, and threat intelligence solutions, as well as ATT&CK-based analysis and threat hunting.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We monitor the threat landscape relevant to the organization and integrate internal and external threat intelligence sources. The information is analyzed and structured using, for example, threat actors, campaigns, and IOC and TTP data, and is translated into support for the organization's decision-making and security measures.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We continuously monitor credentials, data, and dark web activity related to the organization. Findings are analyzed and validated, and their significance to the organization and the necessary security measures are assessed.
Short: 1-2 days / Medium: 3-5 days / Extensive: 6-10 days
We collect and analyze threat intelligence from internal and external sources and correlate it with vulnerabilities, the organization's own observation data, threat actor TTPs, and asset criticality. Based on the results, we identify risks, knowledge gaps, and the most important priorities for security measures.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We strengthen secure system configurations based on defined risks and security baselines. We identify configuration drifts, remediate gaps, and verify the success of fixes using, for example, CIS Benchmark, STIG, or SCAP-based checks.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We protect user and service identities, authentication, and access rights based on risk. We manage account lifecycles, the principle of least privilege, MFA, authorizations, and, where necessary, cross-system access and service identities.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We protect API interfaces with authentication and authorization and ensure access rights for objects, operations, and data fields. We validate request and response schemas, limit traffic and resources, and manage API Gateway, WAF, error handling, and monitoring controls.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We protect application security throughout the development lifecycle. We assess and test input handling, access rights, error handling, secure defaults, dependencies, logging, and the application's attack surface, and verify that corrections have been made.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We protect sensitive and critical information by identifying and classifying data, restricting access based on need, and utilizing encryption, integrity protection, key management, and secure data disposal throughout the information lifecycle.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We manage user, administrator, and service account access rights throughout their entire lifecycle. We restrict access based on roles and the principle of least privilege, monitor privileged access, and remove or modify rights as needs, roles, or risks change.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We continuously monitor the organization's security posture, log and event data, and detect and correlate anomalies. We generate alerts, report findings, and initiate necessary measures based on observations.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We protect the recoverability of data and systems by identifying recoverable assets and their criticality, automating backups, securing and isolating recovery data, and testing restores regularly. Recovery ensures the restoration of data, functionality, and a secure state.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We provide a continuously maintained cybersecurity ecosystem that monitors security posture, manages vulnerabilities and security settings, handles findings, and produces reporting and expert support. The service implementation is based on defined responsibilities, service levels, continuous monitoring, and performance measurement.
Short: 5-10 days / Medium: 10-20 days / Extensive: 20-40 days
We manage firewall configurations and rules centrally, define an approved security baseline, handle changes through a controlled change management process, and regularly verify the functionality, currency, and deviations of rules.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We maintain firewall and infrastructure software and firmware versions under control: we inventory versions and support status, prioritize updates based on risk, test and install updates in a controlled manner, and verify their success. Firmware updates also account for authenticity checks, rollback protection, and recovery.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
We ensure that security policies are translated into practical standards, procedures, and technical controls that can be verified and remediated. Security policies, their implementation, and requirements are updated based on changes.
Short: 2-3 days / Medium: 5-10 days / Extensive: 10-20 days
In continuous development, the state of cybersecurity is constantly monitored, assessed, and improved. A changing operating environment, new threats, findings, and organizational changes guide the next steps and development priorities.
A continuous service where the state of cybersecurity, threats, vulnerabilities, and the effectiveness of security controls are monitored, analyzed, and developed on a risk-based approach. Findings drive actions, their impact is verified, and the security status is reported to support decision-making.
Short: 5-10 days / Medium: 10-20 days / Extensive: 20-40 days
We provide a continuously maintained cybersecurity framework that combines risk management, ongoing monitoring, development of protections and controls, compliance support, incident preparedness, reporting, and expert support. The framework is guided by current and target states and continuous improvement.
Short: 10-15 days / Medium: 20-40 days / Extensive: 40-80 days
A continuous service that verifies the functionality of security controls through managed attack simulations and security testing. Results are measured, identified security gaps are remediated, and the effectiveness of the fixes is verified through re-testing.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
Continuous identification of vulnerabilities, risk-based prioritization, tracking of remediation, and verification of fixes through re-scanning. Management also accounts for new vulnerabilities, emergency patches, exceptions, and alternative security measures for unpatchable systems.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We continuously monitor external and internal threat intelligence, new vulnerabilities, threat actors, and campaigns, while enriching and analyzing data to identify organization-specific risks. The results drive necessary protection, monitoring, and mitigation actions.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We continuously collect, enrich, and correlate internal and external threat intelligence, and analyze the behavior of threat actors, attacks, and campaigns. Information is structured using frameworks such as MITRE ATT&CK and translated into conclusions and recommendations to support the organization's defense.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We continuously monitor the organization's credentials, data, and other exposures on the dark web, leak sites, criminal marketplaces, and ransomware environments. Detected hits are validated, assessed, and reported for action.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We continuously monitor the organization's security posture by collecting and correlating security-related data and generating security metrics, analyses, and reports. This situational awareness helps identify changes, assess the effectiveness of protections, and support risk management decisions.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We regularly assess and re-evaluate the organization's risks, threats, vulnerabilities, and the effectiveness of security controls based on changes. This re-evaluation compares the current situation to the previous one, updates risks and necessary improvement actions, and verifies their impact.
Short: 3-5 days / Medium: 7-15 days / Extensive: 15-30 days
We continuously update cybersecurity development activities based on the current state, identified risks, findings, and the target state. Gaps are prioritized, and measures, responsibilities, resources, deadlines, and, where necessary, milestones are defined for them. Implementation is monitored, and the plan and current state are updated based on new information and achieved results.
Short: 3–5 days / Medium: 7–15 days / Extensive: 15–30 days
We repeat security testing and validations to ensure that defenses remain effective and that previously addressed vulnerabilities have not returned.
We translate technical findings into risks, priorities, and development areas that are understandable to management and support decision-making.
We create a comprehensive view of the organization's cybersecurity level, key areas for development, and their progress. This situational awareness is used to guide cybersecurity development.
We analyze attack campaigns, their methods, and technical characteristics to provide intelligence that supports security decision-making.
We identify and analyze threat actors, their tactics, and their behavior, and generate intelligence on their potential objectives and operational patterns.
We monitor cybersecurity performance, security levels, and progress using defined metrics.
The SMC model provides an organization with a clear overview of its current cybersecurity status, key risks, and necessary development measures. The goal is to systematically reduce cybersecurity risks and maintain security in a changing operating environment.
The end result for the client is →

A clear overview of the current state of cybersecurity and the risk landscape

A prioritized development plan

Concrete remediation and protection measures

Continuous security situational awareness

A measurable way to monitor and improve security

A new risk-based assessment cycle