Skip to content
CyberSmithSECURE
Under Attack

About

Art of cyber security, perfected

A CERT-In empanelled security firm working with organisations that have something worth protecting and a regulator asking about it.

How we work

In a connected estate the threat surface grows with every system, network and device you add. Testing exists to find what that growth introduced before somebody else does.

Reporting is deliberately split in two. A technical assessment carries reproduction steps and evidence. An executive summary carries risk in business terms. Most vendors produce one and let the other audience make do.

Reduced security defects
Near zeroReduced security defects
Faster threat detection
5×Faster threat detection

Method

The same seven steps, every time

Consistency is the point. A repeatable sequence is what makes one engagement comparable to the next, and what makes a retest meaningful.

  1. 01

    Scope & Risk Analysis

    Agree what is in scope, what it is worth, and what would hurt.

  2. 02

    Security Architecture Analysis

    Understand how the environment is built before trying to break it.

  3. 03

    Threat Modeling

    Work out who would attack this, and how they would go about it.

  4. 04

    Test Plan & Preparation

    A written plan, agreed in advance. No surprises during execution.

  5. 05

    Test Execution

    Controlled testing against the agreed scope, evidenced as it goes.

  6. 06

    Document & Report Findings

    Proof, business impact and severity — not a scanner dump.

  7. 07

    Recommend Remediation

    What to fix, in what order, and how to confirm it is fixed.

Founder

Dr. Smith Gonsalves

Director & CEO, CyberSmithSECURE

Began as an ethical hacker and forensic investigator, assisting law enforcement and nodal agencies, and has since served as Chief Information Security Officer and security advisor to boards across SaaS, logistics, financial services and manufacturing.

He still practises. Formally a red team architect, he breaches companies and breaks products — which is what keeps the advice grounded in what actually works rather than in what a framework recommends.

“Evaluating a product by controls and price is not going to stop the breach that is bound to happen.”
  • Red team architect
  • Virtual CISO

Education & published

PhD, Cyber Security
Counter-Adversarial Simulations of Defensive and Offensive Systems Using Stochastic Games: Markov Models and Game Theory. Pacific Academy of Higher Education & Research University, Udaipur.
Master's, Cyber Security
University of Mumbai.
Reviewing author
Mastering Defensive Security, Packt Publishing. Columnist, “The War Is On”, FORCE Magazine.

Certifications

  • OSCPOffensive Security Certified ProfessionalCleared at 19
  • CISACertified Information Systems Auditor · ISACA
  • CERT-In Empanelled AuditorGovt. of India
  • CCSKCertificate of Cloud Security Knowledge · CSA
  • TOGAFEnterprise Architecture · The Open Group
  • CEHCertified Ethical Hacker · EC-CouncilCleared at 15
  • CHFIComputer Hacking Forensic Investigator · EC-Council

Recognition

  • Global 30 Under 30 in CybersecurityTop Cyber News Magazine, France · 2026
  • CIO1000 APAC AwardEnterprise IT World
  • Award of Excellence, Cyber Risk MitigationFuture Crime Research Foundation Summit · 2024
  • India's Cyber SoldiersCyberFrat, Cyber Warfare Symposium
  • Outstanding Young Cyber Security ProfessionalComputer Society of India, Mumbai Chapter

On the record

Colleagues, clients and mentors

Recommendations left publicly by people who managed him, hired him, or worked alongside him. Reproduced as published.

His technical virtuosity is such that he can sniff out the vulnerability time and again. Beyond a shadow of doubt, I will recommend him any time anywhere.
Sanil N.CISO · Cybersecurity & AI LeaderMarch 2019
Smith Gonsalves is one of the youngest cyber security evangelists and an ethical hacker of great repute. He is a great asset to my organisation, and destined for great glory and success.
Samrendra Mohan KumarCo-founder & MD, MitKat AdvisoryApril 2019
Smith is an assiduous champ, open minded, having plethora of knowledge. There is not a single question which Smith has not got an answer for.
Gaurav BatraFounder, CyberFrat · Times 40 Under 40July 2019
Mr Smith Gonsalves is a very passionate and dedicated person who has a tremendous ability to relay his knowledge to others. I highly recommend Mr Smith to everyone looking for Cyber Security stuff.
Nitin PandeyGlobal Cybersecurity Researcher & SpeakerAugust 2018
Smith is a very hard-working person. He is one of the youngest Infosec professional around. Smith has good knowledge about the infosec domain.
Santosh KhadsareArmy Veteran · DFIR Advisor, Former CERT-InApril 2018
Smith is energetic and very patriotic. I wish to see him as a Cyber Icon of India.
Amar Prasad ReddyFormer Advisor, MoH&FW, Govt. of IndiaSeptember 2018

Presence

Where we are

Engagements run remotely by default. These are where the paperwork lives and where we can meet in person.

  • India

    Mumbai

    511, Ascot CentreMumbai 400099
  • India

    Virar (HQ)

    Nanaji Apartment, UmbergothanVirar (W) 401301
  • USA

    New Jersey

    381 Blair RoadAvenel, NJ 07001
  • Canada

    Ontario

    Suite 750, 2 Robert Speck PkwyMississauga, ON L4Z 1H8
  • UK

    Glasgow

    50 Mossbank DriveGlasgow G33 1LS
  • KSA

    Al Khobar

    Al Khobar 31952P.O. Box 4607
  • UAE

    Dubai

    308 Indigo Tower, Cluster DJLT, Dubai, P.O. Box 112965
  • Wherever the estate is. Testing is remote by default, so the office list is about paperwork and meetings, not coverage.

    Talk to us
Capability statementWho we work with, what they say, the six service lines and 54 capabilities, and anonymised engagement evidence.
Download PDF3.4 MB

Want to know whether we are a fit?

Start a conversation