Dr. Smith Gonsalves

Capability Statement // CyberSmithSECURE

Where toengage us

Dr. Smith Gonsalves · Director & CEO, CyberSmithSECURE
Red team architect · Virtual CISO · CERT-In empanelled auditor

Seven engagement areas, one operating principle: find the way in before someone else does, then make the finding impossible for a board to ignore.

12Years in information security
500+Organisations secured
25,000+Professionals trained
1,000+Conference stages
4Continents operated across

Engagement map // capability × audience

Founder / CEOCISO / CxOGov / LEAMedia / Org01 · VAPT & red teaming02 · Virtual CISO03 · GRC & compliance04 · Cyber investigation & forensics05 · Offensive & defensive training06 · Cyber awareness programmes07 · Conference build-up & advisoryPRIMARY ENGAGEMENTSECONDARY / SUPPORTING

Read across a row to see who a capability serves; read down a column to see everything available to you.

How an engagement runs

1ScopeThreat modelRisk appetiteSuccess criteria2TestBlind-spot analysisVAPT / red teamControl evasion3WeaponiseControlled exploitRecorded PoCCVSS impact4ReportExec summaryTechnical detailMust-have controls5SustainRemediation supportQuarterly retestBoard reporting

Stages 1–4 are project work · stage 5 is where most of the risk reduction actually happens

Capability areas

Seven areas, and what you can actually ask for.

Each area below lists concrete engagements — not service categories. If what you need is not listed, it is probably adjacent to something that is.

01

VAPT & Red Teaming

For CISOs · CTOs · Engineering leadership

Offensive assurance across the whole estate. The method is to predict the attack before it lands — mapping blind spots, weaponising them under controlled conditions, and modelling risk in UAT before it reaches production.

  • Web, mobile and API application penetration testing
  • Cloud configuration and posture assessment (AWS, Azure, GCP)
  • Container and Docker environment assessment
  • Network and infrastructure VAPT, internal and external
  • Full red team engagement with control-evasion reporting
  • Secure code review and DevSecOps pipeline assessment
  • Social engineering and phishing simulation drills
  • Quarterly continuous security assessment retainer
PDFDownload profile — Product & Infrastructure SecurityOne page · method, estate coverage, client engagements
Technical panel session
Technical panel session
02

Virtual CISO (vCISO)

For founders · CEOs · Boards · Investors

Security leadership on a fractional basis, for organisations that need the function before they can justify the headcount. Cyber budget framed as deterrence ROI rather than overhead.

  • Fractional CISO retainer with defined reporting cadence
  • Security strategy and multi-year roadmap
  • Long-range cyber budget modelling and spend optimisation
  • Board and audit-committee reporting packs
  • Security steering committee leadership or participation
  • Pre-IPO and listed-company security diligence readiness
  • Series A, B and C investor diligence support
  • Incident response readiness and tabletop exercises
  • Security due diligence on M&A targets
PDFDownload profile — Virtual CISOOne page · board mandates, cyber economics, recommendations
Enterprise security panel — New Delhi
Enterprise security panel — New Delhi
03

GRC & Compliance

For CISOs · CFOs · Legal & risk · Founders

Governance, risk and compliance run as a programme rather than an annual scramble — including audit work under CERT-In empanelment.

  • ISO 27001 readiness, implementation and internal audit
  • PCI-DSS gap assessment and remediation support
  • CERT-In empanelled security audit
  • India DPDP Act and GDPR privacy readiness
  • SOC 2 readiness support
  • Policy, standard and procedure framework build-out
  • Third-party and vendor risk assessment programme
  • Data loss prevention strategy and implementation planning
  • Managed GRC on an ongoing retainer
PDFDownload profile — Virtual CISOGRC and compliance sit within the vCISO mandate
04

Cyber Investigation & Forensics with Government

For law enforcement · Nodal agencies · Government · Enterprise legal

Casework and capability-building with agencies including CERT-In, NCIIPC, state police cyber cells and the Ministry of Home Affairs — beginning with the National Cyber Defence Research Centre at the age of 15.

  • Digital forensics — disk, memory and mobile
  • Case support and investigative assistance for cyber cells
  • Evidence handling and chain-of-custody advisory
  • OSINT, attribution and threat-actor tracking
  • Financial and job-fraud trail analysis
  • Malware triage and artefact reconstruction
  • Policy-level governance recommendations for national cyber posture
  • Capability-building programmes for investigating officers
  • Expert advisory on critical information infrastructure protection
PDFDownload profile — Cyber Crime InvestigatorOne page · agency engagements, forensics, LEA capability
United Service Institution of India — New Delhi
United Service Institution of India — New Delhi
05

Offensive & Defensive Security Training

For security teams · Engineering · SOC · Officers · Executives

More than 25,000 professionals trained to date. Delivered in-person or remote, scoped to the estate the team actually defends rather than a generic syllabus. Full course matrix below.

  • Offensive track — ethical hacking, VAPT and exploitation
  • Defensive track — detection engineering, SOC and blue team
  • Forensics track — DFIR and evidence handling
  • Secure engineering track — secure code and DevSecOps
  • Executive track — board-level cyber briefings and tabletops
  • Cyber range and capture-the-flag exercises
  • Certification preparation mentoring (CEH, CHFI, OSCP)
PDFDownload profile — Cyber Crime InvestigatorTraining record and agency capability-building
06

Cyber Awareness Programmes

For HR · Internal comms · CISOs · All staff

The control that fails most often is the person. Awareness run as a measured programme with a baseline and a trend, not a once-a-year video.

  • Organisation-wide awareness campaign design and delivery
  • Phishing simulation with click-rate baselining and retesting
  • Role-specific modules — finance, HR, engineering, leadership
  • New-joiner security onboarding module
  • Cyber Security Awareness Month programming
  • Executive and high-value-target briefings
  • Awareness content in regional languages
07

Conference Build-Up & InfoSec Event Advisory

For media companies · Conference organisers · Trade bodies

Advisory roles across GISEC, GITEX, InterSec, BlackHat Middle East, FCRF, CyberX, CSI Cyber-FiFC and InfoComm. Scaling an event end to end through a network reaching 15,000+ security professionals.

  • Senior keynote and panel speaker acquisition
  • Agenda and track design
  • Community and knowledge partner brokering
  • Embassy and consulate partnerships — Israel, EU, UK, US
  • Sponsor and exhibitor pipeline development
  • Delegate registration growth via social and media coverage
  • Press and media partnerships
  • On-stage hosting and panel moderation
  • CXO round tables and closed-door briefings
PDFDownload profile — Event Orchestration & AdvisoryOne page · advisory roles, partnerships, hosted stages
Innovation Stage, InterSec 2025 — Dubai
Innovation Stage, InterSec 2025 — Dubai

Training catalogue

Five tracks, offensive through executive.

Every track is scoped to your environment. Durations are indicative and adjust with depth and cohort size.

Track coverage by audience seniority

ALL STAFFPRACTITIONERSENIOR / LEADBOARD / EXEC01 · OFFENSIVEETHICAL HACKING · VAPT · EXPLOITATION02 · DEFENSIVEDETECTION ENGINEERING · SOC · BLUE TEAM03 · FORENSICSDFIR · EVIDENCE HANDLING · CHAIN OF CUSTODY04 · SECURE ENGINEERINGSECURE CODE · DEVSECOPS · THREAT MODELLING05 · EXECUTIVETABLETOP · BOARD BRIEFING

Cyber awareness sits beneath all five tracks and is delivered organisation-wide — see capability 06.

Offensive

Ethical Hacking, VAPT & Exploitation

Reconnaissance through to exploitation and reporting, on a live lab estate. Built from the same methodology used on client engagements.

Audience — security analysts, pen testers, engineersIndicative — 3–5 days · hands-on lab

Defensive

Detection Engineering, SOC & Blue Team

Building resilient detection pipelines — telemetry, correlation and context. Writing detections that survive an attacker who knows they exist.

Audience — SOC analysts, detection engineers, IR teamsIndicative — 3–4 days · purple-team exercise

Forensics

Digital Forensics & Incident Response

Disk, memory and mobile forensics, evidence handling and chain of custody. Delivered for both enterprise IR teams and investigating officers.

Audience — IR teams, LEA officers, internal auditIndicative — 3–5 days · case-based

Secure engineering

Secure Code & DevSecOps

Threat modelling, secure coding patterns and pipeline security for the people who will actually fix the findings.

Audience — developers, DevOps, architectsIndicative — 2–3 days · language-specific

Executive

Board Briefing & Crisis Tabletop

What a breach looks like from the boardroom: decisions, disclosure, and the questions regulators and press will ask within the first 24 hours.

Audience — boards, CxOs, comms and legalIndicative — half day · scenario-driven

Awareness

Organisation-Wide Cyber Awareness

Phishing simulation with baselining, role-specific modules and measurable susceptibility trends over time.

Audience — all staff, role-segmentedIndicative — ongoing programme

Client recommendations

From the people who engaged us.

I had the privilege of working closely with Smith Gonsalves and his team during their engagement for Vulnerability Assessments, Penetration Testing, Red Teaming etc. Smith's expertise and meticulous approach to cybersecurity were instrumental in ensuring our systems remained robust and resilient against potential threats.
Arup Mandal
VP — IT, Infosec & Data Privacy, Ather Energy
Client · February 2025
His technical virtuosity is such that he can sniff out the vulnerability time and again. Beyond a shadow of doubt, I will recommend him any time anywhere.
Sanil N.
CISO · Cybersecurity & AI Leader
Client · March 2019

Engage

Start with the threat you already suspect.

First response within two working days. Engagements can run under NDA from first contact.

Useful to include in a first brief

  • Which capability area above is closest to your need
  • Rough scale — estate size, headcount, or delegate numbers
  • Any deadline driving it: audit, funding round, launch, event date
  • Whether you need an NDA in place before details
  • Preferred engagement shape — project, retainer, or advisory
What’s this about?