Cybersecurity · Kharkiv · Emergency 24/7

We defend companies from attacks —
from a pentest to full security ops

Need to test your defenses, stop an incident, or run security day to day. An engineer replies within one business day. If the attack is already on — use the Emergency 24/7.

  • NDA before the first message
  • Fixed scope and timeline
  • A report an auditor will accept

We work with teams that need product and infrastructure protection: MilTech, fintech, healthcare, manufacturing, retail and critical infrastructure.

move the cursor · click
Perimeter4 services exposed outside
Dark webleaked credentials found
MDR24/7 monitoring
24/7Emergency channel during an incident
1 dayfor a fixed proposal
NDAbefore the first brief
retestretest included
02 — services

What to do to protect,
during an attack, and on an ongoing basis.

Find yourself by the job to do, not by how many services we list. Pentesting has its own page — with scope, timeline and a fixed quote.

01

External pentest ePTS

We look at the perimeter the way an outside attacker would: public services, VPN, mail, cloud consoles and anything visible from the internet.

  • Recon and perimeter inventory
  • Exploitation of found vulnerabilities
  • A report with evidence and a fix plan
02

Internal pentest iPTS

We model an attacker who is already inside: a contractor, an infected laptop, or a former employee with live access.

  • Privilege escalation in the domain
  • Lateral movement across the network
  • A check of segmentation and monitoring
03

Social engineering SEPT

We test people and process, not just systems: phishing, fake “support” calls, and physical attempts to enter the office.

  • Targeted phishing campaigns
  • Vishing and pretexting
  • An attempt at physical access to the premises
04

Application security

Web and mobile apps against OWASP. Manual pentest plus tools — where a scanner only sees half the picture.

  • OWASP Top 10 and logic flaws
  • Authentication, sessions and access rights
  • APIs and external integrations
05

Source-code review

A systematic review with repository access. We find what you cannot see from the outside, and show how to fix it.

  • Manual review of critical paths
  • SAST with false-positive review
  • Dependency and supply-chain risk
06

Incident response

We contain the attack, stop the spread and restore operations. Then a root-cause write-up that a regulator or insurer can use.

  • Containment of the attack
  • Forensics and the entry point
  • Recovery and a closing report
07

Network defence

Layered defence: segmentation, access policy and traffic control. Legitimate users pass; the attacker does not.

  • Segmentation and access policies
  • Hardening of the controls
  • Traffic control and filtering
08

Dark-web monitoring

We watch closed markets and channels for your databases, credentials or internal documents.

  • Search for leaked credentials
  • Mentions of the company, brands and domains
  • An alert the moment a leak appears
09

Vulnerability management

Regular infrastructure scans, ranked by real risk, with a fix plan — not a nine-hundred-line dump.

  • Regular infrastructure scanning
  • Prioritisation by real impact
  • Fix tracking and a retest
10

Threat Intelligence

Threat data for your industry and stack, not a generic feed nobody can use.

  • Profiles of relevant threat groups
  • Indicators of compromise for your systems
  • Recommendations for your stack
11

MDR — detect and respond

Round-the-clock monitoring, detection and response on an agreed playbook. For teams without their own SOC, people or time.

  • 24/7 security-event monitoring
  • Investigation of suspicious activity
  • Response on an agreed playbook
12

Security maturity assessment

Where you are now, what is missing, and what to do first — across process, technology and culture.

  • Audit of existing controls and process
  • A comparison with your industry
  • A twelve-month roadmap
13

Standards and compliance

ISO 27001, SOC 2, PCI DSS, GDPR and NIS2 — from gap analysis to being ready for an external audit.

  • Gap analysis against the standard you need
  • Policies, process and evidence collection
  • Support during the external audit
14

Staff training

The most expensive incidents start with one click. Training, workshops and regular phishing simulations for the whole team.

  • Training for specific roles
  • Phishing simulations with metrics
  • Regular reminders and refreshers
15

DevSecOps consulting

We build security into the delivery cycle: SAST and DAST in the pipeline, review gates and coaching for your engineers.

  • SAST and DAST in your CI/CD
  • Security gates in the release process
  • Developer coaching on your own code
16

vCISO — security leadership

Security leadership without hiring a CISO: priorities, budget, regulators and reporting to the board.

  • Security strategy and priorities
  • Risk and budget management
  • Reporting for the board and clients
03 — how we work

What you get at the end

Not a severity table — findings your team can act on before lunch.

  • A technical report with reproduction steps
  • A working proof-of-concept for every exploitable finding
  • A short brief for people who will not open the technical report
  • A live walkthrough with your engineers
  • A free retest after your fixes
  • A signed attestation letter for clients and regulators
finding-0417.mdCVSS 9.1

      
  1. day 1 · free

    NDA and scope

    We sign an NDA, look at your infrastructure and the job. You get a work list, a timeline and a fixed fee.

  2. main phase

    Project work

    A named lead engineer and a shared Slack or Telegram channel. Critical findings go out immediately, not with the report.

  3. close-out

    Report and live review

    A technical report, an executive brief, and a session with your team to argue the trade-offs in the fixes.

  4. after your fixes

    Retest

    We check that the class of issue is closed, not a single instance, and issue an attestation letter. Included in the fee.

manufacturing · internal pentest 0

From guest Wi-Fi to the domain controller

A flat network and a forgotten print service reached domain admin in half a day. Segmentation was rebuilt in two weeks.

retest passed clean
retail · dark-web monitoring 0

The leak was found before the buyer of the dump

Customer credentials showed up in a closed sale. Forced password resets started before the dump was advertised.

no confirmed fraud
fintech · compliance 0

Certification passed on the first attempt

We came in four months before the audit, closed seven technical blockers and collected evidence that keeps itself current.

no auditor findings
We started with a one-off pentest and six months later handed them all of security on a retainer. Cheaper than keeping one specialist on staff, and a lot calmer.
OK
Chief operating officerretail, 600+ employees
04 — about

How we work with clients

KH Account Systems is a cybersecurity team in Kharkiv. We take a one-off project or a retainer. An engineer decides, not a sales desk.

01

NDA first, details second

We do not ask for sensitive data until the NDA is signed.

02

The price is fixed once

Scope, timeline and fee — before we start. The number does not grow later.

03

Critical findings the same day

We do not wait for the report if a finding already opens production.

04

We talk to engineers

The person on the call is the one who does the work, not a slide deck.

05

The retest is included

After your fixes we re-check the class of issue, not a single report line.

06

Emergency when it is already on fire

A normal request — one business day. An incident — a separate 24/7 channel.

05 — contact

Tell us what to
test or stop

A normal request — an engineer replies in one business day, with scope and a fixed fee. If the attack is already on — tick Emergency or call now.

normal reply — 1 business day · incident — 24/7

We sign an NDA before you send anything sensitive. Urgent: +38 095 079 14 31