Services
Four engagements, each scoped around a question you need answered.
Nothing here is sold by the hour or by the vulnerability count. Each service is defined by what we test, what you receive at the end, and how long it takes from the day you sign.
Penetration Testing
Goal-driven, manual, chained
A penetration test is only useful if it answers a question your team is actually arguing about. We start by agreeing on that question. Can an unauthenticated visitor reach customer records? Can a standard employee account become a domain administrator? Can a compromised build agent reach production? The objective shapes the scope, and the scope shapes where we spend time.
Testing is performed by hand. Automated tooling runs first to clear the ground and remove noise, but the findings that matter almost never come from a scanner. They come from reading how an application handles state, where one service trusts another, and which assumptions stop holding once you hold a valid session.
What we test
- External perimeter and internet-facing services
- Web and API application testing, authenticated and unauthenticated
- Internal network testing from an assumed-breach position
- Active Directory and identity provider privilege paths
- Segmentation validation between environments and tiers
- Business logic abuse, access control and tenancy isolation
What you receive
- Technical report with reproduction steps, evidence and affected assets
- Attack path narrative from first foothold to worst realistic outcome
- Risk-ranked remediation plan sequenced by effort and impact
- Executive summary written for a non-technical reader
- Live findings walkthrough with the testers who ran the engagement
- One free retest of remediated findings within 90 days
Typical timeline
2 to 4 weeks
One week of scoping and access setup, one to three weeks of active testing depending on application count and network size, then five business days to report. Critical findings are reported the day they are confirmed rather than held for the report.
Ransomware Simulations
Nothing encrypted, nothing exfiltrated
Ransomware is the last five minutes of an intrusion that has usually been running for days. Simulating the encryption itself teaches you very little. Simulating everything that has to succeed first teaches you almost everything, because each stage is a place your controls could have stopped it and your responders could have caught it.
We replicate the tradecraft of active ransomware operators as documented in public threat intelligence, mapped to MITRE ATT&CK so your detection team can trace every action back to a technique. Destructive steps are replaced with harmless markers: benign canary files instead of encryption, and instrumented transfers of synthetic data instead of your own.
What we test
- Initial access simulation through phishing, exposed services or a supplied foothold
- Credential harvesting, token theft and privilege escalation
- Lateral movement across workstations, servers and hypervisors
- Backup and recovery infrastructure reachability review
- Exfiltration staging using synthetic data and instrumented channels
- Detection and response timing measured at every stage
What you receive
- Stage-by-stage timeline mapped to MITRE ATT&CK techniques
- Detection gap analysis showing what fired, what logged and what passed unseen
- Time-to-detect and time-to-contain measurements per stage
- Backup and recovery exposure assessment
- Prioritised hardening and detection engineering recommendations
- Purple team debrief run jointly with your security operations team
Typical timeline
3 to 5 weeks
Two weeks of threat profiling and rules of engagement, two to three weeks of staged execution with agreed checkpoints between stages, then a joint debrief. Every stage has a documented stop condition and a named contact who can halt the exercise immediately.
Cloud Security Assessments
Effective privilege, not declared policy
Cloud breaches rarely start with an exotic vulnerability. They start with an identity that can do more than anyone realised, a role another account can assume, or a storage bucket that was public for one afternoon in 2022. The difficulty is not finding the misconfiguration. It is knowing which of the several thousand you have actually leads somewhere.
We resolve permissions the way the platform resolves them at runtime, following role chains, resource policies and federated trust across accounts and subscriptions. Then we test the paths that matter from the position of a compromised workload, so you can see the blast radius rather than a compliance score.
What we test
- Identity and access review across accounts, subscriptions and projects
- Role assumption chains, federation and cross-account trust
- Network exposure, security groups and private connectivity
- Data store configuration, encryption and public access controls
- Secrets handling in pipelines, workloads and container images
- Kubernetes and container platform configuration where in scope
- Logging, guardrail and detection coverage against control-plane abuse
What you receive
- Effective permission map with the privilege escalation paths we could reach
- Findings tied to the exact resource, policy statement and account
- Infrastructure-as-code remediation snippets your team can apply directly
- Guardrail and preventative control recommendations
- Control-plane logging and detection coverage review
- Prioritised backlog sized for a normal engineering sprint
Typical timeline
2 to 3 weeks
Three to five days for read-only access provisioning and inventory, one to two weeks of analysis and targeted path testing, then five business days to report and walk your platform team through the results.
Compliance Testing
Evidence your assessor can accept
A control that exists on paper and a control that works are different things, and an audit is an expensive place to discover which one you have. Compliance testing puts the technical controls behind your framework under the same pressure an attacker would apply, and records the result in a form your assessor already understands.
We test the control, not the questionnaire. Access reviews are checked by attempting access. Segmentation claims are checked by attempting to cross the boundary. Logging requirements are checked by generating the event and confirming it arrived, was retained and could be retrieved.
What we test
- Technical control validation mapped to your chosen framework
- Access control, least privilege and joiner-mover-leaver enforcement
- Network segmentation and cardholder or regulated data boundaries
- Encryption in transit and at rest, including key handling
- Logging, monitoring, alerting and retention verification
- Vulnerability management and patch cadence evidence
- Change management and deployment control testing
What you receive
- Control-by-control results mapped to the framework requirement
- Evidence pack formatted for direct submission to your assessor
- Gap register with owner, effort estimate and remediation guidance
- Readiness assessment against your target audit date
- Retest of remediated controls before the audit window opens
- Assessor question support during the audit itself
Typical timeline
3 to 6 weeks
Duration scales with framework and environment count. A single-framework readiness pass typically runs three weeks; a multi-framework programme across several environments runs closer to six. Retesting before the audit window is included in the engagement.
Engagement process
How an engagement runs, start to finish.
Every service follows the same five stages. The middle stage changes shape depending on what we are testing. The stages either side of it never do.
- 012 to 5 days
Scoping
A working call with the people who would run the test. We agree the question the engagement has to answer, the systems in scope, and what would count as a serious finding. You get a written proposal with dates, scope and a fixed cost.
- 021 to 3 days
Authorisation
Rules of engagement are signed, testing windows are fixed, and your named stop contact is confirmed. Where a third-party provider hosts systems in scope, we help you obtain their written approval before anything begins.
- 031 to 4 weeks
Testing
Active testing against the agreed scope, with a shared channel open throughout. Progress is reported at agreed checkpoints, and anything critical is escalated the day it is confirmed rather than saved for the report.
- 043 to 5 days
Reporting
You receive the technical report, the attack path narrative, the ranked remediation plan and an executive summary. A live walkthrough with the testers follows, so your engineers can ask questions while the detail is fresh.
- 05Within 90 days
Retest
Once your team marks findings as fixed, we verify each one, confirm the fix cannot be bypassed by a variation of the original technique, and reissue the report with those findings closed and dated.
Next step
Contact Ion Aegis
Tell us which service fits and which systems are in scope, or describe the problem and let us recommend one. Scoping calls are free, and we will tell you if the work would not answer your question.
Fixed scope, fixed cost, dates agreed before anything begins