Skip to main content

About Ion Aegis

Security you can verify, not security you have to trust.

We are an independent offensive security practice. Our entire job is to establish whether the defenses an organisation has paid for would hold, and to say so plainly either way.

01Mission

Certainty is the thing security budgets rarely buy.

Ion Aegis was built around a single conviction: an organisation should be able to check whether its defenses work, on demand, without waiting for an incident to answer the question.

Most security budgets buy capability. Very little of that spending buys certainty. Tools get deployed, policies get written, controls get marked as implemented, and the question of whether any of it would hold against a competent attacker goes unanswered until the day it is answered badly.

Our work is to answer it deliberately instead, in a controlled way, on a schedule you choose. Every engagement is designed to leave a team with three things: a clear picture of what an attacker could reach, an ordered list of what to fix first, and enough detail to fix it without guessing.

02Approach

Three disciplines, run as one engagement.

Detection, risk and hardening are usually owned by different teams, bought from different vendors and reported in different formats. We treat them as one continuous question, because an attacker does.

  1. 01

    Threat detection

    Finding the intrusion while it is still an intrusion.

    Prevention fails eventually, which makes detection the control that decides how bad a breach becomes. We test detection the only way it can honestly be tested: by generating genuine attacker behaviour inside your environment and checking what your tooling actually saw, logged and escalated.

    • Techniques executed and mapped to MITRE ATT&CK
    • Alert, log and telemetry coverage verified technique by technique
    • Detection rules drafted from behaviour we ran, then tuned against your own data
  2. 02

    Risk management

    Ranking findings by consequence, not by score.

    A severity score describes a vulnerability in isolation. It does not know that the affected host holds your signing keys, or that the vulnerable service is unreachable from anywhere that matters. We rank findings by where they sit in your environment and what they would actually cost you.

    • Findings assessed against your systems and data rather than a generic scale
    • Attack paths weighed by realistic impact and the effort needed to execute them
    • Remediation sequenced so the first week of work removes the most exposure
  3. 03

    System hardening

    Closing the route, not just the door.

    Fixing the exact issue we reported is the minimum outcome. The better one is a configuration where that class of issue stops being possible. Every finding therefore arrives with both: the immediate fix, and the structural change that stops it returning in six months under a different name.

    • Configuration baselines aligned to CIS Benchmarks and vendor guidance
    • Identity and privilege design reviewed alongside the technical fix
    • Retesting to confirm the fix holds and cannot be trivially bypassed

03Team and credentials

Senior testers, standard methodologies, no logo wall.

Ion Aegis is a small and deliberately senior practice. Our testers come from application development, network engineering, cloud architecture and incident response, which is why our reports tend to describe fixes that survive code review rather than fixes that break something else.

Every engagement is led by a named tester who stays with it from scoping through to retest. Findings are peer-reviewed inside the team before they leave it, and nothing is reported that a second person has not reproduced independently.

We do not publish client names or logos. A security engagement produces a detailed map of an organisation at its weakest, and the fact that a particular company was tested at all is information worth protecting. References are shared privately during scoping, with the client's consent.

Methodologies we work to

Application testing
OWASP Testing Guide and OWASP Application Security Verification Standard
Network and infrastructure
Penetration Testing Execution Standard and NIST SP 800-115
Adversary simulation
MITRE ATT&CK technique mapping across every executed stage
Configuration review
CIS Benchmarks and the relevant cloud provider baselines
Risk rating
CVSS as a starting point, adjusted for reachability and business impact
Reporting
Reproduction steps, evidence and a fix for every finding, without exception

How we operate

  • 01

    Authorisation before activity

    Nothing is touched until scope, rules of engagement and authorisation are agreed and signed by someone empowered to sign them.

  • 02

    A stop contact who can actually stop us

    Every engagement has a named contact on your side with the authority to halt testing immediately, and a channel that reaches us in minutes.

  • 03

    Critical findings reported the same day

    Anything that puts you at immediate risk is escalated the moment it is confirmed. Serious findings are never held back for the final report.

  • 04

    Retesting is part of the work

    Verifying your fixes is included in the engagement rather than sold back to you as a second one, because an unverified fix is only an intention.

Work with us

Find out what your defenses are actually worth.

Bring us the system you are least confident about. We will scope an engagement around it, tell you honestly whether the work would answer your question, and say so if a different service would serve you better.

Every engagement is led by a named tester from scoping through retest

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now