Skip to content

02About

A shield placed over systems that cannot stop moving

Ion Aegis is a security practice built for the organisations most likely to be damaged by an incident, and least likely to have anyone in the building who can prevent it.

01The name

What Aegis represents

Ion
A charged particle. Current, signal, data in motion, the things your organisation now runs on and cannot switch off.
Aegis
The shield Athena carried, and lent out. In the old stories it was never a weapon, only a covering placed over something worth keeping.

Put the two together and you have an accurate description of the work. A shield held over things that are already moving, and that cannot be stopped while you secure them. Nobody gets to close the clinic for a fortnight while the network is rebuilt, or stop taking orders until the identity platform is tidy.

That constraint shapes everything we do. We sequence work so the business keeps running. We prefer a change that can be made on a Tuesday afternoon to a perfect architecture that will never be funded. And we would rather leave one honest gap documented, with a named owner and a date against it, than close it on paper and let you believe it was handled.

Protection is not a product you install. It is a set of decisions, made in the right order, by people who will still be there when they are tested.

02Our story

Why the practice exists

Ion Aegis was formed around an uncomfortable observation. Enterprise security is a mature market with deep budgets, dedicated staff and vendors who answer the phone. Everyone below that line is sold much the same tools, left to configure them alone, and told they are covered.

The result is an entire tier of organisations carrying enterprise-grade risk with none of the enterprise-grade support. A clinic holding decades of patient records. A manufacturer whose production line now depends on a handful of unpatched machines. An accountant with every client return on one laptop. They are not careless. They simply have nobody whose actual job this is.

We built the practice for that gap, and we work with individuals in the same position for the same reason. Not by selling more software, but by doing the unglamorous work that closes it: finding what is genuinely exposed, fixing it in a sensible order, switching on the capability you are already paying for, and rehearsing the day it all goes wrong before that day arrives.

03Team and approach

Who does the work

We staff engagements with practitioners who have run infrastructure, responded to live incidents, and sat through audits from the inside rather than across the table. One lead consultant owns your account from the first call to the final handover, so you never explain your environment twice.

Specialists join for the phases that need them, and the person who found a problem is the person who explains it to you. We do not rotate account managers to keep an org chart tidy, and we do not hand your network to a junior as a training exercise.

If we are not the right people for a piece of work, we will say so early and tell you what to look for in whoever is.

How an engagement runs

  1. 01

    Scoping call

    Thirty minutes, no charge, no tooling. We ask what you run, what you are worried about and what has already gone wrong.

  2. 02

    Written scope and price

    You receive the boundaries of the work, what is explicitly excluded and a fixed price before anything begins.

  3. 03

    The work

    Assessment or remediation runs to the agreed window, with anything urgent raised the same day rather than held for the report.

  4. 04

    Findings review

    We walk the report through with your technical staff and your leadership, in the same room, answering questions until they stop.

  5. 05

    Remediation and handover

    We fix, or support your team while they fix, then hand over the documentation, the reasoning and the retest results.

04Values

What we hold to

These are the commitments clients hold us to, and the ones we are happy to be judged against.

  • Plain language

    Findings are written so the person approving the budget can understand them without a translator standing next to them.

  • Evidence over assumption

    We verify by hand before we report. You will never be handed a raw tool output with our name on the cover.

  • Fix the cause

    Closing a single finding is easy. We would rather understand why it was open and prevent the next ten like it.

  • Your team keeps the knowledge

    Every engagement ends with a handover, because security your own people cannot maintain is rented rather than owned.

  • No selling through fear

    If a control is not worth what it costs you, we say so and record the decision instead of quietly adding it to the invoice.

  • Confidential by default

    What we find stays between us. Nothing about your environment appears in our marketing, including your name.

Next step

Tell us what you are working with

A short scoping call is usually enough for us to say what we would look at first, what it would cost, and whether you need us at all.

Already dealing with an incident? Call +1 (512) 555-0182 rather than filling in a form.