Our services
Five service poles
Detail of the engagements offered by CyberAar. All services are priced on request after scoping.
Offensive security
Audit & offensive security
Engagement types
- → External penetration testing (network, web, API)
- → Internal penetration testing
- → Red team (multi-vector attack simulation)
- → Social engineering (targeted phishing, vishing)
- → Source code review
- → Configuration audit (firewall, Active Directory, cloud)
- → Architecture audit (threat modelling)
Deliverables
- → Vulnerability report with reproducible proof of concept
- → Prioritised remediation plan (CVSS)
- → Oral debrief for technical teams and management
Security operations
Managed SOC: AarSOC
Platform built exclusively on open-source components. Two deployment models to choose from.
Managed hosted model
- → CyberAar infrastructure (sovereign European cloud)
- → Log collection from your systems and applications
- → AarView client portal: dashboard, incidents, tickets
- → Operated by the CyberAar team
Sovereign on-premise model
- → Full deployment within your own infrastructure
- → No data transits through our systems
- → Operated autonomously by your teams or with CyberAar assistance
- → AarView client portal deployed within your perimeter
Common services
- → Continuous detection: MITRE ATT&CK rules, correlation, real-time alerts
- → Triage, investigation, incident response
- → AES-256 encrypted incident reports, bilingual FR/EN
- → Full traceability of operator actions
Engineering and deployment
Security integration
Deployment and configuration of security solutions within your existing environment. No commission on recommended solutions.
Network
- · Next-generation firewall (NGFW)
- · Intrusion prevention systems (IPS)
- · DNS filtering
- · Network segmentation and micro-segmentation
Endpoint
- · EDR (endpoint detection and response)
- · Windows and Linux system hardening
- · Fleet management and configuration compliance
Identity and access
- · Multi-factor authentication (MFA)
- · SSO and identity federation
- · Privileged account management (PAM)
Application
- · Web application firewall (WAF)
- · SAST / DAST integration in CI/CD pipelines
- · Secrets and key management
Cloud
- · Cloud security posture management (CSPM)
- · Cloud environment hardening
- · Cloud-native logging and detection
Every integration concludes with operational documentation and a skills handover to internal teams.
Advisory
Advisory
Security project ownership advisory. We work in an advisory capacity, not an execution role.
Security programme management
Governance, roadmap, steering indicators. Coordination between business, IT and executive teams.
Infrastructure transformation
Redesign or migration of secured infrastructure. Support from design through to production deployment.
SOC / CERT capability building
Design and strengthening of an internal security operations centre or incident response team.
Secure by design
Integration of security from the design phase of software or infrastructure projects.
Post-incident crisis management
Operational coordination, remediation, internal and external communications after a security incident.
Interim or deputy CISO
Part-time coverage during a vacant position or in support of an existing security team.
Governance and compliance
Governance & compliance
Frameworks covered: ISO/IEC 27001:2022, GDPR / Law 2008-12 (Senegal), NIST CSF, CIS Controls.
Positioning against NIST CSF and CIS Controls frameworks (levels 1 to 3). Identification of priority gaps.
Implementation or revision of an information security management system aligned with ISO/IEC 27001:2022.
Structured risk analysis under ISO 31000 or EBIOS Risk Manager. Risk register and treatment plan.
Alignment with applicable sector requirements: finance, healthcare, telecommunications, public administration.
Data protection impact assessment, in compliance with GDPR and Senegalese Law 2008-12.
Weekly or monthly coverage: security programme steering, executive reporting, incident management.
Our commitments
Vendor independence
We do not sell software licences and receive no commission on the solutions we recommend. Our recommendations are based solely on technical fit.
Open-source components
Our hardening toolkit, aartool (109 CIS checks and 52 Ansible roles, GPL-3.0), is published under a free licence. The AarSOC platform runs exclusively on open-source components with no proprietary licence. Our orchestration layer and client portal are proprietary.
Data sovereignty
You choose where your data is hosted. The on-premise model guarantees that no data transits through our systems.
Pricing on request
Our services are priced according to the actual scope of each engagement, after analysis. No imposed subscription or hidden fees.
Skills transfer
Every engagement concludes with operational documentation usable by your teams. The objective is your autonomy, not your dependency on us.