Our services

Five service poles

Detail of the engagements offered by CyberAar. All services are priced on request after scoping.

Pole 01

Audit & offensive security

Engagement types

  • External penetration testing (network, web, API)
  • Internal penetration testing
  • Red team (complex multi-vector attack simulation)
  • Social engineering (targeted phishing, vishing)
  • Source code review
  • Configuration audit (firewall, Active Directory, cloud)
  • Architecture audit (threat modelling)

Deliverables

  • Vulnerability report with reproducible proof of concept
  • Prioritised remediation plan (CVSS)
  • Oral debrief for technical teams and management
All services →

Pole 02

Managed SOC: AarSOC

Platform built exclusively on open-source components. Two deployment models to choose from.

Managed hosted model

  • CyberAar infrastructure (sovereign European cloud)
  • Collection via Wazuh agents or syslog / Beats forwarding
  • AarView client portal: dashboard, incidents, tickets
  • Operated by the CyberAar team

Sovereign on-premise model

  • Full deployment within your own infrastructure
  • No data transits through our systems
  • Operated autonomously by your teams or with CyberAar assistance
  • AarView client portal deployed within your perimeter

Common services

  • Continuous detection: MITRE ATT&CK rules, correlation, real-time alerts
  • Triage, investigation, incident response
  • AES-256 encrypted incident reports, bilingual FR/EN
  • Full traceability of operator actions
All services →

Pole 03

Security integration

Deployment and configuration of security solutions within your existing environment. No commission on recommended solutions.

Network

  • · Next-generation firewall (NGFW)
  • · Intrusion prevention systems (IPS)
  • · DNS filtering
  • · Network segmentation and micro-segmentation

Endpoint

  • · EDR (endpoint detection and response)
  • · Windows and Linux system hardening
  • · Fleet management and configuration compliance

Identity and access

  • · Multi-factor authentication (MFA)
  • · SSO and identity federation
  • · Privileged account management (PAM)

Application

  • · Web application firewall (WAF)
  • · SAST / DAST integration in CI/CD pipelines
  • · Secrets and key management

Cloud

  • · Cloud security posture management (CSPM)
  • · Cloud environment hardening
  • · Cloud-native logging and detection

Every integration concludes with operational documentation and a skills handover to internal teams.

Pole 04

Advisory

Security project ownership advisory. We work in an advisory capacity, not an execution role.

Security programme management

Governance, roadmap, steering indicators. Coordination between business, IT and executive teams.

Infrastructure transformation

Redesign or migration of secured infrastructure. Support from design through to production deployment.

SOC / CERT capability building

Design and strengthening of an internal security operations centre or incident response team.

Secure by design

Integration of security from the design phase of software or infrastructure projects.

Post-incident crisis management

Operational coordination, remediation, internal and external communications after a security incident.

Interim or deputy CISO

Part-time coverage during a vacant position or in support of an existing security team.

Pole 05

Governance & compliance

Frameworks covered: ISO/IEC 27001:2022, GDPR / Law 2008-12 (Senegal), NIST CSF, CIS Controls.

Maturity assessment

Positioning against NIST CSF and CIS Controls frameworks (levels 1 to 3). Identification of priority gaps.

ISMS construction

Implementation or revision of an information security management system aligned with ISO/IEC 27001:2022.

Risk analysis

Structured risk analysis under ISO 31000 or EBIOS Risk Manager. Risk register and treatment plan.

Regulatory compliance

Alignment with applicable sector requirements: finance, healthcare, telecommunications, public administration.

DPIA / PIA

Data protection impact assessment, in compliance with GDPR and Senegalese Law 2008-12.

Part-time CISO

Weekly or monthly coverage: security programme steering, executive reporting, incident management.

Our commitments

Vendor independence

We do not sell software licences and receive no commission on the solutions we recommend. Our recommendations are based solely on technical fit.

Open-source components

Our hardening toolkit (51 Ansible roles, GPL-3.0) is published under a free licence. The AarSOC platform runs exclusively on open-source components with no proprietary licence. Our orchestration layer and client portal are proprietary.

Data sovereignty

You choose where your data is hosted. The on-premise model guarantees that no data transits through our systems.

Pricing on request

Our services are priced according to the actual scope of each engagement, after analysis. No imposed subscription or hidden fees.

Skills transfer

Every engagement concludes with operational documentation usable by your teams. The objective is your autonomy, not your dependency on us.

Contact us All services