Our services
Five service poles
Detail of the engagements offered by CyberAar. All services are priced on request after scoping.
Pole 01
Audit & offensive security
Engagement types
- → External penetration testing (network, web, API)
- → Internal penetration testing
- → Red team (complex multi-vector attack simulation)
- → Social engineering (targeted phishing, vishing)
- → Source code review
- → Configuration audit (firewall, Active Directory, cloud)
- → Architecture audit (threat modelling)
Deliverables
- → Vulnerability report with reproducible proof of concept
- → Prioritised remediation plan (CVSS)
- → Oral debrief for technical teams and management
Pole 02
Managed SOC: AarSOC
Platform built exclusively on open-source components. Two deployment models to choose from.
Managed hosted model
- → CyberAar infrastructure (sovereign European cloud)
- → Collection via Wazuh agents or syslog / Beats forwarding
- → AarView client portal: dashboard, incidents, tickets
- → Operated by the CyberAar team
Sovereign on-premise model
- → Full deployment within your own infrastructure
- → No data transits through our systems
- → Operated autonomously by your teams or with CyberAar assistance
- → AarView client portal deployed within your perimeter
Common services
- → Continuous detection: MITRE ATT&CK rules, correlation, real-time alerts
- → Triage, investigation, incident response
- → AES-256 encrypted incident reports, bilingual FR/EN
- → Full traceability of operator actions
Pole 03
Security integration
Deployment and configuration of security solutions within your existing environment. No commission on recommended solutions.
Network
- · Next-generation firewall (NGFW)
- · Intrusion prevention systems (IPS)
- · DNS filtering
- · Network segmentation and micro-segmentation
Endpoint
- · EDR (endpoint detection and response)
- · Windows and Linux system hardening
- · Fleet management and configuration compliance
Identity and access
- · Multi-factor authentication (MFA)
- · SSO and identity federation
- · Privileged account management (PAM)
Application
- · Web application firewall (WAF)
- · SAST / DAST integration in CI/CD pipelines
- · Secrets and key management
Cloud
- · Cloud security posture management (CSPM)
- · Cloud environment hardening
- · Cloud-native logging and detection
Every integration concludes with operational documentation and a skills handover to internal teams.
Pole 04
Advisory
Security project ownership advisory. We work in an advisory capacity, not an execution role.
Security programme management
Governance, roadmap, steering indicators. Coordination between business, IT and executive teams.
Infrastructure transformation
Redesign or migration of secured infrastructure. Support from design through to production deployment.
SOC / CERT capability building
Design and strengthening of an internal security operations centre or incident response team.
Secure by design
Integration of security from the design phase of software or infrastructure projects.
Post-incident crisis management
Operational coordination, remediation, internal and external communications after a security incident.
Interim or deputy CISO
Part-time coverage during a vacant position or in support of an existing security team.
Pole 05
Governance & compliance
Frameworks covered: ISO/IEC 27001:2022, GDPR / Law 2008-12 (Senegal), NIST CSF, CIS Controls.
Our commitments
Vendor independence
We do not sell software licences and receive no commission on the solutions we recommend. Our recommendations are based solely on technical fit.
Open-source components
Our hardening toolkit (51 Ansible roles, GPL-3.0) is published under a free licence. The AarSOC platform runs exclusively on open-source components with no proprietary licence. Our orchestration layer and client portal are proprietary.
Data sovereignty
You choose where your data is hosted. The on-premise model guarantees that no data transits through our systems.
Pricing on request
Our services are priced according to the actual scope of each engagement, after analysis. No imposed subscription or hidden fees.
Skills transfer
Every engagement concludes with operational documentation usable by your teams. The objective is your autonomy, not your dependency on us.