Penetration testing
Web, mobile, cloud, and internal network testing by hand, not just a scanner. We prove real impact, then stay to help you close it and verify the fix.
Cybersecurity consultancy
We're a cybersecurity firm that thinks like an attacker and reports like an engineer. Penetration testing, 24/7 managed detection, and compliance readiness — one team accountable for your whole posture.

500+
Engagements delivered
24/7
Monitored coverage
12min
Median containment time
40+
Certified consultants
Who we are
Plenty of firms will sell you a PDF full of findings and disappear. We measure ourselves on the only thing that matters — whether the way in is actually closed when we leave.
We founded Aegis in 2013 after years on the inside of security teams, watching consultants hand over a thick report full of criticals and move on to the next client. The findings were real, but nothing changed — the same issues showed up the following year, reworded. We built the firm we wished we could have hired: one that stays until the fix is verified, speaks to engineers in their own language, and treats a clean retest as the deliverable, not the invoice.
That principle runs through everything we do. Our penetration testers don't just prove a vulnerability exists — they sit with your developers to close it and come back to confirm it's gone. Our security operations centre doesn't just raise alerts — it contains the threat and tells you exactly what happened and why. Our compliance work isn't a checklist to survive an audit; it's the by-product of security that would hold up whether or not anyone were watching.
We stay senior and hands-on by design. The consultant scoping your engagement is the one testing your systems and briefing your board, not a name on a proposal handed to a junior. Fewer clients, deeper accountability, and a standing offer to be judged on the retest. If you want a stack of findings to file away, we're the wrong firm. If you want your attack surface genuinely smaller by the time we leave, let's talk.
Selected engagements
Every engagement below is measured the same way — what we found, what we fixed, and what the retest proved. Details anonymised, results real.
Penetration Test · 2025Northgate Payments
An external and internal penetration test of a payments platform that turned a clean scanner report into a hard lesson — and then a fixed one.
17
Critical findings
<1 day
Time to domain admin
Clean
Retest result
SOC / MDR · 2025Cordant Health
Onboarding a healthcare SaaS company onto 24/7 managed detection, which proved its worth within the first month.
11 min
Median containment
-83%
Alert noise
24/7
Coverage
Compliance · 2024Vela Cloud
Taking a fast-growing SaaS company from no formal controls to a SOC 2 Type II report without turning security into theatre.
0 exceptions
Audit result
90%
Controls automated
6 mo
Time to report
Incident Response · 2024Meridian Retail
A ransomware intrusion caught mid-attack, contained, and fully understood before it could reach the client's customer data.
<1 hr
Containment
None
Data exfiltrated
3 days
Full recovery
Cloud Security · 2023Aperture Analytics
A configuration and identity review of a sprawling multi-account cloud estate that had grown faster than its guardrails.
0
Public buckets
-68%
Excess roles cut
34
Accounts hardened
Red Team · 2023Northwind Enterprises
A multi-week red team engagement testing people, process, and technology against a realistic advanced-adversary scenario.
12
New detections
Reached
Objective
Stopped
Follow-up
What we do
Most clients start with an assessment and grow into ongoing defence. We recommend the right mix after we've seen your environment — never before.
Web, mobile, cloud, and internal network testing by hand, not just a scanner. We prove real impact, then stay to help you close it and verify the fix.
A 24/7 security operations centre that watches your estate, hunts for what tools miss, and contains threats in minutes — with a human on the line, not just an alert.
SOC 2, ISO 27001, PCI DSS, and HIPAA — mapped to controls you'll actually run, so passing the audit is the by-product of being genuinely secure.
When something has already happened, we contain it, work out exactly what occurred, and get you back to safe operations — with an honest account for your board.
How we operate
A finding isn't done when it's written up — it's done when the retest is clean. We work with your engineers to close every path, then prove it's closed.
The consultant who scopes your work is the one testing your systems and briefing your board. No junior learning on your production estate, no name-only leads.
We rank findings by the business impact, not a raw CVSS score, and we explain them in terms your team and your board can both act on. No fear, no jargon walls.
Credentials
OSCP & OSCE
Offensive Security certified testers
CREST accredited
Penetration testing & incident response
ISO 27001 lead auditors
Certified on staff
PCI QSA
Qualified Security Assessors
In their words
We'd rather let the security leaders we've worked with do the talking. Here's a little of what they've told us.
Their red team got domain admin in under a day and then, more importantly, sat with our engineers until every path was closed. The retest came back clean. That's the part most firms skip.
We passed SOC 2 Type II on the first attempt because Aegis treated the audit as an outcome of good security, not a paperwork exercise. Our biggest enterprise deal closed the week after.
At 2am their SOC caught lateral movement our own tools missed, contained the host, and had us on a call before the attacker moved again. They earned the retainer that night.
Tell us about your environment and your concerns. We'll come back with a scoped assessment plan — within two business days.