One provider. Named accountability.

Traditional MSSPs sell tool licenses bundled into rigid packages. Aetos One works differently. We start with your business processes, then assign named security leaders who own the outcomes for exactly the modules your organization needs.

01
Start with your process
We map your program to how your business actually runs, not to a generic control checklist.
02
Choose your modules
Guardian, Bastion, Citadel, or a standalone engagement. Take what your risk profile requires.
03
Named accountability
Every module has a named leader who owns the outcome. No shared inbox. No ticket queue.
Combine modules and your program gets simpler to run and priced as one engagement, not stacked line items.

Guardian: Program Leadership

Fractional CISO/DPO leadership. A named leader owns your security program, your board reporting, and your vendor risk posture.

Built for organizations that need experienced security leadership but aren't ready to hire a full-time CISO. Your lead is named, reachable, and accountable for your program, whether you run this module alone or combine it with Bastion or Citadel. See what your board is actually asking about cybersecurity for the reporting gap Guardian closes.

Inquire About Guardian
What's Included
  • Named fractional CISO leadership
  • Named fractional DPO (Data Protection Officer)
  • Security program governance and roadmap
  • Board-level risk reporting (quarterly minimum)
  • Vendor and third-party risk oversight
  • Information security policy development
  • Incident response planning
  • Security awareness program oversight
  • Executive escalation and advisory access
Best fit: Organizations facing compliance mandates or board scrutiny without an internal CISO.

What does a fractional CISO engagement cost?

Cost depends on your organization's size, regulatory obligations, and how much of the program already exists. A 30-minute call is enough to scope a fair estimate for your situation.

Can I combine Guardian with Bastion or Citadel?

Yes. Each module stands on its own, and combining modules simplifies your program into a single engagement instead of separate vendor relationships.

What's Included
  • AI-native threat detection
  • 24/7 automated alert triage
  • Named security analyst coverage
  • Alert fatigue reduction through AI correlation
  • Automated incident response playbooks
  • Integration with your existing security stack
  • SIEM, EDR, and log source onboarding
  • Monthly threat briefings
  • Four uniquely scoped annual penetration tests
Best fit: Organizations experiencing alert overload or after-hours coverage gaps.

Bastion: AI-Powered SecOps

Managed security operations. Your existing tools, SIEM, EDR, network sensors, feed into one intelligent layer that triages and responds around the clock.

The AI SOC platform connects to your stack without rip-and-replace. Your team focuses on strategic projects instead of alert queues. Four uniquely scoped penetration tests run through the year, so testing reflects how your environment changes, not a single point-in-time snapshot. Bastion also solves the staffing problem behind why your hardest security hire takes six months and leaves in eighteen.

Inquire About Bastion

What is included in a managed security operations engagement?

You get 24/7 threat detection and alert triage, built on top of your existing security tools. It includes a named security analyst, incident response playbooks, and scheduled penetration testing throughout the year.

Citadel: Compliance Automation

GRC and compliance readiness. One framework is included in the base module, with additional frameworks scoped and priced as add-ons.

If your organization faces multi-framework requirements, HIPAA, SOC 2, NIST CSF, CMMC, and others, this module keeps your controls current and your audit evidence organized. We handle readiness and GRC; where formal certification is required, a certified third-party assessor completes that step. State and federal laws are already active, see how your state's cybersecurity law affects your program.

Inquire About Citadel

Is there a universal CMMC compliance deadline?

No single deadline applies to every contractor. CMMC requirements activate at the point of contract award, once a solicitation names a required level. Your actual deadline is the date of your next award, not a fixed calendar date.

Do I need a C3PAO if I work with Citadel?

Yes, for CMMC Level 2 and above. Citadel builds your program and prepares your evidence, but only a C3PAO can issue formal certification. We work alongside your C3PAO partner for that step.

What if I need more than one compliance framework?

Citadel includes one framework in the base module. Additional frameworks are scoped and priced individually, so you cover exactly the requirements you face.

What's Included
  • Compliance automation platform
  • One framework included in the base module
  • Continuous control monitoring
  • Automated audit evidence collection
  • Pre-audit validation and gap analysis
  • Compliance posture dashboards
  • Regulatory change management alerts
  • Additional frameworks scoped and priced individually
Best fit: Healthcare, financial services, or government contractors managing one or more compliance mandates.

A la carte

Not every organization needs a full modular program. These engagements stand on their own.

Penetration Testing
Standalone penetration testing for organizations that are not enrolled in Bastion. Scoped to your environment, delivered with a report your team and your auditors can use.
Inquire About Testing
Security Architecture Review
A structured review of your current architecture against your business processes and risk profile, with prioritized recommendations you can act on immediately.
Inquire About a Review
M&A Due Diligence
Know the security debt you inherit before you sign. A scoped assessment of the target's security posture, delivered on your deal timeline.
Inquire About Due Diligence
Readiness Assessments
A gap assessment against the framework or standard you need to meet, with a prioritized remediation roadmap your team can act on.
Inquire About an Assessment

What's in each module

Capability Guardian Bastion Citadel
Named fractional CISO/DPO
Board-level risk reporting
Security policy development
AI-native detection and 24/7 triage
Four annual penetration tests
Compliance automation platform
Framework coverage 1 included,
additional frameworks add-on

Modules combine into one engagement. Combining Guardian, Bastion, and Citadel simplifies your program and your invoice.

Not sure which modules fit?

A 30-minute call is enough to scope the right combination for your organization.

Schedule a Conversation