Security built around your business processes. Take one module or combine them. You decide what your program needs.
The Delivery Model
Traditional MSSPs sell tool licenses bundled into rigid packages. Aetos One works differently. We start with your business processes, then assign named security leaders who own the outcomes for exactly the modules your organization needs.
Module
Fractional CISO/DPO leadership. A named leader owns your security program, your board reporting, and your vendor risk posture.
Built for organizations that need experienced security leadership but aren't ready to hire a full-time CISO. Your lead is named, reachable, and accountable for your program, whether you run this module alone or combine it with Bastion or Citadel. See what your board is actually asking about cybersecurity for the reporting gap Guardian closes.
Inquire About GuardianCost depends on your organization's size, regulatory obligations, and how much of the program already exists. A 30-minute call is enough to scope a fair estimate for your situation.
Yes. Each module stands on its own, and combining modules simplifies your program into a single engagement instead of separate vendor relationships.
Module
Managed security operations. Your existing tools, SIEM, EDR, network sensors, feed into one intelligent layer that triages and responds around the clock.
The AI SOC platform connects to your stack without rip-and-replace. Your team focuses on strategic projects instead of alert queues. Four uniquely scoped penetration tests run through the year, so testing reflects how your environment changes, not a single point-in-time snapshot. Bastion also solves the staffing problem behind why your hardest security hire takes six months and leaves in eighteen.
Inquire About BastionYou get 24/7 threat detection and alert triage, built on top of your existing security tools. It includes a named security analyst, incident response playbooks, and scheduled penetration testing throughout the year.
Module
GRC and compliance readiness. One framework is included in the base module, with additional frameworks scoped and priced as add-ons.
If your organization faces multi-framework requirements, HIPAA, SOC 2, NIST CSF, CMMC, and others, this module keeps your controls current and your audit evidence organized. We handle readiness and GRC; where formal certification is required, a certified third-party assessor completes that step. State and federal laws are already active, see how your state's cybersecurity law affects your program.
Inquire About CitadelNo single deadline applies to every contractor. CMMC requirements activate at the point of contract award, once a solicitation names a required level. Your actual deadline is the date of your next award, not a fixed calendar date.
Yes, for CMMC Level 2 and above. Citadel builds your program and prepares your evidence, but only a C3PAO can issue formal certification. We work alongside your C3PAO partner for that step.
Citadel includes one framework in the base module. Additional frameworks are scoped and priced individually, so you cover exactly the requirements you face.
Standalone Engagements
Not every organization needs a full modular program. These engagements stand on their own.
Building Your Program
| Capability | Guardian | Bastion | Citadel |
|---|---|---|---|
| Named fractional CISO/DPO | ✓ | — | — |
| Board-level risk reporting | ✓ | — | — |
| Security policy development | ✓ | — | — |
| AI-native detection and 24/7 triage | — | ✓ | — |
| Four annual penetration tests | — | ✓ | — |
| Compliance automation platform | — | — | ✓ |
| Framework coverage | — | — | 1 included, additional frameworks add-on |
Modules combine into one engagement. Combining Guardian, Bastion, and Citadel simplifies your program and your invoice.
A 30-minute call is enough to scope the right combination for your organization.
Schedule a Conversation