01Service line

Cybersecurity services: advisory, testing, engineering, detection and response

Onion Infosec assesses risk, tests systems the way an attacker would, engineers controls across identity, cloud, data and applications, and runs detection and response 24×7. Each engagement ends with evidence, a prioritized fix list and, where you want it, the engineers to carry out the fixes.

Line
01 of 07 · Cybersecurity
Shape
Assess → Protect → Detect → Respond
Delivery
Project, retainer or managed service

01Context

What the cybersecurity line covers

The cybersecurity line has seven capability groups. They are advisory and GRC, offensive security, application security, protection of identity, cloud and data, detection and response, threat intelligence, and incident response and forensics. Each group can be engaged on its own. Together they cover the full cycle: assess risk, test controls, build protection, monitor, and respond when something goes wrong.

Work is delivered remotely and on site, as fixed-scope projects, retainers or managed services. Security monitoring and incident response readiness are available 24×7. What the practice learns feeds Security Labs research and the security products Onion is developing.

Controls need independent testing
A control that has never been tested is an assumption. Manual testing and adversary simulation show which weaknesses can be reached and chained, so remediation effort goes to the paths that lead to sensitive data and critical systems.
Customers and regulators ask for evidence
Procurement teams, auditors and regulators expect a documented risk assessment, tested controls and a working incident process. A program built on controls that operate produces that evidence as a by-product of normal work.
Detection and response take practice
Monitoring works when telemetry is complete, detections reflect real attacker behavior and the response path has been rehearsed. Staffing that around the clock is difficult for most internal teams.

Architecture

How detection and response fit together.

Assessment and protection work reduce what can go wrong. This is the part that runs every day: what is collected, where it is correlated, who investigates, and how each incident makes the next detection better.

Fig. 01From telemetry to response

Six telemetry sources (identity, endpoint, network, cloud, email, and SaaS and applications) feed one pipeline. Stage one collects telemetry. Stage two correlates it in a SIEM or XDR platform such as Microsoft Sentinel, Splunk or Elastic. Stage three is detection engineering mapped to MITRE ATT&CK. Stage four is investigation by analysts and threat hunting. Stage five is incident response and digital forensics. Stage six, tuning and threat intelligence, returns to detection. Red teaming and adversary simulation test the detections.

Every source lands on one bus. Incidents move left to right. What is learned returns to detection.
  • Telemetry and incident flow
  • Feedback into detection

02Approach

How we work

Every engagement starts from your threat model and business context: what you run, what matters most and who is likely to target it. Scope, rules of engagement and deliverables are agreed in writing before work begins.

Testing is manual and findings are validated before they are reported. Advisory work ends in controls that operate. Managed services run to documented runbooks with agreed escalation paths.

01

Validated findings

Every reported vulnerability is confirmed by hand, with evidence and reproduction steps. Unexploitable scanner output is left out.

02

Attack paths over finding counts

Individual issues matter less than the routes they create. Reports show how weaknesses chain together, from an exposed endpoint to privileged access.

03

Controls that operate

Compliance work is anchored to risk assessment. Policies are short, specific and mapped to how teams work, so evidence comes from normal operations.

04

Fix what we find

Remediation guidance is written for engineers. Where you want hands-on help, Onion cloud, development and IT teams can carry out the fixes.

03Capabilities

How cybersecurity work is organized.

  1. Assess

    Understand risk, obligations and what an attacker can reach.

  2. Protect

    Engineer controls into applications, identity, cloud and data.

  3. Detect

    Watch for adversary behavior, informed by intelligence.

  4. Respond

    Contain, investigate and recover when it counts.

Advisory & GRC

Governance, risk and compliance advisory anchored to real risk, from gap assessment to audit support. Onion is not a certification body. External audits are performed by independent accredited firms.

Offensive Security

Manual penetration testing and adversary simulation across applications, infrastructure, cloud and wireless. Findings are validated, evidenced and rated by exploitability and business impact.

Application Security

Security placed in design reviews, pull requests and pipelines, where issues are cheapest to fix. The work is done with your engineering teams, and controls are delivered as code they own.

Identity, Cloud & Data Protection

Engineering of the controls that decide whether a stolen credential or a misconfiguration turns into an incident. We design, implement and tune these controls on the platforms you already run.

Detection & Response

Security operations run as an engineering discipline: measured telemetry, detections mapped to MITRE ATT&CK, documented triage and rehearsed response. Monitoring is available 24×7, fully managed or co-managed with your team.

Threat Intelligence

Intelligence scoped to your sector, technology and exposure, delivered in a form that detection, response and risk teams can use.

Incident Response & Forensics

Response and investigation for active or suspected intrusions, plus the preparation that shortens them. Evidence handling follows forensic practice so that findings hold up under regulatory, insurance and legal review.

04Process

How a cybersecurity engagement runs.

  1. Scope

    We map the environment and agree objectives, rules of engagement, test windows and emergency contacts. The statement of work names the deliverables.

  2. Assess or onboard

    Projects begin with reconnaissance, document review or a gap assessment. Managed services begin with log-source onboarding, runbooks and escalation paths.

  3. Execute

    Testing, implementation or monitoring runs within the agreed boundaries. Critical findings are reported as soon as they are confirmed.

  4. Report

    Leadership receives a summary of risk in business terms. Engineers receive technical findings with evidence, reproduction steps and prioritized remediation guidance.

  5. Remediate and verify

    We stay available during the fix cycle and retest remediated findings where retesting is in scope. Onion engineers can carry out the fixes if you want them to.

  6. Review

    Managed services and retainers have regular service reviews. Incidents, false positives and test results feed back into detection content and the roadmap.

What you receive

  • Executive summary with risk described in business terms
  • Technical findings with evidence, reproduction steps and CVSS scoring adjusted for context
  • Attack-path analysis showing how findings chain together
  • Prioritized remediation roadmap with owners
  • Gap assessment, risk register and treatment plans for advisory work
  • Detection use cases mapped to MITRE ATT&CK, with runbooks and an escalation matrix
  • Regular service reports on coverage, incidents and tuning actions for managed services
  • Incident reports with timeline, scope of compromise and root cause

05Technical depth

Typical cybersecurity engagements, technology and methods.

  • Penetration test

    Fixed-scope project against one or more applications, networks or cloud environments, usually measured in weeks. A retest of remediated findings can be included in scope.

  • Gap assessment and readiness program

    A short assessment against the target framework, followed by a multi-month implementation program that ends with an internal audit and support during the external audit.

  • Red team exercise

    Objective-based campaign over an extended window, known only to a small group on your side. It closes with a joint debrief between testers and defenders.

  • Managed detection and response

    Ongoing managed service. An onboarding phase covers log sources, runbooks and escalation paths, then 24×7 operation begins with regular reporting and service reviews.

  • Incident response retainer

    Annual retainer with environment onboarding, a readiness review and pre-agreed engagement terms.

  • Security architecture review

    Time-boxed advisory engagement that documents the current state, defines a target architecture and delivers a sequenced roadmap.

Technology areas

SIEM and analytics

  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic Security
  • Wazuh

Endpoint and XDR

  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • CrowdStrike Falcon
  • Wazuh agents

Identity

  • Microsoft Entra ID
  • Active Directory
  • Privileged Identity Management
  • Conditional Access
  • FIDO2 and passkeys
  • SAML, OAuth 2.0 and OIDC

Cloud platforms

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Microsoft 365
  • Kubernetes
  • Terraform

Application security tooling

  • SAST
  • DAST
  • SCA
  • Secrets detection
  • SBOM and artifact signing
  • GitHub, GitLab and Azure DevOps pipelines

Testing and forensics

  • Burp Suite
  • Nmap
  • BloodHound
  • Volatility
  • Disk and memory acquisition tools
  • Malware sandboxing

Technologies are named to describe the work. Naming a product does not indicate a commercial partnership.

Frameworks and methods

MITRE ATT&CK

Maps detection coverage, plans red team and purple team exercises, and structures threat hunts.

OWASP ASVS, Top 10 and testing guides

Define test coverage for web, mobile and API assessments.

PTES

Structures penetration test phases from scoping to reporting.

CVSS

Scores findings, with severity adjusted for business context.

NIST CSF

Structures security programs and maturity assessments.

ISO/IEC 27001

Baseline for ISMS design, gap assessment and internal audit.

CIS Controls and Benchmarks

Prioritized hardening baselines for configuration reviews.

NIST SP 800-61

Reference for incident handling phases in IR plans and playbooks.

06Across lines

Engineering to fix what we find.

Onion also builds and runs technology, so the organization that reports a weakness can fix it. Cloud engineers rebuild landing zones and IAM as code, and development teams correct application flaws and harden pipelines. IT operations closes patching, hardening and backup gaps. Remediation is scoped separately from testing, and a retest confirms closure.

07Questions

Cybersecurity: questions we are asked

A scan lists known vulnerabilities automatically. A penetration test is manual: testers examine logic, chain findings into attack paths and confirm every result. The report contains fewer findings, and each one is real.

Rules of engagement are agreed up front, including test windows, excluded systems and emergency contacts. Destructive techniques are never used without explicit written authorization.

No. Certification and attestation audits must be independent, and they are performed by accredited certification bodies or licensed audit firms. We prepare you, support control implementation and assist during that audit.

No. We operate the platforms you own, such as Microsoft Sentinel, Splunk, QRadar, Elastic, CrowdStrike and Microsoft Defender. A change is recommended only when the current tooling cannot meet the requirement. Runbooks and detection content built for you remain yours.

Members of our team hold OSCP, CISSP, CISM, CEH, CHFI and more. These are individual certifications, not company accreditations.