Aegis Ascent
Common Questions

Questions We Get Asked

Straight answers about how engagements work, what they cost, and what access we need.

View Service Packages

How we work

Are you a managed service provider?

No. An MSP sells a monthly contract and takes over ongoing operations. Aegis Ascent does defined projects with a start, an end, and a fixed price. You get the work without a recurring commitment and you keep control of your own environment. For most businesses under two hundred people, that costs meaningfully less than a year of managed services.

Why don't you publish prices?

The same project is a different amount of work at every company. Compliance work for a six-attorney firm and a forty-attorney firm share a name and nothing else. A published number would have to cover the worst case, and you'd be paying for someone else's complexity.

What's fixed is the price against an agreed scope. If something new surfaces or you want to add work, that's a written amendment with its own price — never a surprise on the invoice.

The scoping conversation is free, so you know the number before you commit to anything.

Do I have to commit to the whole thing up front?

No. The assessment and the remediation work are separate engagements with separate prices. You can stop after the assessment and keep the findings and the remediation plan, whether you hand them to internal staff, another vendor, or a drawer.

If you do proceed within 60 days, the assessment fee is credited against the remediation engagement.

Is Aegis Ascent one person?

Yes. The person who scopes your project does the work and answers the phone afterward. Nothing gets translated into a ticket and handed off to someone you've never met.

That limits how many engagements run at once. It also means nothing gets lost in translation, which is why “Expertise You Can Talk To” isn't just a line on the front page.

Do you work remotely or on site?

Remote for anything that can be done remotely, which covers most Microsoft 365, identity, and policy work. Some things need hands on hardware — firewall deployments in particular — and for those I travel up to 150 miles from Peoria. Travel is quoted as a dispatch fee inside the original scope, based on distance, so it's never a surprise line item.

What happens when a project ends?

You get the full report, the change log, and thirty days of support for anything that appears to trace back to the work performed.

After that, your administrators have had access to the environment again, and attributing a new problem to work completed a month earlier stops being honest. You're welcome to come back for more work at any point — it gets scoped separately unless we've agreed otherwise up front.

Who we work with

What size organizations?

Roughly ten to two hundred people. Small enough that a dedicated security hire doesn't make sense, large enough that the risk is real and somebody has noticed.

Do you only work with law firms?

No. The specialization is security, compliance, and AI readiness — not a single industry. Law firms are a strong early focus because eDiscovery, retention policy, and legal hold in Microsoft Purview are a well-defined problem I've solved repeatedly, and because the consequences of getting client data wrong are unusually clear there.

The same work applies anywhere sensitive data matters. Financial services, healthcare, agriculture, manufacturing, professional services.

How far do you travel?

Onsite work goes up to 150 miles from Peoria, which covers most of Central Illinois and reaches into the Quad Cities, Champaign, Springfield, and the Bloomington-Normal corridor. Remote work has no geographic limit. Farther onsite travel is possible if the engagement justifies it.

Technical

What's your relationship with Sophos?

Aegis Ascent is a Sophos Silver Partner with twelve-plus product accreditations across endpoint, XDR, MDR, and firewall. Practically: direct access to Sophos support and engineering rather than going through a reseller, correct licensing without markup games, and someone configuring the product who has been trained on it rather than reading the manual on your time.

Do we need to be on Microsoft 365 already?

No. Tenant creation and migration are part of the work. Legacy on-premises Exchange, Google Workspace, or a mix nobody has documented are all normal starting points.

Can you help if we're mid-migration or inherited a mess?

That's most engagements. Environments configured correctly from the start don't usually need this work. Half-finished migrations, tenants stood up years ago by someone who left, and security settings enabled once and never revisited are the normal case.

What access do you need, and what happens to it afterward?

The assessment is read-only. Global Reader in Microsoft 365 and read access to your firewall shows everything without the ability to change anything.

Every account is a named account created specifically for this engagement. No shared credentials, no borrowing an existing admin login. Where automation is used to collect data or apply changes, it runs under its own separate service account rather than mine — so your audit log distinguishes what a person did from what a tool did, and both trace back to something identifiable.

When the engagement ends, every account is stripped of its rights and removed.