Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Managed Security

Identity is the perimeter. Most estates cannot see theirs.

Identity and access management services in India are usually bought as a single sign-on project and then quietly abandoned once the login page works. The login page was never the hard part. The hard part is knowing who can reach what, why they still can, and what happens to that access the day they leave.

Every organisation accumulates the same debt: accounts belonging to people who left, service accounts nobody will admit to owning, administrators who were granted rights for one project in 2022, and a set of standing privileges that would each be refused if requested today. That accumulation is what turns a single compromised workstation into a domain-wide incident.

We work the whole discipline (governance and lifecycle, privileged access, and customer identity) with a bias toward removing standing access rather than monitoring it. Where the estate is Active Directory, the attack paths are demonstrable; see VAPT. Where it is cloud, permissions compose in ways nobody reads; see cloud security testing.

Why you need it

01 / 06

Why identity is where breaches now happen.

01

The attacker logs in rather than breaking in.

Phished credentials, session cookies lifted by stealer malware, a token that never expires, an unused administrative account with a password from 2019. None of it trips a firewall, because none of it is an attack in any technical sense. It is a valid authentication.

02

Privilege accumulates and never sheds.

People change roles and gain permissions; they very rarely lose the old ones. After a few years the average long-serving employee holds an access profile that no one would approve as a whole, and each individual grant looks entirely reasonable in isolation.

03

Leavers keep working.

HR removes payroll on the last day. The mailbox, the VPN certificate, the SaaS logins bought on a departmental card and the personal access token in a build pipeline frequently survive for months. Every one is a credential outside your control.

04

Auditors ask a question most estates cannot answer.

"Show me everyone who can access this system and when their access was last reviewed" is a standard request under ISO 27001:2022 and SOC 2. Producing that answer by hand, per system, per quarter, is the work that identity governance exists to remove.

Instrument

02 / 06

What one over-permissioned account reaches.

Thirty-six assets. Toggle a single path, a backup service account with domain rights, and watch what one compromised workstation can touch.

What we deliver

03 / 06

What we deliver.

01

Identity assessment and current state

A full picture of who and what can authenticate: user, service, machine and third-party identities across directory, cloud and SaaS. Orphaned and dormant accounts, standing privilege, shared credentials, unmanaged service accounts and the gap between your documented model and the live one.

02

Access model and role design

A role and entitlement model derived from what people actually need to do their jobs, with segregation-of-duties conflicts identified. Designed to be maintainable: a role model nobody can administer decays back into ad-hoc grants within a year.

03

Authentication and single sign-on

Consolidating applications behind one identity provider, phishing-resistant multi-factor authentication where it matters most, conditional access based on device and risk, and the elimination of the local application accounts that sit outside every control you have built.

04

Zero Trust access

Moving from network location as the basis of trust to continuous verification of identity, device posture and context on every request. Delivered incrementally against your highest-value systems rather than as an estate-wide programme that never finishes.

05

Platform implementation

Deployment and configuration of the identity platform you have chosen or are choosing (Microsoft Entra ID, Okta, Keycloak, CyberArk, Ping) integrated with your directory, your HR system and your applications, with the lifecycle automation actually switched on.

06

Access reviews and ongoing governance

Recurring certification campaigns that managers can complete in minutes rather than abandon, with revocation actually executed and evidenced. The measurable outcome is the percentage of access removed, not the percentage of reviews returned.

How we run it

04 / 06

Five phases.

  1. 01

    Discovery

    Every identity store, every application and its authentication method, every privileged account, and every joiner-mover-leaver path as it is actually executed today rather than as documented. The inventory alone is usually the first deliverable of real value.

    Weeks 1-3
  2. 02

    Risk analysis

    Standing privilege, orphaned and dormant accounts, shared credentials, segregation-of-duties conflicts, and the attack paths that identity misconfiguration creates, demonstrated rather than described, so that the priority order is not a matter of opinion.

    Weeks 3-4
  3. 03

    Target model design

    The access model, the authentication standards, the privileged access approach and the lifecycle automation, sequenced into phases that each deliver something on their own. We design for the team who will run it, not for a maturity diagram.

    Weeks 4-7
  4. 04

    Implementation

    Delivered in stages, highest risk first: privileged accounts before general users, critical applications before the long tail. Each phase is proved in a pilot group before it reaches the estate.

    Months 2-6
  5. 05

    Operate and review

    Recurring access certification, privileged session monitoring, joiner-mover-leaver automation running against HR as the source of truth, and a periodic re-assessment, because privilege starts accumulating again the day the project closes.

    Ongoing

Key benefits

05 / 06

What changes after.

The blast radius shrinks

A compromised account reaches what that role needs and nothing more, so an incident stays an incident instead of becoming a domain-wide event.

Leavers actually leave

Deprovisioning runs from HR as the source of truth across directory, cloud and SaaS, so access ends when employment does rather than when someone remembers.

Access reviews stop being a fire drill

Certification campaigns run on a schedule with evidence retained, which answers the ISO 27001:2022 and SOC 2 access-control questions without a quarterly spreadsheet exercise.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Identity platforms

  • Microsoft Entra ID
  • Okta
  • Keycloak
  • Ping Identity

Privileged access

  • CyberArk
  • Delinea
  • HashiCorp Vault
  • Microsoft PIM

Governance

  • SailPoint
  • Microsoft Entra ID Governance
  • Omada

Assessment

  • BloodHound
  • PingCastle
  • ROADrecon
  • PMapper
  • Certipy

Standards

  • NIST SP 800-63
  • OAuth 2.0 / OpenID Connect
  • SCIM
  • ISO 27001:2022 Annex A.5

Included in this service

Privileged access management (PAM)

Also

Administrative accounts are the accounts worth stealing, and in most estates they are the least controlled: shared passwords in a spreadsheet, domain administrator rights used for daily work, service accounts with permanent privilege and a password that has not changed since installation.

Privileged access management replaces standing privilege with brokered, time-bound, monitored access. Credentials are vaulted and rotated rather than known; elevation is requested, approved and expires; sessions to critical systems are recorded; and administrative work happens from hardened workstations rather than from the same laptop that reads email.

We scope it in the order that removes risk fastest: domain and cloud administrators first, then service accounts, then the third-party and vendor access that nobody owns. Just-in-time elevation is the single highest-value change in most environments, because an account with no standing privilege is worth very little to an attacker who steals it.

Included in this service

Consumer identity (CIAM)

Also

Customer identity is a different problem from employee identity. The population is larger by orders of magnitude, it is not in your HR system, it registers and abandons and returns, and every additional step in the flow costs conversion. Security that makes signing up harder gets removed by the growth team, and it should be.

We design registration and login that is secure because of how it is built rather than because of what it asks the user to endure: passwordless and social authentication, risk-based step-up that only intervenes when the signal warrants it, credential-stuffing and bot protection at the edge, secure account recovery, the flow attackers actually target, and session handling that survives real devices.

Privacy is part of the design, not a review at the end. Consent capture and withdrawal, data minimisation in the profile, retention and deletion, and preference management are built into the identity layer, which is where DPDP Act and GDPR obligations are most cheaply satisfied.

Included in this service

Identity governance and administration (IGA)

Also

Governance is the part that keeps the model true after the project ends. It automates the joiner-mover-leaver lifecycle from your HR system: access granted on the first day from the role definition, adjusted on a move with the previous role's entitlements actually removed, and revoked across every connected system on the last day.

On top of that sits certification: periodic reviews where managers confirm or revoke each person's access, designed to be completable rather than rubber-stamped, plus segregation-of-duties policy enforced at request time instead of discovered in an audit, and a request and approval workflow that gives users a faster route than asking IT informally.

The reason to invest is that it produces evidence continuously. Who had access to what, when it was granted, who approved it, when it was last reviewed and when it was removed, the exact record ISO 27001:2022 and SOC 2 assessors ask for, generated as a by-product of the process rather than reconstructed the week before an audit.

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about identity.

Where should we start if our identity estate is a mess?
With discovery and with privileged accounts, in that order. You cannot govern what you have not enumerated, and the inventory of who and what can authenticate is genuinely useful on its own. Then remove standing administrative privilege, because it is the smallest change with the largest effect on how far an intrusion travels. Role modelling and certification come after; done first, they model a state you do not actually understand yet.
We have multi-factor authentication everywhere. Is that enough?
It closes the largest gap and it is the right first control, but the current generation of attacks is built around it: adversary-in-the-middle phishing kits that relay the code, stolen session cookies that bypass authentication entirely, push-notification fatigue, and SIM swapping against SMS codes. Phishing-resistant factors (FIDO2 security keys, passkeys, certificate-based authentication) close most of that, and none of it addresses what a legitimately authenticated account is then allowed to reach.
How long does an IAM programme take?
Discovery and assessment take three to four weeks. Privileged access management for the highest-risk accounts is typically two to three months. Full lifecycle automation and certification across a mid-sized estate runs six to twelve months, and it is best delivered in phases that each stand alone. Programmes structured as one large delivery tend to stall at the point where the application owners are asked to change something.
Do we need to buy an identity governance platform?
Not immediately, and not before you know your requirements. A great deal of value comes from the design work, from cleaning up what already exists, and from switching on capability you have already licensed. Most organisations on Microsoft 365 own more of Entra ID than they use. We assess against your existing licensing first and tell you where a platform is genuinely required rather than merely conventional.
Can you work with the identity platform we already have?
Yes. We work with Entra ID, Okta, Keycloak, Ping, CyberArk, Delinea and SailPoint among others, and we are not tied to any vendor. In most engagements the finding is not that the platform is wrong but that a third of its capability was never configured: lifecycle workflows, conditional access, privileged identity management and certification campaigns are commonly licensed and switched off.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.