Autonomy secured
the hard way

We get in first, so adversaries can't. You see every gap before they do, and take control of your security.

Request an assessment →If it moves, we are already in.

Trusted by

  • Tridel
  • Integral
  • Pearler
  • TriplePlay

Most of our work is under NDA, so this is the short list.

The argument

Two clocks are running. Only one is yours.

The exposure window is how long a weakness stays reachable, from the moment it exists to the moment it is genuinely closed. It predicts both outcomes that matter: whether you get breached, and how badly it lands. Every other number the industry counts is a proxy for it.

Their clock
22sec

Median time from initial access to handing that access to another crew, down from more than eight hours in 2022.

Mandiant M-Trends 2026
29min

Average breakout time in 2025: intrusion to lateral movement. The fastest observed was 27 seconds.

CrowdStrike Global Threat Report 2026
05days

Median time from a vulnerability being published to it being confirmed exploited in the wild. It was 8.5 days the year before.

Rapid7 Global Threat Landscape Report 2026
Your clock
14days

Global median dwell time in 2025, how long an intruder sat inside before anyone noticed. It rose from 11.

Mandiant M-Trends 2026
25days

Median dwell time when somebody outside the organisation was the one to break the news. It rose from 11.

Mandiant M-Trends 2026
241days

Average breach lifecycle, identify through contain. Organisations that found it themselves saved roughly $900,000.

IBM Cost of a Data Breach 2025

Twenty-two seconds against fourteen days. No count of open criticals closes that gap. Shortening your side does. So we keep the same clock we ask you to keep, and criticals reach you the day we prove them, with a reproduction and a fix.

48hSigned scope to operators on target
03Days to first critical, typical engagement
14Days to final report, most engagements

What we do

Full-stack offense

Drone and robotics testing, adversarial assessments, security consulting, incident response, and the ASEC platform.

Experience

More than a decade in business.

Member of

Canadian Association of Defence and Security IndustriesAlliance of Canadian Defence CompaniesCanadian Cyber Threat ExchangeCanadian Cybersecurity Industry Cluster
Nick Aleks, founder of ASEC

Who breaks it

Nick Aleks

Founder & CEO

Nick Aleks is a security engineer, researcher, and the founder and CEO of ASEC. He's led security at some of the biggest names in fintech, including Wealthsimple and Robinhood, and now heads security at Dominion Dynamics. Over ten years he's broken into websites, APIs, safes, locks, cars, drones, and smart buildings, and he trains the next wave of hackers on advisory boards at George Brown and the University of Guelph.

He also co-wrote the books the industry trains on.

Black Hat GraphQL (No Starch Press)Black Hat Bash (No Starch Press)The Drone Hacker's Handbook (No Starch Press)
Founder of DEF CON Toronto, with more than 3,000 members.

The ask

Your exposure window is ticking.

00:00Open since you arrived

Tell us what you're building and what you're worried about. You'll hear from an operator, not a sales team, within one business day.

Call us

1-877-411-1337

Business hours, Eastern Time

Email us

contact@asec.io

security@asec.io for disclosure

Find us

18 King Street East, Suite 1400
Toronto, Ontario
M5C 1C4

Canada