About IONSEC
A boutique house of responders and researchers.
We are a team of cybersecurity experts specializing in combating sophisticated cyberattacks and threat actors — 24/7 incident response, advanced threat research, and security work tailored to each organization we serve.
24/7
On-call incident response, every day of the year.
+100k
Hours in research and DFIR expertise.
IT · OT · IoT
Converged environments, not just the corporate estate.
6
Open-source DFIR tools published and maintained.
Small on purpose.
Boutique is a deliberate choice, not a stage we are trying to grow out of. The people who publish our APT research are the people who take your escalations, and the people who take your escalations are the ones on the call at 3am. There is no bench between you and the analyst.
That is also why we say no. If a preparedness engagement is what you need and a retainer is not, we will tell you — an honest baseline is worth more to both of us than a contract you resent in six months.
How we work
Professionalism, ingenuity and integrity — and what each one costs us.
Professionalism
Unmatched expertise with a commitment to excellence in every engagement.
In practice: named senior analysts on your retainer, and reporting your board, insurer and regulator can all read.
Ingenuity
We innovate continuously, staying ahead of emerging threats with creative solutions.
In practice: six open-source tools built because the commercial ones did not cover the case in front of us.
Integrity
Complete transparency and accountability, building lasting trust.
In practice: we prioritise gaps by what they would cost you in an incident, not by what is easiest for us to sell.





Leadership
Who you will actually be talking to.

Founder & CEO
Nir Halfon
Leads IONSEC's research and response practice. Presented at HackExpo 2024 on responding to exploits in fintech first-party applications under live pressure, and represents IONSEC in the INCD MIRROR Forum.
LinkedIn profile for Nir Halfon (opens in a new tab)
COO
Moran Halfon
Runs engagement delivery and the on-call rota that backs the four-hour response commitment — scoping, scheduling and keeping the reporting readable for boards, insurers and regulators.
LinkedIn profile for Moran Halfon (opens in a new tab)Standing
Where we sit in the ecosystem.
We work alongside national cyber bodies, defence and critical infrastructure — and we share what we find rather than hoarding it.
2024
MIRROR Forum with INCD
One of 15 Israeli incident response companies convened by the Israel National Cyber Directorate for its third MIRROR Forum.
2024
Czech delegation briefing
Hosted a Czech delegation in Israel to present our wiper malware research, including the campaign we track as Operation HANDALA.
2025
GISEC Global, Israeli Pavilion
Showed an exclusive preview of our next-generation DFIR platform at one of the world’s premier cybersecurity events.
Ongoing
Defence, energy and infrastructure
We work with national bodies, utilities, finance and critical infrastructure operators — the environments where downtime is not an inconvenience.


Whether protecting your systems or preparing your teams.
Our mission is clear: to conquer the cyber world together, delivering unmatched service and lasting impact.