Incident response, 7 days a weekPapeete · Fort-de-France · ParisFREN
TAVITA CYBERSECURITYCyber guardian of the territories

Cyber guardian of the overseas territories

Audit, hardening, outsourced CISO, training and crisis management for businesses, local authorities and associations in French Polynesia and Martinique — with the rigour gained over 23 years at the Ministry of the Armed Forces.

Microsoft Certified Expert PECB ISO/IEC 27001 Lead Auditor PECB ISO/IEC 27001 Implementer PECB ISO/IEC 27005 Risk Manager
David Touche, founder of TAVITA CYBERSECURITY
David TOUCHEFounder of TAVITA CYBERSECURITY
  • Cybersecurity consultant and trainer
  • Engineer, Network and Security Systems Architect
  • 28 years in IT, including 17 in cybersecurity
  • Certified ISO/IEC 27001 Lead Auditor & Implementer, ISO/IEC 27005 Risk Manager
  • Bpifrance Diag Cybersécurité provider
65Projects carried out since 2021: security audits, information system security, "Security by Design" virtualised infrastructure, GRC advisory.
11Post-cyberattack interventions (micro-businesses, SMEs, mid-caps, groups, local authorities).
234People trained or made aware, French Polynesia and Martinique.
6Local authorities supported, including 2 outsourced CISO contracts.
Why now

The overseas territories are not spared, and compliance is no longer optional

Collectivité Territoriale de Martinique (2023), Le Robert (2023), Collectivité Territoriale de Guadeloupe (2022), Mahina in French Polynesia (2024), Conseil départemental de La Réunion (2024): all victims of ransomware. The 2025 reports from ANSSI, the CNIL and Cybermalveillance.gouv.fr confirm the trend.

+73 %of assistance requests from businesses and associations to 17Cyber in 2025Cybermalveillance.gouv.fr, 2025 report
48 %of ransomware victims reported to ANSSI in 2025 are micro-businesses, SMEs and mid-capsANSSI, 2025 Cyber Threat Overview
+93 %of transfer fraud targeting businesses in 2025: fake bank details, fake supplier, fake CEOCybermalveillance.gouv.fr, 2025 report
5 078local authorities and public administrations assisted by 17Cyber in 2025, +22% in a yearCybermalveillance.gouv.fr, 2025 report
GDPRSecurity measures (art. 32), notification to the CNIL within 72 hours. €486.8m in fines in 2025.
NIS 2From 50 employees or €10M revenue across 18 sectors; incidents must be reported within 24 hours, executives held accountable.
LPM · CGCTCritical services and continuity of public service: BCP/DRP and crisis management are essential.
DORA · CRAFinancial-sector resilience and connected-product security, reflected in your contracts.
RGS · SecNumCloudGeneral security framework for public administrations and online public services; ANSSI qualification for trusted cloud hosting providers.
LOPMIFiling a police report within 72 hours of a cyberattack, a condition for cyber insurance compensation.
HDSCertified hosting mandatory for any personal health data (healthcare facilities, social care, e-health).
AI Regulation (AI Act)Transparency and risk-management obligations for AI uses, applicable on a phased basis since 2025.
Our services

Our services: securing, operating and monitoring your information system

Get a quote within 48 hours

Consulting and governance

  • Outsourced or shared-time CISO
  • Drafting and implementation of the ISSP
  • ISO/IEC 27005 and EBIOS RM risk analysis
  • NIS 2, DORA, LPM compliance, accreditation
Learn more

Security audit and testing

  • Infrastructure audit: firewalls, servers, network, Wi-Fi
  • Active Directory and Microsoft 365 audit
  • Organisational and compliance audit
  • Penetration tests, web vulnerability scans
Learn more

Information system hardening

  • Active Directory (tiering, GPO) and Microsoft 365 hardening
  • Immutable, offline backups, tested restores, DRP
  • Firewalls, network segmentation, MFA, PKI
  • Remediation after an audit or incident
Learn more

Security monitoring — managed SOC

  • Endpoint detection and response on workstations and servers (EDR)
  • Log collection and correlation (Wazuh SIEM)
  • Vulnerability management, threat watch and 7-day alerting
  • Monthly reporting and review with management
Learn more

Secure managed IT services

  • Administration and operational maintenance
  • Managed updates, backups and antivirus/EDR
  • User support and secure remote maintenance
  • Monthly plan, a single contact who knows your IS
Learn more

"Security by Design" virtualised infrastructure

  • Design and deployment of VMware vSphere, Windows Server, Active Directory
  • Backup and replication (Veeam, Zerto), built-in DRP
  • FortiGate firewalls, PKI, segmentation from the design stage
  • Migration and modernisation of existing infrastructure
Learn more

Training and awareness

  • Awareness training for all audiences, on-site or remote
  • IT training: AD, Windows Server, vSphere, Veeam
  • Simulated phishing campaigns
  • Tailored pathways for your teams
See our courses

Cyber crisis management

I'm under attack
TAVITA CYBERSECURITY entry-level package

1-day flash diagnostic

A diagnostic designed by TAVITA CYBERSECURITY, on-site or remote: we assess your security level across 10 key points (email, accounts, backups, workstations, network, website…) and hand you a prioritised, costed action plan, presented to management. Independent of the Bpifrance Diag Cybersécurité.

700 €excl. VAT · 1-day flat fee
Request the flash diagnostic
Incident response and security hardening

When the attack is under way, we respond the same day. Local authorities share their experience.

D+0ContainSupport from the first call, isolation of compromised access, halting the ongoing attack.
D+0 → D+2SecureNetwork, accounts, Microsoft 365 tenant, backups: the attacker's access is shut down.
D+1 → D+5InvestigateDiagnostic and report tracing the actions, findings and recommendations taken.
In parallelReport and cooperateComplaint filed within 72 hours, CNIL, insurer; cooperation with the national police (DTPN).
ThenStrengthenCorrective measures, hardening, staff awareness training to prevent recurrence.
Incident response
Local authority — French PolynesiaFebruary 2024 incident · Tahiti

“Called in as soon as the facts came to light, TAVITA CYBERSECURITY responded very quickly to stop the attack. It secured our network, including our Microsoft 365 tenant, carried out an initial investigation and diagnostic recorded in a report, and worked closely with the national police's cybercrime investigation services.”

Chief Administrative Officer
Incident response
Municipality — MartiniqueAugust 2025 incident

“TAVITA CYBERSECURITY responded very quickly to stop the attack our municipality was facing. It carried out the intervention effectively, securing the network and then implementing the necessary corrective measures, and ran a cybersecurity awareness session for our staff.”

The Mayor
Security hardening
Municipality — French PolynesiaSupport and strengthening of IT security

“TAVITA CYBERSECURITY brought us its expertise in consulting, auditing, technical support and recommendations, with professionalism, availability and rigour. This support strengthened our infrastructure's security and improved our practices. We recommend TAVITA CYBERSECURITY for its expertise and thoroughness.”

The Mayor
Bpifrance Diag Cybersécurité — Protecting your business to secure its long-term future
Diag Cybersécurité · Bpifrance · France 2030

A complete 8-day diagnostic, 50% funded by Bpifrance

The Diag Cybersécurité is a Bpifrance scheme for SMEs and mid-caps. An accredited expert assesses your organisation and systems, carries out technical testing and provides you with a prioritised action plan. TAVITA CYBERSECURITY is an approved provider for the scheme, in French Polynesia, in Martinique and remotely.

8 daysof support from an authorised expert, over 3 to 6 months depending on the agreed schedule
50 %funded by Bpifrance (France 2030), i.e. €4,400
4 400 € HTremaining cost to the business, out of a total cost of €8,800 excl. VAT (one site visited)

The 4 stages of the Diag Cybersécurité

1
Phone pre-briefingInterview between the expert, the business leader and the head of information systems to define the scope and timeline.
2
Organisational diagnosticTeam awareness training, infrastructure assessment and interviews to measure cyber maturity.
3
Technical diagnosticIn-depth technical tests to identify the security flaws in your information system.
4
DebriefDelivery of a prioritised action plan and tailored recommendations, including for crisis management.

Flash diagnostic or Diag Cybersécurité: which one to choose?

Flash diagnostic TAVITA CYBERSECURITYDiag Cybersécurité Bpifrance · France 2030
Who it's forMicro-businesses, tradespeople, self-employed professionals, small local authorities, associationsSMEs and mid-caps eligible for Bpifrance support
Duration1 day, on-site or remote8 expert-days, spread over 3 to 6 months
ContentOverview: email, accounts, backups, workstations, network, websiteFull organisational and technical diagnostic, security testing, team awareness training
DeliverableDebrief with the business leader, 10-point prioritised action plan with costingsDiagnostic report, prioritised action plan, crisis management recommendations
Price700 € excl. VAT, 1-day flat fee, no subsidy8 800 € excl. VAT, of which 50% is covered by Bpifrance — remaining cost 4 400 € excl. VAT
Start-up timeWithin a few daysOnce the application is approved by Bpifrance
Request a flash diagnosticCheck my eligibility

Amounts and terms as indicated by Bpifrance at the time of publication; they may change. We support you throughout the application process with Bpifrance.

Support sized to fit your organisation

Three offers, three realities: Micro-businesses, Local authorities, SMEs-Mid-caps-Groups

We refuse any one-size-fits-all approach. After an initial diagnostic, the programme is built in tiers that can be activated one at a time, each quoted individually, with no commitment to the next.

Micro-businesses · Tradespeople · Independent professionals

The essentials, right-sized

The few measures that really matter, put in place without tying up the business owner for weeks.

1Flash diagnostic — 1 day
2Security baseline — 2 to 5 days
3Peace-of-mind follow-up — light package
See the Micro-businesses offer
Local authorities

Resilient, compliant and sovereign

From the small municipality to the inter-municipal authority: a proportionate scheme, deployable in stages over several budget years.

1Initiation
2Consolidation
3Building maturity
See the Local authorities offer
SMEs · Mid-caps · Groups

Structure, govern, supervise

An SME with 60 staff and a multi-site group don't have the same obligations or the same resources: the set-up follows your exposure.

1SMEs — structure
2Mid-caps — govern
3Group — industrialise
See the SMEs-Mid-caps offer
Our method

A hands-on approach, built for the islands

Digital sovereignty, local presence and responsiveness. No 200-page report gathering dust in a drawer: every engagement ends with a prioritised action plan your teams can put to use immediately. David Touche is personally involved in every engagement, on-site and remotely.

1
UnderstandInterview with management, mapping of the information system, identification of critical assets and regulatory obligations.
2
MeasureTechnical and organisational audit, risk analysis, maturity rating and prioritisation by business impact.
3
SecureHardening, tested offline backups, MFA, supervision: the measures that actually stop the attacks we see in the field.
4
SustainTeam awareness, a written DRP known to everyone, crisis exercises, shared-time CISO follow-up.
They trusted us

Hospitality, local authorities, healthcare, automotive, hosting providers

"I want to commend the flexibility and professionalism of TAVITA CYBERSECURITY. They provided a concrete solution to a major need, where no other local player had been able to. A reliable and responsive partner."

Moana LI FUNG KUEE — IS Manager, Solari Mobility Group
See all our references and testimonials →
Our partners in the French Antilles and Guiana

A local ecosystem serving the digital sovereignty of the French overseas territories

TAVITA CYBERSECURITY works alongside two partners based in the French West Indies, in Martinique and Guadeloupe: each focuses on its core business, you keep a single point of contact, and both your data and cyber skills stay in the territory.

KARIGUARDNetwork and cybersecurity integration — Martinique

Who are they?

  • Company based in Martinique, operating in Martinique, Guadeloupe and French Guiana
  • Network and security audits
  • Firewall and equipment integration: Palo Alto Networks, Fortinet, Forescout, Aruba, Ubiquiti
  • Managed services and incident response

How we complement each other

  • KARIGUARD: network engineering, equipment integration, managed operations
  • TAVITA CYBERSECURITY: architecture, audit, governance (outsourced CISO), training
  • Joint projects in Martinique, from diagnosis to implementation
Discover KARIGUARD ↗
KOSEICOLocal, sovereign and compliant SOC — Guadeloupe

Who are they?

  • Company based in Guadeloupe, serving public and private organisations across the French West Indies and French Guiana
  • Consulting, audits and integration of cybersecurity solutions
  • Local security operations centre (SOC), data analysed and hosted in the European Union (GDPR)
  • Listed by Cybermalveillance.gouv.fr, ExpertCyber label, ISO 27001 Lead Implementer certified, France 2030 laureate (AUTOSOC)

How we complement each other

  • KOSEICO: SOC for the French West Indies and Guiana — log collection and centralisation, incident detection and analysis by analysts, remediation and escalation
  • TAVITA CYBERSECURITY: design of the set-up, onboarding of your equipment, service management with you (indicators, reviews, governance)
Discover KOSEICO ↗
Areas of operation

On the ground, in your time zones

A French Polynesian company founded in Papeete in 2021, now also based in Martinique, and available remotely for mainland France and all the overseas territories.

French PolynesiaHead office in Papeete. Operating across Tahiti, Moorea and the archipelagos.UTC−10
Martinique & the West IndiesAgency in Sainte-Marie, interventions in Guadeloupe and French Guiana.UTC−4
Mainland France & remoteHybrid assignments: outsourced CISO, audits, risk analyses and remote training, with regular trips to Paris and mainland France.UTC+1
Contact

Need a quote, advice, or immediate help?

Response within 48 business hours for quote requests. If you're under attack right now, call us directly: we'll pick up.