Support sized to fit your organisation
We refuse any one-size-fits-all approach. After an initial diagnostic, the programme is built in tiers that can be activated one at a time, each quoted individually, with no commitment to the next.
The essentials, right-sized
A micro-business doesn't need a 24/7 SOC or ISO 27001 certification: it needs the few measures that really matter to be in place, without tying up its owner for weeks.
The 5 essential measures
MFA, tested backups, updates, managed antivirus/EDR, accounts and permissions under control.
Anti wire-transfer fraud
Double-checking of bank details and urgent requests, securing online banking.
Short awareness session
2 hours with the whole team, on your own tools. Annual refresher with a phishing test.
The right level of compliance
Simplified GDPR register, charter, responses to cyber questionnaires from your clients and insurers.
The "what if it happens" plan
One page: who to call, what to unplug, how to restore, what to report.
Providers and cloud
Review of access rights and contracts: hosting provider, business software, accountant, managed service provider.
Three ways to work together
Resilient, compliant and sovereign
Every local authority is unique in its size, resources, maturity level and exposure. A proportionate, modular scheme, deployable in stages, over several budget years if necessary.
Information system audit and security
AD, Microsoft 365, firewall, EDR, network, backups, applications; then remediation.
Organisational audit
Processes, roles, regulatory obligations, maturity level, prioritised plan.
Awareness and training
Elected officials, chief executives, staff, IT directors, DPOs; simulated phishing campaigns; technician training.
Information security governance and compliance
ISSP, charter, risk analysis, security committee, GDPR, NIS 2, LPM, RGS.
Cyber crisis management
BCP/DRP, response plan, tabletop exercises, escalation to ANSSI, CNIL, Préfecture.
Supervision and MCS
SOC/EDR (Wazuh), logging, vulnerabilities, ongoing hardening, monthly reporting.
Three ways to work together
Structure, govern, supervise
An SME with 60 staff and a multi-site group don't have the same obligations or the same resources. After an initial diagnostic, we scale the set-up to your size, your exposure and your obligations.
Information system audit and security
AD, M365, firewall, EDR, network, backups, business applications, web scan, penetration test.
Organisational audit and risks
Mapping, dependencies, EBIOS RM, prioritised improvement plan.
Awareness and training
Executive committee, accounting, business units, IT; wire-transfer fraud; simulated phishing.
Information security governance and compliance
ISSP, charter, security committee, GDPR, NIS 2, DORA, ISO 27001.
Crisis management and incident response
BCP/DRP, tabletop exercises; contain, restore, forensics, declarations.
Supervision and MCS
SOC/EDR (Wazuh), dark web monitoring, vulnerabilities, secure managed services, monthly reporting.
