Incident response, 7 days a weekPapeete · Fort-de-France · ParisFREN
TAVITA CYBERSECURITYCyber guardian of the territories
Home › Offers

Support sized to fit your organisation

We refuse any one-size-fits-all approach. After an initial diagnostic, the programme is built in tiers that can be activated one at a time, each quoted individually, with no commitment to the next.

Micro-businesses · Tradespeople · Independent professionals

The essentials, right-sized

A micro-business doesn't need a 24/7 SOC or ISO 27001 certification: it needs the few measures that really matter to be in place, without tying up its owner for weeks.

Tiers, at your own pace
1Flash diagnostic — 1 day, on-site or remote: email, accounts, backups, workstations, router and Wi-Fi, website. A prioritised, costed 10-point action plan.
2Security baseline — 2 to 5 days: MFA everywhere, tested 3-2-1 backup, managed antivirus/EDR, Microsoft 365 or Google Workspace hardening, firewall and Wi-Fi, anti-fraud procedure for bank transfers, IT charter.
3Peace-of-mind follow-up — Light monthly or quarterly package: EDR and alert supervision, updates, backup checks, annual phishing exercise, file for your insurer, direct line in the event of an incident.
Download the factsheet (PDF)

The 5 essential measures

MFA, tested backups, updates, managed antivirus/EDR, accounts and permissions under control.

Anti wire-transfer fraud

Double-checking of bank details and urgent requests, securing online banking.

Short awareness session

2 hours with the whole team, on your own tools. Annual refresher with a phishing test.

The right level of compliance

Simplified GDPR register, charter, responses to cyber questionnaires from your clients and insurers.

The "what if it happens" plan

One page: who to call, what to unplug, how to restore, what to report.

Providers and cloud

Review of access rights and contracts: hosting provider, business software, accountant, managed service provider.

Three ways to work together

One-off interventionFlash diagnostic then security baseline, by the day, with a clear deliverable at each stage.
Follow-up packageA few hours a month or a quarter, with a single point of contact who knows your business.
Incident responseHacked account, diverted wire transfer, encrypted workstation: contain, restore, report, strengthen.
Local authorities

Resilient, compliant and sovereign

Every local authority is unique in its size, resources, maturity level and exposure. A proportionate, modular scheme, deployable in stages, over several budget years if necessary.

Tiers, at your own pace
1Initiation — Raise awareness among elected officials and management, lay the foundations of information security governance, secure the fundamentals (backups, MFA, segmentation), start on compliance.
2Consolidation — Formalise governance (CISO, security committee), professionalise risk management, build crisis plans, prepare for NIS 2 and LPM audits.
3Building maturity — Advanced frameworks (ISO 27001, ANSSI), continuous supervision (SOC, EDR, SIEM), third-party risks, high-level crisis exercises.
Download the factsheet (PDF)

Information system audit and security

AD, Microsoft 365, firewall, EDR, network, backups, applications; then remediation.

Organisational audit

Processes, roles, regulatory obligations, maturity level, prioritised plan.

Awareness and training

Elected officials, chief executives, staff, IT directors, DPOs; simulated phishing campaigns; technician training.

Information security governance and compliance

ISSP, charter, risk analysis, security committee, GDPR, NIS 2, LPM, RGS.

Cyber crisis management

BCP/DRP, response plan, tabletop exercises, escalation to ANSSI, CNIL, Préfecture.

Supervision and MCS

SOC/EDR (Wazuh), logging, vulnerabilities, ongoing hardening, monthly reporting.

Three ways to work together

Outsourced CISORecurring shared-time information security management, advice to management and elected officials, liaison with ANSSI and the CNIL.
One-off strategic consultingCyber master plan, bringing into compliance, security component of your digital and shared-service projects.
Targeted operational interventionAudit, remediation, awareness training or incident response, on-site and via secure remote maintenance.
SMEs · Mid-caps · Groups

Structure, govern, supervise

An SME with 60 staff and a multi-site group don't have the same obligations or the same resources. After an initial diagnostic, we scale the set-up to your size, your exposure and your obligations.

Tiers, at your own pace
1SMEs — structure — Technical and organisational audit, remediation of critical points, awareness, ISSP and charter, BCP/DRP, GDPR compliance and insurer file; shared-time CISO for a few days a month.
2Mid-caps — govern — EBIOS RM risk analysis, NIS 2, ISO 27001, DORA compliance, security committee and dashboard, SOC/EDR/SIEM, penetration testing, third-party risk management, crisis exercises with management.
3Group — industrialise — Group cyber master plan, shared policies rolled out by site, ISO 27001 ISMS, centralised supervision, audits of subsidiaries and providers, cross-site crisis exercises, reporting to the executive committee.
Download the factsheet (PDF)

Information system audit and security

AD, M365, firewall, EDR, network, backups, business applications, web scan, penetration test.

Organisational audit and risks

Mapping, dependencies, EBIOS RM, prioritised improvement plan.

Awareness and training

Executive committee, accounting, business units, IT; wire-transfer fraud; simulated phishing.

Information security governance and compliance

ISSP, charter, security committee, GDPR, NIS 2, DORA, ISO 27001.

Crisis management and incident response

BCP/DRP, tabletop exercises; contain, restore, forensics, declarations.

Supervision and MCS

SOC/EDR (Wazuh), dark web monitoring, vulnerabilities, secure managed services, monthly reporting.

Three ways to work together

Outsourced CISO / IT DirectorShared-time IT and information security management, advice to management, liaison with providers, insurers and authorities.
One-off consulting and interventionFlash diagnostic, audit, penetration test, remediation, awareness training, roadmap, by the day.
Incident responseCompromised privileged account, diverted wire transfer, encrypted servers: contain, restore, analyse, report, strengthen.