Our services
Practical services, suited to the size of your organisation and the constraints of island territories: limited connectivity, small teams, distant service providers.
Consulting and governance
- Outsourced or shared-time CISO
- Drafting and implementation of the ISSP
- ISO/IEC 27005 and EBIOS RM risk analysis
- NIS 2, DORA, LPM compliance, accreditation
Security audit and testing
- Infrastructure audit: firewalls, servers, network, Wi-Fi
- Active Directory and Microsoft 365 audit
- Organisational and compliance audit
- Penetration tests, web vulnerability scans
Information system hardening
- Active Directory (tiering, GPO) and Microsoft 365 hardening
- Immutable, offline backups, tested restores, DRP
- Firewalls, network segmentation, MFA, PKI
- Remediation after an audit or incident
Security monitoring — managed SOC
- Endpoint detection and response on workstations and servers (EDR)
- Log collection and correlation (Wazuh SIEM)
- Vulnerability management, threat watch and 7-day alerting
- Monthly reporting and review with management
Secure managed IT services
- Administration and operational maintenance
- Managed updates, backups and antivirus/EDR
- User support and secure remote maintenance
- Monthly plan, a single contact who knows your IS
"Security by Design" virtualised infrastructure
- Design and deployment of VMware vSphere, Windows Server, Active Directory
- Backup and replication (Veeam, Zerto), built-in DRP
- FortiGate firewalls, PKI, segmentation from the design stage
- Migration and modernisation of existing infrastructure
Training and awareness
- Awareness training for all audiences, on-site or remote
- IT training: AD, Windows Server, vSphere, Veeam
- Simulated phishing campaigns
- Tailored pathways for your teams
Cyber crisis management
- Incident response after a cyberattack
- Forensic analysis and remediation
- Secure rebuild of the information system
- Crisis exercises for your leadership team
- Incident response factsheets and reflex memo (PDF)
1-day flash diagnostic
A diagnostic designed by TAVITA CYBERSECURITY, on-site or remote: we assess your security level across 10 key points (email, accounts, backups, workstations, network, website…) and hand you a prioritised, costed action plan, presented to management. Independent of the Bpifrance Diag Cybersécurité.
ISSP consulting and governance
Structuring cybersecurity, defining policies, NIS 2, LPM, GDPR and DORA compliance. Recurring shared-time information security management, advice to management and elected officials, liaison with ANSSI, the CNIL, your insurers and your providers.
- Outsourced CISO / IT Director, from a few hours a month to several days
- ISSP, IT charter, security committee and dashboard
- ISO/IEC 27005 and EBIOS RM risk analysis
- Cyber master plan, security component of your digital and shared-service projects
- A compliance plan you can rely on with your insurers and clients
Security audit and testing
Assessment of the security level, identification of vulnerabilities, concrete recommendations prioritised by business impact.
- Infrastructure audit: Active Directory, Microsoft 365, firewall, EDR, network and Wi-Fi, backups, business applications
- Organisational audit: processes, roles, dependencies (providers, cloud), maturity level
- ISSP compliance audit (NIS 2, DORA, RGS, LPM) and security accreditation
- Penetration testing and web vulnerability scans
- 1-day flash diagnostic (micro-businesses) or 8-day Bpifrance Diag Cybersécurité, 50% subsidised (SMEs, mid-caps)
Information system hardening
Raising the overall level of protection of your infrastructure and putting in place concrete corrective measures, prioritised by risk.
- Active Directory hardening: T0/T1/T2 tiering, GPO, PingCastle; Microsoft 365 hardening (MFA, conditional access, mailbox rules)
- Immutable, isolated and offline backups, tested restoration, a written DRP known to the teams
- Firewalls and network segmentation, VPN, Microsoft PKI, privileged account management
- Remediation after an audit or an incident, with verification of fixes
Security monitoring — managed SOC
Detect early and react fast: continuous monitoring of your workstations, servers and cloud services, sized for an SME or a local authority, without an unaffordable 24/7 SOC.
- EDR on workstations and servers: detection of malicious behaviour, remote isolation of a compromised machine
- Wazuh SIEM: log collection and correlation (Windows, Linux, firewalls, Microsoft 365), alert rules tailored to your context
- Vulnerability management: regular scans, prioritisation, patch follow-up
- Data-leak and domain-name monitoring, 7-day alerting with an agreed on-call arrangement
- Management-friendly monthly reporting, quarterly KPI review, insurer-ready documentation
- In the French Antilles and Guiana, monitoring is operated with the local SOC of our partner KOSEICO
Secure managed IT services
We take over the day-to-day operation of your IT with security built in from the start, for organisations that have no IT department or want to strengthen it.
- Administration of servers, workstations, network, Microsoft 365 and email; operational and security maintenance
- Scheduled updates, managed antivirus/EDR, verified backups and tested restores
- Account and rights management: joiners, leavers, MFA, periodic access reviews
- User support and secure remote maintenance; on-site intervention in Martinique and Tahiti when needed
- Monthly plan based on the number of workstations and servers, up-to-date inventory and documentation, a single point of contact
"Security by Design" virtualised infrastructure
Designing and deploying infrastructure whose security is built into the architecture rather than bolted on afterwards: this is TAVITA CYBERSECURITY's core business, with several complete infrastructures delivered in French Polynesia and Martinique.
- Architecture and deployment of VMware vSphere, Windows Server, Active Directory (tiering, GPO, PKI) and infrastructure services
- Veeam / Zerto backup and replication, built-in and tested disaster recovery plan
- FortiGate firewalls, network segmentation, secure remote access, monitoring-ready logging
- Migration or modernisation of an existing environment (domain rename, consolidation, version upgrade) without prolonged downtime
- Operations documentation and skills transfer to your teams or your managed service provider
Cyber crisis management
Compromised privileged account, diverted wire transfer, encrypted servers: contain, restore, analyse, report, and strengthen so it doesn't happen again.
- Incident response, remediation, forensic analysis
- Secure rebuild of the information system
- BCP/DRP, incident response plan, tabletop exercises with management
- Escalation to the authorities: ANSSI, CNIL, Prefecture, national police
- Three engagements with local authorities →
A complete 8-day diagnostic, 50% funded by Bpifrance
The Diag Cybersécurité is a Bpifrance scheme for SMEs and mid-caps. An accredited expert assesses your organisation and systems, carries out technical testing and provides you with a prioritised action plan. TAVITA CYBERSECURITY is an approved provider for the scheme, in French Polynesia, in Martinique and remotely.
The 4 stages of the Diag Cybersécurité
Flash diagnostic or Diag Cybersécurité: which one to choose?
| Flash diagnostic TAVITA CYBERSECURITY | Diag Cybersécurité Bpifrance · France 2030 | |
|---|---|---|
| Who it's for | Micro-businesses, tradespeople, self-employed professionals, small local authorities, associations | SMEs and mid-caps eligible for Bpifrance support |
| Duration | 1 day, on-site or remote | 8 expert-days, spread over 3 to 6 months |
| Content | Overview: email, accounts, backups, workstations, network, website | Full organisational and technical diagnostic, security testing, team awareness training |
| Deliverable | Debrief with the business leader, 10-point prioritised action plan with costings | Diagnostic report, prioritised action plan, crisis management recommendations |
| Price | 700 € excl. VAT, 1-day flat fee, no subsidy | 8 800 € excl. VAT, of which 50% is covered by Bpifrance — remaining cost 4 400 € excl. VAT |
| Start-up time | Within a few days | Once the application is approved by Bpifrance |
| Request a flash diagnostic | Check my eligibility |
Amounts and terms as indicated by Bpifrance at the time of publication; they may change. We support you throughout the application process with Bpifrance.
A local ecosystem serving the digital sovereignty of the French overseas territories
TAVITA CYBERSECURITY works alongside two partners based in the French West Indies, in Martinique and Guadeloupe: each focuses on its core business, you keep a single point of contact, and both your data and cyber skills stay in the territory.

Who are they?
- Company based in Martinique, operating in Martinique, Guadeloupe and French Guiana
- Network and security audits
- Firewall and equipment integration: Palo Alto Networks, Fortinet, Forescout, Aruba, Ubiquiti
- Managed services and incident response
How we complement each other
- KARIGUARD: network engineering, equipment integration, managed operations
- TAVITA CYBERSECURITY: architecture, audit, governance (outsourced CISO), training
- Joint projects in Martinique, from diagnosis to implementation

Who are they?
- Company based in Guadeloupe, serving public and private organisations across the French West Indies and French Guiana
- Consulting, audits and integration of cybersecurity solutions
- Local security operations centre (SOC), data analysed and hosted in the European Union (GDPR)
- Listed by Cybermalveillance.gouv.fr, ExpertCyber label, ISO 27001 Lead Implementer certified, France 2030 laureate (AUTOSOC)
How we complement each other
- KOSEICO: SOC for the French West Indies and Guiana — log collection and centralisation, incident detection and analysis by analysts, remediation and escalation
- TAVITA CYBERSECURITY: design of the set-up, onboarding of your equipment, service management with you (indicators, reviews, governance)
