Area 08 · Security

Cybersecurity

Company security is settled on two fronts that have to agree with each other. The first is written down: policies, registers and answers to the questionnaires your large customers, your insurer and, where it applies, the data protection authority will send you. The second is technical: whatever genuinely stops a booby-trapped email, a ransomware crew or the quiet export of your client list. A document with nothing behind it protects nobody, and protection that was never described cannot be demonstrated on the day of an inspection. We take on both, entirely remotely.

15
services grouped here
NIS2
and how French law brings it in
100 %
of the work carried out remotely
ISO 27001
the principles we work along

Regulation and requirements

The trigger nearly always comes from outside: a security questionnaire from a major client, the renewal of cyber cover, a request from a public buyer, or the question of whether NIS2 reaches you directly or through the back door, as a supplier to an entity that is in scope. We work along ISO 27001 principles and the guidance published by ANSSI.

Take stock

Technical safeguards

Tools are chosen from the risk assessment, not from a vendor catalogue. Protection that is heavier than the risk slows people down, and they end up inventing ways round it; so we take first whatever measurably lowers the risk.

Security tooling deployment

An inventory of what your subscriptions already cover, then a pilot on a handful of machines, then a roll-out carried through to the end. The tool has to protect, not merely appear on an annual invoice.

Infrastructure security

Firewall rules, a network cut into zones, protected remote access instead of a remote desktop published on the internet, and logs gathered in one place.

Application security

Roles in the ERP and the CRM, a dedicated account for every automated link, API keys taken out of configuration files, and dependencies checked before each release.

Data leak prevention (DLP)

Information classification, encrypted laptops and rules in Microsoft Purview that hold back a file of personnel records before it leaves the company.

Database security

Permissions set in the engine itself, a record of who reads which tables, and anonymised datasets for developers instead of a production copy on a laptop.

Web application firewall (WAF)

A filter in front of your shop or client portal that screens out injection attempts, password guessing against the admin area and bots copying your prices.

Access control and endpoint security

A second factor on every account, conditional access in Entra ID, machines looked after through Intune, and rights cut back to what each person truly uses.

VPN and encryption

Encrypted links between your premises and for people on the move, disk encryption on laptops, and a protected way of sending the documents that warrant it.

Vulnerability scanning

Regular examination of your servers, your network and your websites, followed by a ranked list: what gets fixed today, what waits for the next maintenance window.

Monitoring and upkeep

A configuration set once and left alone ages within months: new people arrive, new software appears, attack techniques move on. These services exist to keep protection moving with them.

Where to start

Buying everything at once usually ends with an overspent budget and consoles nobody opens. For an organisation of 10 to 250 people, this is the order we suggest.

01

Inventory

Which systems and which data you hold, where they live and who holds the keys. Everything else follows from that: which rules apply to you and what deserves the most serious protection.

02

Risk assessment

A list of the threats that are plausible for your trade and your size. This document prevents pointless purchases, and a risk-led approach is exactly what both the GDPR and NIS2 build on.

03

The baseline

Policies, a second factor everywhere, patching that happens, endpoint protection and backups whose restore has been tested. That baseline already answers most customer questionnaires and turns away the common attacks.

04

Targeted tools and watchfulness

We add whatever the risk assessment pointed at, segmentation, application filtering, leak prevention, and then connect monitoring so that an attack is seen arriving rather than discovered afterwards.

A fine is almost never the most expensive part of an incident. Losing a client file costs trust first and sometimes a contract, and ransomware paired with a backup nobody had ever restored can stop a company for weeks. So we begin with whatever limits the damage, not with whatever looks best in a report.

Questions and answers

That depends on your sector, your size and detailed criteria set by the directive and by the national law bringing it in, with exceptions along the way. Many smaller organisations feel the text indirectly, when a customer in scope starts asking about the security of its supply chain. We prepare the technical part of those answers; whether the text reaches you directly is settled with your legal counsel.

Yes. Size excuses nothing once you handle data about employees, patients or clients. A small organisation simply has fewer systems to go through. The seventy-two hour deadline for notifying a breach applies to a five-person practice exactly as it does to a chain of shops.

They are enough to complete a questionnaire, not to stop an attack. A document shields you from the accusation of having no procedure; it does not shield your data. In every recommendation we separate clearly what satisfies a formal requirement from what lowers the risk. Choosing between the two, and at what pace, is yours.

Seldom at the outset. A company with fifteen or so machines already gets a lot from an EDR driven through one console, with well-tuned alerts and somebody reading them. Wider monitoring earns its place when an hour of downtime is expensive, when a contract sets a response time, or when the data you hold is unusually sensitive.

The duration follows the size of the environment and the scope agreed; the timetable is fixed after the opening review and written into the agreement. No visit is needed: conversations happen over video and configuration goes through secure remote access. Where something physical is unavoidable, your team or your installer does it from our instructions.

Measure the gap between where you are and what is expected

Tell us what data you handle and what protection is already running. After a remote review we show you where you stand against what your clients and the regulations expect.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.