Service · Cybersecurity

Security policies and documentation

A downloaded policy template reads well until the auditor asks the first question: who approved it, when was it last reviewed, and how do you know your staff have read it? Documentation written for somebody else comes unstuck from reality within a fortnight. We build yours from conversations with your own people and from what we can see in your systems, so that it holds up in front of a public buyer, in front of a demanding client, and above all on an ordinary working day.

Tailored
a set sized for your organisation
Timetable
agreed in the first workshop
ISO 27001
used as the reference frame
Annual review
written into the documents

Where this service reaches

The contents follow the purpose: NIS2 as brought into French law, the demands of a large customer, DORA where a client sits in financial services, or simply the wish to have clear rules in a commune or an EPCI.

Put your scope to an engineer

Information security policy

The top-level document, approved by the leadership or by the elected sponsor: what is protected, against what, and who answers for it. Management should be able to defend that policy, not merely sign it.

Risk assessment

A readable table of threats and consequences, from which the necessary measures follow along with the ones you deliberately leave out, each with the written reasoning beside it.

Access governance

Rules for granting, changing and removing access, wired into the joiner and leaver process that HR already runs rather than into one person's memory.

Detailed procedures

Remote work aligned with your charter and the labour code, passwords and strong authentication, personal devices, backups, supplier oversight, and incident handling including the reporting path to CERT-FR.

Instructions for staff

One or two pages in plain language. Nobody reads thirty pages about passwords; two pages with real examples stick.

Registers and evidence

Templates for the incident register, the access review and training acknowledgements. Auditors ask for these far more often than for the policy itself.

The way an engagement runs

One test decides everything: the procedure has to be workable. A rule that contradicts the way people work will be bypassed in the first week.

01

Interviews

Video calls with the leadership, the IT contact and HR about how a new starter is set up, how access is granted, how suppliers are handled and what happens when something fails.

02

Drafting

We write the text and go through every phrase with you, so that no rule turns out to be impossible under your own conditions.

03

Roll-out

Management approves, staff sit a short online session, and the acknowledgements are filed with their date and document version.

04

Keeping it alive

The annual review goes into the calendar, and the documents are revisited whenever a system or the organisation changes noticeably.

NIS2 puts cybersecurity squarely on the leadership. In the entities it covers, directors are expected to understand the risk management measures they approve and to be trained on the subject. A policy nobody at the top has read then stops being a weak document and becomes a governance problem. Every engagement therefore ends with a short session for the leadership or the elected members.

Questions and answers

Usually yes, as a starting point. We check what still matches reality and what describes a server scrapped long ago, then fill the familiar gaps: supplier oversight, incident handling, business continuity. Starting from a blank page is rarely necessary.

No, and nobody honestly can promise that: certification is issued by an accredited body after an audit. We write along ISO 27001 principles, which gives you a solid base if you later decide to go for the audit, and we can help you prepare for it.

Yes. Local authorities work with tight budgets, staff who wear several hats, and obligations coming at once from the GDPR, from ANSSI guidance and from the online services offered to residents. We write short documents a small team can actually apply, and we take on the technical part of the file when a support programme calls for it.

No. Each person confirms they have read the instructions that concern them, ideally electronically, with a date and a version number. The full policies are read by those who apply them: management, IT and HR.

Documentation that survives an audit

Tell us what it has to achieve: NIS2, a public tender, a customer request or simply your own need for clarity. We will propose a contents list and a timetable.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.