Information security policy
The top-level document, approved by the leadership or by the elected sponsor: what is protected, against what, and who answers for it. Management should be able to defend that policy, not merely sign it.
A downloaded policy template reads well until the auditor asks the first question: who approved it, when was it last reviewed, and how do you know your staff have read it? Documentation written for somebody else comes unstuck from reality within a fortnight. We build yours from conversations with your own people and from what we can see in your systems, so that it holds up in front of a public buyer, in front of a demanding client, and above all on an ordinary working day.
The contents follow the purpose: NIS2 as brought into French law, the demands of a large customer, DORA where a client sits in financial services, or simply the wish to have clear rules in a commune or an EPCI.
The top-level document, approved by the leadership or by the elected sponsor: what is protected, against what, and who answers for it. Management should be able to defend that policy, not merely sign it.
A readable table of threats and consequences, from which the necessary measures follow along with the ones you deliberately leave out, each with the written reasoning beside it.
Rules for granting, changing and removing access, wired into the joiner and leaver process that HR already runs rather than into one person's memory.
Remote work aligned with your charter and the labour code, passwords and strong authentication, personal devices, backups, supplier oversight, and incident handling including the reporting path to CERT-FR.
One or two pages in plain language. Nobody reads thirty pages about passwords; two pages with real examples stick.
Templates for the incident register, the access review and training acknowledgements. Auditors ask for these far more often than for the policy itself.
One test decides everything: the procedure has to be workable. A rule that contradicts the way people work will be bypassed in the first week.
Video calls with the leadership, the IT contact and HR about how a new starter is set up, how access is granted, how suppliers are handled and what happens when something fails.
We write the text and go through every phrase with you, so that no rule turns out to be impossible under your own conditions.
Management approves, staff sit a short online session, and the acknowledgements are filed with their date and document version.
The annual review goes into the calendar, and the documents are revisited whenever a system or the organisation changes noticeably.
NIS2 puts cybersecurity squarely on the leadership. In the entities it covers, directors are expected to understand the risk management measures they approve and to be trained on the subject. A policy nobody at the top has read then stops being a weak document and becomes a governance problem. Every engagement therefore ends with a short session for the leadership or the elected members.
Usually yes, as a starting point. We check what still matches reality and what describes a server scrapped long ago, then fill the familiar gaps: supplier oversight, incident handling, business continuity. Starting from a blank page is rarely necessary.
No, and nobody honestly can promise that: certification is issued by an accredited body after an audit. We write along ISO 27001 principles, which gives you a solid base if you later decide to go for the audit, and we can help you prepare for it.
Yes. Local authorities work with tight budgets, staff who wear several hats, and obligations coming at once from the GDPR, from ANSSI guidance and from the online services offered to residents. We write short documents a small team can actually apply, and we take on the technical part of the file when a support programme calls for it.
No. Each person confirms they have read the instructions that concern them, ideally electronically, with a date and a version number. The full policies are read by those who apply them: management, IT and HR.
Tell us what it has to achieve: NIS2, a public tender, a customer request or simply your own need for clarity. We will propose a contents list and a timetable.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.