New: autonomous XDR detection

Offensive security for critical infrastructure

We map your attack surface, test it the way an adversary would, then defend it around the clock from a sovereign SOC operated in Rennes.

Incident response engaged within 30 minutes · PASSI-qualified team · Data hosted in France

Trusted with their attack surface.

Clients include Havrelis, Cindre Health, Orbanne, Valmeyre, Tessane Group, Kordyn, Aubrac Energy, Nolven.

From offensive diagnosis to continuous defence_

From a code review to the endpoint on a desk, we turn every blind spot into a signal you can act on, then into defence you can measure.

Watching since 2016
A collective of 34 analysts
/ PASSI & ISO 27001 qualified
0% SOC availability over 24 months
0+ Offensive engagements delivered
0 min Median time to detect
Method

Turning uncertainty into a posture you control

Step 01

Map

We inventory exposed assets, third-party dependencies and the attack paths that are genuinely walkable. Not a theoretical CVE list.

Step 02

Break

Red team, application testing and configuration review. We break what needs breaking, before an adversary does it without warning.

Step 03

Defend

Continuous detection, response playbooks and hardening run from the SOC, with metrics your board can actually read.

What we run

Defences cut to your exposure

No two estates look alike. Each engagement is scoped against your business criticality, your technical debt and the regulations that bind you.

Penetration testing & red team

Full adversary simulations across external, internal, application, physical and social vectors, delivered with a remediation plan ranked by effort and impact.

WebCloudOT / ICS

Managed SOC, 24/7

Continuous monitoring, multi-source correlation and triage by human analysts. Nothing is subcontracted outside the European Union.

SIEMXDRThreat hunting

Incident response & forensics

Permanent on-call, containment, eradication and a post-mortem that stands up in front of an insurer and a regulator alike.

CERTRansomwareChain of custody

NIS2 & ISO 27001 readiness

Gap analysis, a dated compliance path and support through certification audit. Evidence over paperwork.

NIS2ISO 27001DORA

Cloud security & Zero Trust

Hardening across AWS, Azure and GCP, identity segmentation and conditional access rolled out without breaking production.

IAMCSPMKubernetes

Awareness & phishing drills

Realistic campaigns, reporting-rate measurement and short modules. We train your people rather than blame them.

CampaignsE-learningReporting
Engagements

Short mandates, results you can measure

A selection of work delivered between 2024 and 2026. Names are anonymised where the client asked us to.

Referenced engagements
( 2024–26 )

Havrelis©

A six-week red team against the industrial network of a port operator, run without a single hour of downtime.

14/ critical paths closed
( Port operator )Red team, OT security
Long-running engagement
( Managed SOC )

Cindre Health©

A managed SOC and NIS2 readiness programme across eleven hospital sites sharing one clinical record system.

11 min/ median time to detect
( Hospital group )SOC 24/7, NIS2 readiness
Pre-production review
( 2026 )

Orbanne©

Application testing and architecture review of a payments platform, run alongside the delivery team’s sprints.

38/ findings fixed before launch
( Fintech )Application testing, code review
Engagements

Plans you can read, with no trapdoor

Monthly Annual
Two months free on an annual commitment
Up to 150 endpoints

Watch

Exposure monitoring and qualified alerting for organisations starting a security programme.

€890 // per month
  • Monthly attack-surface mapping
  • Vulnerability and dark-web exposure watch
  • Qualified alerting in business hours
  • Quarterly posture report
Most chosen

Defend

The full posture: continuous detection, contractual incident response and regular offensive campaigns.

€2,490 // per month
  • Everything in Watch
  • Managed SOC, 24 hours a day
  • Incident response engaged within 30 minutes
  • Two penetration testing campaigns a year
  • A named lead analyst
Essential operators

Sovereign

For operators of vital importance and environments under strict sovereignty requirements.

Bespoke // after scoping
  • Everything in Defend
  • A dedicated, compartmented team
  • SecNumCloud-qualified sovereign hosting
  • Annual crisis exercises with the board
  • Continuous regulatory support
Testimonials

What the CISOs say

They found a path in eleven days that three consecutive audits had walked straight past.
Maëlle LantierCISO, Havrelis
Havrelis
The SOC woke us at three in the morning for a real incident. That is exactly what we pay them for.
Théo BardinIT Director, Cindre Health
Cindre
A report our board read to the last page. In twelve years I had not seen that once.
Sonia NeffatiHead of Compliance, Orbanne
Orbanne
FAQ

Questions? We have answers

Clients on Defend or Sovereign have a contractual 30-minute engagement commitment, around the clock. A crisis cell opens within the hour when triage warrants it.

Every engagement opens with a rules-of-engagement document setting scope, testing windows and stop conditions. On industrial networks we work passively by default, then against an isolated replica.

In France only, on SecNumCloud-qualified infrastructure. No data leaves the European Union, including for correlation and enrichment processing.

Yes. Watch exists for exactly that: visibility and qualified alerting without requiring an in-house security team. Most clients start there and move to Defend within twelve to eighteen months.

A three-page summary a chief executive can read, reproducible technical detail for every finding, a remediation plan ranked by effort and impact, and a re-test at ninety days included.

Next step

Ready to shrink your attack surface?

Let us find the three blind spots most worth an attacker's time, then build the defence that fits your budget and your calendar.