Findings go out the hour we confirm them
Nothing critical waits for the report. If we get domain administrator on a Tuesday afternoon, you know on Tuesday afternoon.
Thirty-four analysts and engineers in Rennes. We work with operators whose downtime has consequences beyond a revenue chart, which is why we turn down more work than we take.
That question is harder to answer and much harder to invoice against a framework, but it is the only one that changes decisions. It is also why our reports are short, why our findings are reproducible, and why we would rather tell you three true things than forty defensible ones.
Nothing critical waits for the report. If we get domain administrator on a Tuesday afternoon, you know on Tuesday afternoon.
Every report has a section on the limits of the engagement. An assessment that claims total coverage is describing a scope, not a reality.
We write the evidence, your engineers own the system. A programme that collapses when the consultancy leaves was never a programme.
A report with forty low-severity items exists to justify a fee. If we found three things that matter, the report has three things in it.
We have grown slowly on purpose. Every analyst who has run an engagement here was hired before we needed them.
Two people, one industrial client and a rented desk. The first engagement was a water utility that had never had its network mapped.
Formal qualification for penetration testing and security audit, which opened work with public-sector operators.
Continuous monitoring launched with four clients and a rotation of six analysts. Sovereign hosting from the first day.
A dedicated incident response cell, with a contractual thirty-minute engagement commitment for retainer clients.
Still one office, still no offshore first line, still refusing engagements we do not think we are the right people for.
Every report is reviewed by one of these three before it leaves the building.
Head of Compliance
Leads compliance engagements. Translates regulation into work an engineering team can actually schedule.
Read their posts CRCo-founder & CTO
Co-founder and CTO. Fifteen years breaking industrial systems, now spent making them harder to break.
Read their posts KMHead of Incident Response
Runs the incident response cell. On call the night most people are not.
Read their posts