What we run

Six disciplines, one practice

Every engagement is scoped against your business criticality, your technical debt and the regulations that bind you. Nothing here is sold as a platform subscription.

01

Penetration testing & red team

Scoped adversary simulation against the estate you actually run. External perimeter, internal lateral movement, application logic, physical access and social engineering, depending on what the mandate calls for.

  • Rules of engagement agreed before a single packet moves
  • Reproducible proof for every finding, not a scanner export
  • Remediation ranked by effort against impact
  • A re-test at ninety days included in the fee
4 to 8 weeks
From €18,000
PASSI-qualified
Discuss this
02

Managed detection & response

A SOC staffed by analysts rather than a ticket queue. We ingest your telemetry, write detection content against your estate, and triage what fires before it reaches you.

  • Coverage 24 hours a day, every day, no follow-the-sun handoff
  • Detection engineering against your own log sources
  • Monthly hunt cycles on hypotheses, not just alerts
  • A named lead analyst who knows your architecture
Continuous
From €2,490 / month
Sovereign hosting
Discuss this
03

Incident response & forensics

When it has already happened. Containment first, then eradication, then the analysis that tells you how far it went and what it will take to say so publicly.

  • Engagement within 30 minutes for retainer clients
  • Containment plan before any evidence collection begins
  • Chain of custody suitable for insurers and regulators
  • A post-mortem your board can read in one sitting
On call
Retainer or emergency
CERT team
Discuss this
04

Regulatory readiness

NIS2, ISO 27001 and DORA. A gap analysis scoped against the engineering capacity you actually have, then support through to certification.

  • Gap analysis mapped to your existing controls
  • A dated path, not a hundred-page recommendation
  • Evidence packages prepared for the auditor
  • Board reporting that satisfies management liability
8 to 20 weeks
From €12,000
ISO 27001 lead auditors
Discuss this
05

Cloud security & Zero Trust

Hardening across AWS, Azure, GCP and Kubernetes. Identity blast-radius reduction and conditional access rolled out in monitor mode before anything is enforced.

  • Posture review against CIS and provider baselines
  • Identity and privilege mapping across accounts
  • Segmentation sequenced so delivery keeps shipping
  • Infrastructure-as-code guardrails your team can maintain
6 to 16 weeks
From €15,000
Multi-cloud
Discuss this
06

Awareness & phishing drills

Campaigns modelled on the lures actually reaching your sector, measured on reporting rate rather than click rate. We train people; we do not run a blame exercise.

  • Lures built from live threat intelligence
  • Reporting rate as the primary metric
  • Short modules, no annual four-hour course
  • Departmental reporting without naming individuals
Quarterly
From €4,500 / year
FR / EN / DE
Discuss this
How it runs

The shape of an engagement

The same five stages whether the mandate is four weeks or four years. No surprises in the middle.

01 Scoping call
Thirty minutes. We establish whether we are the right people before anyone writes a proposal.
02 Rules of engagement
Scope, windows, escalation paths and stop conditions, signed by both sides.
03 Execution
Weekly written updates. Critical findings are reported the hour we confirm them, never held for the report.
04 Debrief
A working session with your engineers, then a separate one with your leadership. Different rooms, different documents.
05 Re-test
Ninety days later, at no extra cost, against the findings you closed.

Not sure which of these you need?

That is a normal place to start. The scoping call exists precisely for it.