Cybersecurity
Hold the walls, and know where they are thin.
- Governance, risk and strategy
- Audit and offensive security
- Architecture and protection
- Detection, response and continuity
- Cloud and AI security
Learn more — Cybersecurity
Four practices, held by one team.

Secure. Comply. Transform.
In Rome, the arx was the fortified summit of the Capitol: the place that held when everything else fell.
Trust works the same way. It is not declared. It is built, and then defended.
We build it for mid-size companies — security, compliance, cloud and AI — with one senior partner, a fixed price and deliverables agreed before we start.
Why now
They were written separately. They land on the same teams, in the same months, in companies that rarely have anyone assigned to them.
Applies since
Extends EU cybersecurity duties to thousands of mid-size companies, and makes directors personally accountable for supervising them.
Applies since
Requires financial entities and their ICT providers to prove operational resilience, down to a register of every contract.
Applies since
Makes security a condition for placing a product with digital elements on the EU market. Reporting of actively exploited vulnerabilities comes first, then the full regime in December 2027.
Applies since
Sets obligations by risk level for anyone providing or deploying an AI system, including companies that only use one.
The evidence these four texts ask for overlaps by roughly seventy per cent. Produced once, it answers all of them.
What we do
Most firms will sell you one of these. The gaps between them are where incidents and audit findings live, so we keep all four in the same hands.
Hold the walls, and know where they are thin.
Learn more — Cybersecurity
Prove it once. Use the proof everywhere.
Learn more — Compliance & Regulatory
Security that ships with the code, not after it.
Learn more — Cloud & DevSecOps
Deploy it because it works, and because you can defend it.
Learn more — AI Transformation
How we work
From first call to signed proposal in five working days, and from kick-off to board readout without a single unplanned invoice.
A senior consultant, not a salesperson. We ask what is driving the deadline, what exists already, how many entities and systems are in scope, and who will have to approve the result. You get an honest read on feasibility and a range before we hang up — including, when it applies, the fact that you do not need us for this.
A written proposal with the scope, the deliverables listed item by item, the schedule with dates, the people involved, and a fixed price. No day-rate estimates with a range attached, and no discovery phase billed before the scope is known.
Framework contract and mutual non-disclosure agreement signed, insurance certificates provided, access requested and granted, stakeholders identified, and the reporting rhythm agreed. We confirm the schedule against your constraints — audits, releases, holidays — before anything starts.
The work runs with a thirty-minute checkpoint every week: what was done, what was found, what is next, and anything that threatens the date. Significant findings are raised when we find them, not saved for the report. Work is done in your tools and your repository wherever possible.
A presentation to the people who have to act on it — usually the executive committee or the board — with the executive summary, the findings, and the costed action plan. Then a working handover with your team: the detail, the evidence, the configuration, and how to maintain it.
A written proposal for what comes next, if anything does: targeted missions from the action plan, a recurring service to hold the ongoing work, or nothing at all. Sent within fifteen days of the readout so the decision is made while the findings are fresh, with no obligation attached.
Fixed price
Eighty per cent of our catalogue is sold at a fixed price with deliverables defined upfront. You know the scope, the timeline and the cost before you commit.
Three weeks to a clear picture: maturity, exposure and the ten things to fix first.
From applicability to a defensible compliance position, with the governance duties covered.
Every AI system inventoried, classified and dated, with the obligations that follow.
Who you work with
You work directly with a senior specialist in cybersecurity and compliance, with experience across data security, AI, software platforms and cloud. Not a sales lead who hands you to a junior after signature.
Where a mission needs a qualification we do not hold, or a jurisdiction we do not practise in, we bring in a vetted partner and stay accountable for the result. Penetration testing runs with PASSI-qualified teams, incident response with PRIS, managed detection with PDIS.
Directly from France, and through partners who practise locally.
Named client references are provided under NDA during the qualification call. Published testimonials will appear here once our first clients have authorised them in writing.
Client logos
We publish a client logo only with written permission. This strip will fill as those permissions arrive.
Next step
Tell us what is coming — an audit, a deadline, a customer questionnaire, an AI project nobody has reviewed. We will tell you what we would do, in what order, and what it would cost. If we are not the right firm for it, we will say so.