III Practice
Cybersecurity
Know where you are exposed, what it would cost, and in what order to fix it. No fear-selling, no tool catalogue.
- Starting point
- Audit and gap analysis
- Frameworks
- ISO 27001 · NIS 2 · GDPR · DORA
- Deliverable
- Audit report & remediation plan
The question is no longer “if” but “what it will cost you”.
Regulation has changed in nature. NIS 2 extends the perimeter to thousands of organisations that did not consider themselves concerned, and puts directors personally on the hook. DORA does the same in finance.
Our job is not to sell you fear or licences. It is to measure your real exposure, translate it into euros and days of downtime, then define the correction sequence that removes the most risk for the least cost.
This is for you if
- You fall within NIS 2 scope and do not know where to start.
- A client or insurer is asking for ISO 27001 certification.
- You have never tested restoring your backups.
- Your suppliers access your systems with no formal framework.
- An incident happened and you want to avoid the next one.
From assessment to control
-
01
Security audit
Technical and organisational assessment: architecture, identity, endpoints, cloud, backups, supply chain and what teams actually do day to day.
- Architecture and segmentation review
- Identity and privileged access management
- Backup restoration testing
- External exposure and attack surface
-
02
Compliance & certification
Gap analysis then support through to the certification audit. We build an ISMS people can use, not a binder written for the auditor.
- ISO 27001 / NIS 2 / DORA gap analysis
- Policies, procedures and processing records
- Risk analysis and statement of applicability
- Audit preparation and support
-
03
Remediation plan
A roadmap ordered by risk reduction per euro invested. Every action has an owner, a deadline and a closing criterion.
- Risk / cost / time prioritisation
- Costing and workload planning
- Remediation programme management
- Quarterly risk level review
-
04
Resilience & crisis
Continuity planning, incident response procedures, crisis exercises with the executive committee and employee awareness.
- BCP / DRP with RTO / RPO objectives
- Incident response procedures
- Live crisis exercise
- Awareness and phishing campaigns
The frameworks we work against
- ISO/IEC 27001
- NIS 2
- RGPD / GDPR
- DORA
- ANSSI
- NIST CSF 2.0
- ITIL 4
- CIS Controls v8
- PCI DSS
- Loi 09-08
What you get
- Technical and organisational audit report
- Risk analysis valued in business impact
- Gap analysis against the target framework
- Prioritised, costed and dated remediation plan
- ISMS documentation set
- Executive committee debrief pack
Frequently asked questions
Are we in scope for NIS 2?
The directive covers eighteen sectors and applies based on size and activity, including indirectly through the supply chain. We qualify your situation in a few days, before any commitment.
Do you run penetration tests?
We frame the need, write the scope and manage the testing with specialist partners, then fold the results into the remediation plan. Our value is in what happens after the findings.
How long does ISO 27001 certification take?
It depends entirely on your starting maturity and the scope retained — we will not quote a timeline before measuring them. The initial gap analysis gives you that visibility, and it comes first.
Do you help during a live incident?
We support crisis coordination, communication and rebuild. For forensic investigation itself, we bring in recognised specialists.
Next step
Knowing where you stand takes three weeks, not six months.
We qualify your NIS 2 applicability and exposure level at no cost, before any commitment.
Or email us contact@yhconsulting.fr