>
Our approach
  1. 1Assess
  2. 2Protect
  3. 3Comply
  4. 4Monitor
  5. 5Evolve
Business Unit · Cybersecurity & GRC

From audit to 24/7 defence, with total confidence.

We cover the entire security chain: from risk assessment to continuous monitoring — through protection, compliance and training.

Our approach — a continuous cycle
1 · Assess 2 · Protect 3 · Comply 4 · Monitor 5 · Evolve Our approach
Certifications & accreditations
01 · Assess — Audit & Consulting

Assess, then structure.

We identify your vulnerabilities — technical and organisational — and build a prioritised remediation plan and durable security processes with you.

Technical audits

Find the gaps

A concrete assessment of how well your systems hold up, with a prioritised remediation plan.

  • Penetration testing (pentest)
  • Secure code review
  • Cloud security assessment
  • Active Directory audit
  • Data Center audit
  • PKI infrastructure audit
Consulting & governance

Structure security

From policy to business continuity, we embed security into your processes.

  • Information security policy (ISSP)
  • ISMS & ISO 27001:2022 certification
  • Risk mapping
  • Information security risk management (ISO 27005)
  • SOC implementation support
  • Business continuity & operational resilience (BCP / DRP)
02 · Protect — Solution Integration

Aligned with the NIST CSF 2.0.

We integrate and operate the solutions of our vendor partners, covering every function of the framework. Hover over a function to link it to its solutions.

Identify Protect Detect Respond Recover GOVERN
Identify
Vulnerability Management — continuous scanning, prioritisation and remediation.
Application Security — end-to-end SAST, DAST and IAST.
Data Classification — discovery, classification and labelling.
Data Protection — encryption and protection of sensitive data.
Data Loss Prevention (DLP) — preventing data leakage.
Protect
IAM / PAM — identity and privileged access management.
FIM — file integrity monitoring.
Detect
SIEM — centralised visibility and event correlation.
EDR / XDR — endpoint detection and response.
Respond
SOAR — orchestration and automated, playbook-driven response.
Recover
BCP / DRP — continuity and disaster recovery after an incident.
GovernCross-cutting foundation — underpins and steers the five functions of the framework.
GRC Platform

Centralised steering of governance, risk and compliance.

Our partners

Integrator of the best technologies.

As an integrator, we deploy and operate the solutions of leading software vendors and manufacturers.

IBM Splunk Symantec Fortinet HCL Software Tenable Rapid7 RSA Comforte Cimcor
03 · Comply — Compliance & Certification

From gap to certification.

We measure your compliance (gap analysis), drive remediation and take you all the way to certification — as an accredited centre.

  1. 1

    Audit

    Gap analysis against regulatory requirements.

  2. 2

    Remediate

    Remediation plan and end-to-end operational support.

  3. 3

    Certify

    Accredited centre for PCI DSS, SWIFT CSP and PECB (ISO 27001 / ISO 27005).

04 · Monitor — Managed Services · 24/7 SOC

Detection and response around the clock.

Monitoring, detection and response 24/7 from our SOC, with board-ready metrics (MTTD, MTTR). A modular offering: monitoring alone, incident response, vulnerability management… or the full package, to fit your needs.

  • 24/7 monitoring & detection (MITRE ATT&CK)
  • 24/7 incident response (CERT)
  • Vulnerability Management as a Service
  • Threat Intelligence
  • Managed solutions: SIEM, EDR, XDR…
CERT · 24/7 Incident Response

Hit by a cyberattack?

Our CERT responds in an emergency: containment, forensic investigation and remediation — 24/7, all year round.

Contact the CERT
05 · Evolve — Training & Awareness

Build the human firewall.

People remain the first line of defence. We equip them — from technician to executive — through our Intervalle Training centre.

Cybersecurity

CEH v13, CPENT, ECIH, CSA, OSCP, EC-Council DRP, PKI.

GRC

CISSP, CCSP, CISA, ISO 27001 (LA/LI), ISO 27005.

Compliance

SWIFT CSP, PCI DSS, Data protection.

Awareness

Phishing simulations, e-learning, workshops, kits.

Executives

CISO briefings, board sessions, crisis simulations.

Our training accreditations
EC-Council Offensive Security ISC2 PECB ISACA

Trusted by

Frequently asked questions

A technical audit concretely evaluates how well your systems hold up (pentest, code review, cloud, Active Directory, forensics). Consulting addresses your governance and processes: information security policy, ISO 27001 ISMS, risk mapping, BCP/DRP.

Yes. We are an accredited centre for PCI DSS, SWIFT CSP and PECB (ISO 27001 and ISO 27005), and we support you from gap analysis all the way to certification.

Absolutely. You can take monitoring only, incident response only, vulnerability management, or the full package — we tailor the offering to your organisation.

Our integration covers the Identify, Protect, Detect, Respond, Recover and Govern functions — each solution (SIEM, SOAR, EDR/XDR, IAM/PAM, DLP, GRC…) is positioned on the functions it serves.

Ready to assess your exposure?

A free initial audit and a prioritised roadmap to strengthen your security posture. Leave us your details and an expert will get back to you.