Audit and consulting in cybersecurity.

Tailor-made support for your projects, led by our GRC (Governance, Risk and Compliance) cyber experts, deploying the most effective methods and solutions currently on the market.

Our offers of consulting

Cyber Compliance

  • Audit, support and regulatory watch for compliance (ISO 27001, NIS2, NIST, DORA, ISAE 3402, SecNumCloud, HDS, PCI-DSS, TISAX, SWIFT CSP, LPM, GDPR, SOX, SOC 2, IGI 1300 / RGS, …)
  • Assessment of gaps between your organization's current practices and sector regulatory/normative requirements
  • Verification of your providers' compliance
  • Evaluation of your documentation's compliance
  • Formalization of a roadmap and a macroscopic action plan for your certifications, including priority projects, quick wins and recommended developments
  • Preparation and support for audits (certifications, internal, client, supplier, technical)
  • Coaching of your teams on audit processes
  • Investigation and OSINT (Open Source Intelligence)

  • Continuous clear/deep/dark web monitoring of your digital assets
  • Detection of credential leaks, sensitive documents and strategic data
  • Offensive OSINT: mapping your public exposure (domains, IPs, emails)
  • In-depth investigations and analyses on targeted threats
  • Cyber due diligence in the context of M&A or partner evaluation
  • Global Support "CISO as a Service" (RaaS)

  • Sizing and steering of your Information System security team
  • Coordination with your business teams, clients and providers
  • Identification of a target organizational model and development of a security roadmap (objectives, milestones, priorities)
  • Definition of associated budgets and monitoring via consolidated dashboards (performance indicators)
  • Preparation and running of strategic and operational committees
  • Organization and Governance

  • Drafting of the ISSP and documentation corpus (policies, procedures, charters)
  • Mapping of roles, responsibilities and delegations (RACI)
  • Definition of security KPIs and steering dashboards
  • Structuring and running of governance bodies (steering committee, executive committee)
  • Multi-year security roadmap aligned with business objectives
  • Risk Analysis and Management

  • Definition of the study framework, and the business and technical scope
  • Identification of feared events and their severity level
  • Identification of risk sources (RS), target objectives (TO), and selection of RS/TO pairs deemed a priority for continuing the analysis
  • Identification of critical stakeholders and evaluation of their threat level
  • Development of strategic scenarios
  • Development of operational scenarios for each strategic scenario
  • Evaluation of the likelihood of operational scenarios
  • Synthesis of risk scenarios and definition of the risk treatment strategy
  • Definition of security measures adapted within a risk treatment plan
  • Evaluation and documentation of residual risks and implementation of the risk monitoring framework
  • Awareness

  • Phishing campaigns
  • Personalized awareness journeys
  • Awareness sessions (cyber best practices, challenges around Artificial Intelligence, security integration in projects, …)
  • Creation and distribution of internal notes and infographics
  • Business Continuity and Recovery

  • Design and deployment of your business continuity plans (BCP) and IT continuity plans (ITCP) aligned with your crisis and incident management setup
  • Implementation of a disaster recovery plan (DRP) to ensure a fast and secure restart
  • Business Impact Analysis (BIA) to identify your critical processes and prioritize their restoration
  • Formalization of operational procedures ensuring the resilience and effectiveness of teams in a crisis situation
  • Asset and Vulnerability Management

  • Clear and centralized mapping of your assets for a consolidated and manageable view
  • Targeted identification of vulnerabilities associated with your critical assets
  • Implementation of a continuous asset and vulnerability management process
  • Alerts and proactive monitoring of the most critical vulnerabilities
  • Regular update of your asset repository to ensure its reliability
  • Incident and Crisis Management

  • Implementation of a dedicated organization and processes for crisis and incident management
  • Development and formalization of your crisis management plan and associated procedures
  • Definition of workflows adapted to ensure smooth coordination in a crisis situation
  • Personalized crisis management methodology, aligned with your organization and business challenges
  • Cyber crisis management exercises to test and strengthen the resilience of your teams
  • Operational support and hands-on intervention for the resolution of major incidents
  • Our sectors of expertise

    Each industry faces specific cybersecurity challenges, requiring tailored solutions. The unique challenges they face demand a customized approach to ensure the protection of their data and infrastructure. That's why we offer a cybersecurity consulting service adapted to all industries.

    A project, a security issue? We are here to listen, come talk to us.

    Contact us

    10 rue de Penthièvre.

    75008 Paris

    France.

    © 2026 Wannath, all rights reserved.