I take the people you already have and bring them up to security architect level, on your own projects.

You end up with architects who know cloud, identity and attack paths, a risk process that runs, and the day to day back under control, so your time goes to strategy and the business.

Fabien Soulis
that's me 👋
Three kinds of people call me.
Before
  • Security is your accountability, and the process everyone is supposed to follow isn't understood or can't be replicated at scale.
  • You hear about the new cloud platform the week it goes live.
  • Whether it's safe is still your call to make, alone.
After
  • The process is understood by the people around you, and it holds as the number of projects grows.
  • Asking the security question early becomes their reflex, not your reminder.
  • Less of it ends up on your desk.
  • You finally have the time for strategy and the business, or just to relax.
Before
  • Your consultants find vulnerabilities well, but they aren't the profile a client's CISO wants leading the engagement.
  • A client asks for someone senior and you have nobody free to put forward.
  • The mission goes to another firm.
After
  • They have the technical depth, and they can defend a security decision in front of a client.
  • The next senior profile you put forward is one you already employ.
  • The mission stays with you.
  • And you become the firm that client calls first the next time they need a security consultant.
Before
  • Deep tech knowledge, but you never internalized how attackers actually break a system.
  • You don't know what to look for, or how to structure security at the design phase.
  • So on your own projects, security stays something other people decide.
  • And when a security role opens up, they hire someone external with the experience instead of you.
After
  • You run a secure by design strategy inside your own company.
  • Your tech background becomes the advantage: you secure the technologies you already know.
  • And with the mental map and the thinking method, you secure the ones you don't.

Tell me your situation and I'll tell you where to start: the training, the custom IT risk management software, or the security consulting and coaching retainer.

Let's talk
A message. No sales deck, just a conversation.

Short on time? The whole argument, out loud, in 90 seconds.

three ways this works

Capability, tools, and support. One method behind all three.

Cyber risk management and Secure by Design don't get installed by a slide deck. People need to learn the reasoning, then they need something to run it with, and then they need someone to call the first few times it gets hard. Companies use one of these, or all three.

Tools
Run the process

Risk Expert, the software I built to run risk assessments, keep a risk register your executive committee will actually read, and hold the Secure by Design checkpoints on every project.

See Risk Expert
Support
When it gets real

Ongoing help on live work. I review the deliverables before they go out, prepare your people for the conversations that decide things, and sit in the reviews that matter.

Talk it through
the capability pillar

Four weeks. Real projects.

Nothing on this list is theory I haven't lived myself inside large organizations and as a consultant. Each phase builds on the last. Each one produces a deliverable they keep.

1
Week 1

Think like an attacker, defend like a strategist

Before you can protect anything, you need to understand what you're protecting and why. Most security people skip this and spend years fighting the wrong battles.

The CIA triad. Impact types: financial, operational, reputational, legal, physical. Real incident stories from 15 years inside enterprises: employees deleting servers, CISOs spying on CEOs, phishing attacks on Christmas Eve, call centers stealing customer data.

Then we go wider: every attack vector attackers actually use against Windows endpoints, Linux servers, Active Directory, and cloud infrastructure (Azure, GCP, M365), and the countermeasures (preventive, detective, corrective) that neutralize each one.

By the end of this phase your people will see the full spectrum of what can go wrong, know how attackers move on every major surface, and evaluate each risk by probability and impact.

Ask me for the sample case study On request

An example of the course material for this phase: how to audit a multicloud environment, every attacker technique paired with the control that stops it. This is the one I don't publish. I don't want AI assisted script kiddies reading it, because a complete intrusion chain written out step by step gives them far too much power. Ask me for it and I'll send it to you.

2
Weeks 2 – 3

Security By Design: becoming the security checkpoint

How to become the person everyone consults before making IT decisions. This is what turns a security professional into someone the business cannot route around.

How to get informed early about IT needs. How to evaluate risks of proposed solutions. How to propose security measures that get accepted. How to get formal risk acceptance from business owners. The documentation that saves your career the day something breaks.

We learn the process by dissecting the disasters that happen when it's missing: the first CISO who discovers shadow IT across the entire company, the security approval given over coffee that leads to a breach, the VPN failure costing 250,000 euros per day. Each case comes from inside enterprises I've lived through, and we rehearse the conversations against real stakeholders.

Your people will walk out of this phase running the exact process that turns them from "the security guy" into the security checkpoint no project can bypass.

Read the sample case study PDF · 4 pages

One of the cases we work through: the first CISO of a remote e-commerce start-up who finds shadow IT everywhere, and the moves that put security back in the room before the decision.

3
Week 4

Risk analysis of an AI helpdesk agent

The 2026 architect problem: companies are racing to deploy AI agents inside IT support. Almost none have risk-analyzed them. This is the exact question your team will be asked to answer.

Identify the threat actors: the prompt injection attacker, the malicious end-user, the compromised third-party connector, the over-permissioned agent itself. Map attack scenarios: data exfiltration via tool calls, privilege escalation through ticket creation, social-engineering the model into resetting the wrong password, leaking PII through chat history. Design the full control taxonomy (preventive, detective, corrective, deterrent, compensatory) against each scenario. Build the risk register a risk owner will actually sign.

I review the work line by line.

Your people will leave this phase with a complete AI-agent risk analysis they can show any client, plus a methodology that transfers to any IT project they'll encounter.

Read the sample deliverable PDF · 3 pages

That memo is the condensed version, what a project committee reads. The phase itself goes much deeper: every attack scenario and every control taken apart technically, one at a time. It can also run as a lab in Azure or GCP, where your people deploy a real helpdesk agent and then secure it.

4
Shadowing

Real work, under real conditions

The last phase is different. No exercises. No structured content.

Your employees bring a real task from their current job or client engagement. We work on it together, me alongside them, not ahead of them. I watch how they think, where they hesitate, what they miss. I ask the questions that help them find the answer, rather than giving it.

This is where the framework becomes instinct. And the only way that happens is on real work, under real conditions.

The full program in one PDF PDF · 3 pages

The whole program in a single document, from the four phases to what your teams walk away able to do. Made to be forwarded to whoever else in your organization should see it.

1-on-1 or Small Group · 4-Week Program · Remote

where the knowledge lands

The knowledge taught in this program is applied inside these organizations.

Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
the question I'd ask too

Why me, and not a consulting firm or a training company.

I've spent fifteen years in cybersecurity, inside large and medium organizations across sectors: finance, retail, industry, public services, high-tech startups. I started as a consultant (IT financial auditor, compliance for internal control, forensic investigator, pentester, security analyst), then moved inside as a security architect. For the last 7 years I've been doing this for international retail companies across the globe (Americas, Europe, Asia, Africa, Australia), designing security for strategic projects: infrastructure core services, cloud and data platforms, API-first strategies, SAP migrations, and more.

I've taught this Secure by Design methodology at Paris 1 Panthéon-Sorbonne. I also build the software behind this work: Risk Expert, the tool I use to run risk assessments and Secure by Design reviews, and dmarc-expert.com, an email security SaaS used by large companies.

I don't pretend to be the best on every subject. When a client's context calls for something specific, insurance regulation, banking, AI systems, I bring in an architect from my network: more than twenty senior security architects I've worked with and trust. I run the program either way. You get the person best placed to answer, not the only one available.

I know how hard it is to get security taken seriously before something breaks. I know what it takes to shift a team's habits.

This doesn't promise miracles. It gives your people a structured path and someone to work through it with them, and it leaves the result inside your company instead of inside a supplier's.

If they put the work in, the change is visible. If they don't, no program will fix that. That's the deal, and it's the only one I'd ever offer you.

Fabien
Security Architect · 15 years in enterprise IT security
a 2-minute gut check

When your team makes the wrong call, you're the one the CEO calls.

Five situations your people will face. Pick the answer that honestly reflects what your team would do, not what the policy says. At the end you'll see how much of your own position is riding on their judgment. No email required, nothing saved.

before you reach out

A few things people ask.

Who exactly is this for in my organization?

+

Security consultants, in-house security engineers, or technical IT generalists who are expected to give security guidance but haven't been trained to structure it. They need to be technically comfortable but don't need to be senior. The program works best when they have at least one current project or client context to bring to the work.

Why this rather than hiring someone, or bringing in a consulting firm?

+

If you can hire a senior security architect, hire one. The profile is scarce and expensive at any headcount, and the people who have it are already placed. So the realistic hire is a junior, and a junior needs exactly the thing this installs.

A consulting firm is the other honest answer, and it is the right one when you need the work done once and done now. It is the wrong one when the same question is going to come back at every renewal, every new client, every new project. Then you are renting a capability you should own.

And if what you actually need is someone to run security for you rather than teach your team to, that is a different offer: fractional CISO, three days a month.

Can several people go through it at the same time?

+

Yes. I work in small groups of two or three when the participants come from the same team or firm. More than that and the work loses its depth: everyone needs real feedback on their actual reasoning, not a group presentation.

How much time does it take per week, for my team?

+

Roughly half a day per week for the structured phases, plus whatever time they put into the exercises. It's designed to run alongside their current work, not replace it.

What's the format?

+

Remote, via video call and shared documents. If you're based near the North of Spain, the South of France, or close to an international airport and prefer in-person for some sessions, that's something we can discuss.

How will I know it worked?

+

You'll see it in how your people talk about security decisions, and how their clients respond. The clearest signal is when a project team starts consulting them before a problem appears, rather than after. That shift doesn't happen overnight, but it's visible within 3 months.

What if my sector needs expertise you don't have?

+

Then I bring in someone who does. I keep a network of more than twenty senior security architects I've worked with directly, with deep ground in insurance, banking, industrial systems, and AI. When your context calls for that depth, one of them joins the work for that part of it.

I run the program either way, and the method stays the same. You keep one point of contact and one way of working. You just get the best-placed person on the question instead of the only one in the room.

In which language do you deliver?

+

French, English, or Spanish. Most participants from French firms prefer French, but the written deliverables are often in English. We adapt to what's most useful for your team and your clients.

Other languages are possible. For those, I delegate to senior security architects in my international network: people I know personally and trust to deliver at the same level.

Fabien Soulis
let's talk 👋

Before anything else, a free diagnostic of your context.

I've been a consultant inside a lot of companies. Finance, retail, industry, public services, startups. What works in one of them fails in the next, and I know where the difference comes from.

  • A call: you tell me how security decisions really get made, where your teams lose ground, what your clients and auditors are asking for.
  • A written action plan: how a Security by Design process fits your context, and in which order to build it.
  • The point of it: give your security teams back their visibility, their control, and their soft power.
Ask for your free diagnostic

Or send me a message if you prefer.

Free, and no commitment after it. I'll tell you plainly if I think I can help or not.