I'm the fractional CISO for companies of 100 to 1000 people. Three days a month, one point of contact, plain English and French. You get control over security without hiring a security team.
Every one of these is a business problem.
A revenue, contract or liability problem wearing a technical costume.
Your IT team and your provider execute. They're good at it. But nobody owns the question "what are we protecting, in what order, and who decides?" A full-time CISO costs €120,000 to €160,000 loaded, is nearly impossible to hire, and at your size would be bored half the month.
So every questionnaire becomes a fire drill, every renewal becomes a gamble, and every new standard or law your customers mention is another word that scares you instead of a plan.
The seat needs someone who knows what they're doing in it, three days a month, every month.
Everything below is included.
If your situation doesn't fit this format, I'll tell you in 30 minutes and point you somewhere better.
A security file you can send to any customer, auditor or insurer without sweating.
Which laws and standards apply to you, which don't, and where you stand against each one.
Working on what matters, in the right order, and an IT invoice you understand.
You can say, in one sentence, what happens if your systems are encrypted tomorrow.
Fifteen years in enterprise IT security across finance, retail and industry, the last seven as a security architect on global strategic projects. I use a method that successful CISOs run and that I taught at Paris 1 Panthéon-Sorbonne. I build the tools you need to manage your security the way auditors ask for it. I know what security looks like when it's done properly in a large group, and I know how to scale it down to a company your size without turning it into a caricature.
I take on 3 companies at a time, no more.
Beyond that you're a consultant sending slides.
Good. They stay, and I give them priorities. They'll do a better job.
That's the first thing we settle. And regardless of the law, your customers and your insurer are already asking the same questions.
It's the price of three days of a profile you won't manage to hire, with no payroll costs, no probation period, and cancellable after six months.
Then we don't sign. The diagnostic is free, I'll tell you what to do, and you'll do it yourself or with someone else.
Some companies don't need someone to run their security. The people are already there, and with the right method they can carry it themselves.
That's a different offer: four weeks, real projects, with your consultants or employees. They learn how to manage risk the way regulation and auditors ask for it.
See the training program →
You tell me how security decisions actually get made, what your customers are asking, what worries you. At the end of the call I'll tell you whether I can help, how, and if it's not me, who to talk to.
Book a 30-minute diagnostic →