Attack surface reduction
- exposed services
- obsolete systems
- misconfigurations
- unnecessary access
- dormant accounts
- priority patches
See the cybersecurity audit.
We secure your information system against the main cyberattack scenarios by combining technical protections, access management, monitoring, team awareness, incident response procedures and recovery measures. The goal: reduce your exposure, detect abnormal behaviour faster and limit the impact of an incident.
This matters because a serious cyber strategy is not only about preventing an attack. NIST CSF 2.0 structures risk management around six functions: Govern, Identify, Protect, Detect, Respond and Recover.
What you get
After protection deployment
360° hardening — technical, organisational and human — with a prioritised roadmap and procedures ready to respond to any incident.
€27,000: average cost of a cyberattack for a French SME (CESIN 2024)
Understand
Effective protection relies on several complementary layers. No firewall, antivirus or isolated tool is enough on its own: you need to know your assets, restrict access, keep systems up to date, detect suspicious events, know how to respond and have a recovery capability.
ANSSI presents its IT hygiene measures as a minimum security baseline, covering access, updates, backups, networks and awareness.
Assets, users, software, accessible services.
MFA, privileges, administrator accounts.
Workstations, servers, applications, networks.
Logs, alerts, monitoring.
Procedures and responsibilities in case of incident.
Backups, DRP and continuity.
Our cybersecurity services
Complete IT assessment: systems, networks, access, applications and sensitive data.
Real attack simulation to identify exploitable vulnerabilities before hackers do.
Define and formalise your security rules, access, incident management and IT compliance.
Deploy technical and organisational measures to block and detect attacks.
Our approach
Six operational pillars, deployed together: reduce exposure, secure identities, protect systems, detect, respond and recover.
See the cybersecurity audit.
ANSSI issues specific recommendations on multifactor authentication and passwords; CISA also strongly recommends MFA, particularly against ransomware scenarios.
ANSSI treats security supervision as a device to organise and operate (processes, roles, detection, event handling) — not as a tool that is simply installed. It is not a SOC by default.
CISA specifically recommends offline/encrypted backups and regular testing in its ransomware prevention measures.
Mini diagnostic
Your protection level
Strengthened protection
Indicative diagnostic, not a technical audit. The real deliverable is a 30 / 60 / 90-day roadmap, prioritised after the security audit.
Already have antivirus + firewall?
An antivirus and a firewall remain useful. They only cover part of the information system, though: the network and, in part, the workstations. An attack often comes from elsewhere: an account, an untested backup, an untreated alert or a human error.
That is not necessarily sufficient. Several layers come into play, and each has a distinct role.
Network control.
Workstations and servers.
Identities.
Recovery.
Detection.
Response.
Human factor.
Cybersecurity rests on an architecture of complementary protections, not on buying a single piece of software.
Phishing
Phishing is one of the most frequent attack vectors. Protection combines identities, email, awareness and a reporting reflex — not a single isolated tool.
Limit the impact of a compromised password.
Reduce phishing messages reaching inboxes.
Recognise suspicious requests.
What does the employee do when in doubt?
Ransomware
Ransomware is not handled with a single tool. You need to reduce entry points, detect earlier, contain the incident, restore data and resume operations.
CISA ransomware recommendations cover MFA, updates, protected backups and recovery procedures in particular.
Patches + access + MFA
Monitoring
Incident procedure
Backups
DRP
What do we actually do?
We do not deploy a fixed catalogue of eight mandatory products. Depending on your IT, uses and priorities, we put in place all or part of these protections.
Third-party tools
We do not build your cybersecurity around a mandated tool. We start from your infrastructure, your risks and the solutions already in place, to decide what to keep, complement, replace or configure better.
What already protects you properly — no replacement for the sake of a catalogue.
The real gaps: MFA, backups, supervision, procedures — where the IT system is exposed.
Only what is unfit, too exposed, or impossible to harden as it stands.
The tool is already there: the settings, rights and operating model often are not.
Any vendor licences, cloud subscriptions or supervision services are identified separately in the proposal.
Before / after
The engagement shows up in day-to-day IT operations: controlled access, readable alerts, tested backups and identified owners.
Our method
A clear sequence, adapted to your IT: diagnose, prioritise, deploy, verify, document, train, then keep the setup evolving.
Understand the environment.
Do not treat everything at the same level.
Define suitable protections.
Install/configure the measures.
Verify they work.
Procedures and responsibilities.
Teams concerned.
Tool, hours, handling, escalation, SLA.
Reassessment and evolution.
Deliverable
This is not a generic list of best practices: it is a 30 / 60 / 90-day plan, prioritised from your security audit. NIST CSF 2.0 is built around a full cycle — from governance through to recovery after an incident. That is the thread we follow to protect the business, without deploying everything at once.
0–30 days
30–60 days
60–90 days
Without an audit, the plan stays theoretical. With the audit, each 30 / 60 / 90-day stage maps to a real gap in your environment — not a product catalogue.
Want this deliverable on your scope? The security audit finds the gaps; this roadmap says in which order to fix them so the business can withstand a cyber attack.
Who is it for?
Not only after an incident. Any organisation whose operations, data or access depend on IT needs concrete protection — including when the audit or pentest has already listed the gaps.
You have no CISO or dedicated team — we become your cybersecurity partner and deploy protection suited to your size and budget.
Health, finance, HR, intellectual property, customer data — these assets justify stronger protection (access, encryption, backups, monitoring), not just antivirus.
Your business relies on systems connected 24/7 — protection against DDoS attacks, injections and account compromise is critical.
If a few hours of downtime stop production, billing or customer service, securing the information system is no longer an IT project: it is business continuity.
We close the exploited gaps, harden access, isolate backups and put procedures in place to prevent a repeat — not just “clean up” the incident.
You already have the list of vulnerabilities: we take on the remediation phase. The security audit and penetration test find the gaps; this page is the plan to fix them.
Already completed an audit or pentest?
A report without remediation leaves vulnerabilities open. This page is the step where we fix them — after understanding, testing and prioritising, before monitoring and re-checking.
Already have the list of gaps? We take on the remediation phase: fix, monitor, then verify — not re-read the report.
Our pricing
Cost depends on your IT size, desired protection level and scope to cover. Well-deployed protection costs on average 10× less than an incident.
Essential hardening
€2,500 – 4,900 excl. VAT
Simple environment / SME
Strengthened protection
€5,500 – 9,900 excl. VAT
Access, MFA, endpoints and backups
Complete protection & supervision
€9,900 – 18,000 excl. VAT+
Architecture, scoped supervision and continuity
Indicative pricing excl. VAT — Complianz fees, excluding third-party licences and tools. A tailored quote is provided within 24 hours. What determines the cost?
Installing an alerting tool is not a SOC. Supervision in this pack is a scoped setup: tool, surveillance, hours, event handling, escalation and SLA. A SOC (dedicated team, on-call cover, continuous alert handling) is only offered if it is actually stood up, on quote.
What determines the price
The ranges (€2,500 – 18,000 excl. VAT) are Complianz fees. They do not tell you whether an EDR, firewall or vendor SOC is included: those licences and subscriptions are a separate line, unless the quote says otherwise in so many words.
Included in the prices shown.
Not included, unless the quote says otherwise.
The €5,500 excl. VAT strengthened-protection figure is a fee. It does not, by default, include the EDR licence, the firewall or a SOC. Those costs are shown separately and, where possible, contracted in the client’s name.
By combining reduced exposure, access hardening (MFA), workstation and server protection, detection, incident response and recovery — not a single tool. NIST CSF 2.0 structures this from governance through to recovery. See how to protect the business →
Useful protections are MFA, access hardening, EDR or suitable endpoint protection, isolated and tested backups, scoped supervision, incident procedures and staff awareness. This is not a catalogue of eight mandatory products: we keep, complement, replace or configure according to the IT system. See the protections we can deploy →
An SME starts with the urgent: critical vulnerabilities, MFA, exposed accounts, backups, access. Then it structures (segmentation, procedures, monitoring) and sustains (training, tests, control). A 24/7 SOC is not the starting point. See the 30 / 60 / 90-day roadmap →
No. Antivirus helps against known threats, but it does not replace MFA, tested backups, an incident procedure or supervision. Information-system protection rests on complementary layers, not one piece of software. See antivirus, firewall and complementary layers →
Antivirus relies mainly on known signatures. EDR (Endpoint Detection and Response) watches behaviour on workstations and servers to detect and block attacks, including unknown ones. EDR is not mandatory for every SME, but it becomes relevant when data, remote access or exposure justify it. See protection layers →
MFA (multi-factor authentication) adds a second factor to a password. A credential stolen through phishing or a leak is no longer enough to get in. ANSSI and CISA strongly recommend it, especially against ransomware scenarios and for admin, VPN, email and cloud accounts.
Phishing is treated at several levels: MFA, email protection, filtering rules, staff awareness and a procedure if a link has been clicked. An awareness campaign does not replace access hardening. See phishing protection →
You need to reduce entry points, detect earlier, contain the incident, restore and resume operations. CISA ransomware guidance covers MFA, updates, protected backups and recovery procedures in particular. See how to limit ransomware impact →
Isolate affected machines, do not pay a ransom, call in an expert, report to ANSSI and the CNIL if personal data is involved, then activate recovery. If the IT system is still compromised, incident response or an investigation may be needed before a simple hardening project.
Yes, especially for ransomware. CISA in particular recommends maintaining offline or encrypted backups and regularly testing that they can be restored. A backup reachable from the same network as production can be encrypted or deleted by the attacker.
A SOC (Security Operations Center) is a team and a setup: detection, alert handling, roles, hours, escalation and SLA. It is not a monitoring tool that has been installed. ANSSI treats security supervision as a device to operate, not as a product.
Not systematically: the level of supervision must be proportionate to the risks, exposure, obligations and capabilities of the organisation. Many SMEs first need a scoped tool, defined hours, event handling, escalation and an SLA — a SOC is only offered if it is actually stood up. See what supervision covers in our packs →
The audit finds the gaps in the IT system. Cyber protection fixes them and deploys the measures: it is the deploy step in the journey. Without remediation, the report leaves the holes open. See the path from finding gaps to fixing them →
A pentest tests whether flaws can actually be exploited, in an authorised scope. Cyber protection prioritises and remediates, then hardens the IT system. The two follow each other: test, then remediate, then optionally re-check with a retest. See penetration testing →
Complianz fees range, as a guide, from €2,500 to €18,000 excl. VAT depending on scope. EDR licences, firewall, cloud subscriptions or a vendor SOC are a separate line, unless the quote says otherwise. Cost depends in particular on users, workstations, servers, cloud and current protection level. See pricing and cost factors →
Yes, but not as a simple hardening project if the attacker is still inside. Incident response or an investigation may be needed first: contain, eradicate, then only rebuild and harden. Hardening an IT system that is still compromised can leave the access open.
Yes. If you already have the list of vulnerabilities, we take on the remediation phase: prioritise, fix, monitor, then re-check. A scoping exercise checks the perimeter, how old the report is and what has already been treated. Have my vulnerabilities fixed →
Our experts deploy protection suited to your IT in 4 to 8 weeks. First conversation free, confidential, no commitment.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.