Cyber Resilience

Zero Trust, Red Team Agents, BCP/DRP

Zero Trust cybersecurity augmented by AI: EBIOS RM risk analysis, continuity proven by real exercises, structured crisis management, aligned with NIS2 and DORA.

A posture is only worth the number of times it has been replayed.

A continuity plan that has never been executed describes an intention. It holds on paper, it names owners, and it collapses at the first real exercise because a dependency no diagram showed turns up at the worst moment.

So we work the other way round. Risk analysis ranks by business impact, recovery objectives are negotiated service by service, then everything is replayed under production conditions, with no warning. What breaks during the exercise will not break on the day of the incident.

What we do

Four workstreams so resilience is demonstrated rather than announced.

WORKSTREAM 01ANSSI method

EBIOS RM risk analysis

The ANSSI method applied to the real perimeter rather than to one application: feared events ranked by business impact, risk sources, and a costed treatment plan.

ranked by business impact, not by technical severity

  • Feared events before technical scenarios
  • A grid reusable from one entity to the next
  • A treatment plan that can be arbitrated, not a report
WORKSTREAM 02Verify, don't assume

Zero Trust

No implicit trust: every request verified, every access logged, every connection encrypted. Microsegmentation, identity-aware proxy, least privilege and strong authentication.

applied to network, identity, application and data

  • Microsegmentation and least privilege
  • Access logged, administrators included
  • One directory of record, and only one
WORKSTREAM 03Replayed unannounced

Proven continuity

Recovery objectives negotiated service by service, a runbook that names the roles, then an exercise under real conditions. An RTO that has never been replayed commits nobody.

in production, on the worst plausible scenario rather than the most likely

  • RTO and RPO per service, not for the system
  • A runbook that says who decides
  • The gap to the objective measured, then closed
WORKSTREAM 0424/7

Detection and response

Continuous monitoring, signal correlation and tooled response. What makes the difference in a crisis is not detection but the delay between detection and the first order given.

decision time is measured just like detection time

  • Detection, investigation and response, continuously
  • Decision time measured as well
  • Blameless post-mortems

What you get

One project runs through the four deliverables below: the recovery exercise of an operator in scope of NIS2. Each line states what is actually handed over, in the order it is handed over.

01

The perimeter and its recovery objectives

An RTO and an RPO per service, with dependencies declared. A single objective for the whole system never survives the exercise, because it ignores that some services wait on others.

02

The scenario, chosen for what it reveals

The worst plausible case rather than the most likely: online backups presumed compromised, the directory unavailable, and no shortcuts allowed. It is the prohibitions that make the exercise useful.

03

The crisis runbook

What is missing in a crisis is not competence, it is knowing who decides. The runbook names roles, lists the decisions that cannot be delegated, and sets the communication rhythm even when there is nothing new.

04

The exercise, in production and unannounced

Three services hold their objective, the fourth does not. What the exercise uncovers appears on no architecture diagram, and that is exactly why it had to be replayed for real.

How we deliver

PHASE 012 to 6 weeks

Analyse

depending on scope, sector and the applicable framework, NIS2 or DORA

  • EBIOS RM risk analysis
  • Feared events ranked by business impact
  • A costed, negotiable treatment plan
PHASE 024 to 10 weeks

Put to the test

depending on the number of critical services and the depth of the scenario

  • RTO and RPO negotiated service by service
  • Crisis runbook with named roles
  • A first exercise under real conditions
PHASE 033 to 6 months

Harden

depending on the number of systems and accesses to rework

  • Zero Trust extended to access and networks
  • Detection and response tooled up
  • Gaps from the exercise fixed and replayed
PHASE 04continuous

Hold

service commitment defined with you

  • Exercises replayed, not just documented
  • Continuous monitoring and response
  • Compliance held between two audits

What 2026 requires

10 to 15,000
French companies and organisations newly in scope of NIS2, far beyond the operators of vital importance alone
€10M
or 2% of worldwide turnover, the sanction ceiling for an essential entity in default
17.01.2025
DORA came into force across the Union, for the financial sector and its IT providers

Enterprise Security

No implicit trust, continuous verification at every layer of the stack: network, identity, application and data.

Network microsegmentation
Identity-Aware Proxy
Least Privilege & MFA
(01)

EBIOS RM & ISO 27005

The ANSSI method for the analysis, ISO 27005 for the framework. That is what makes a result comparable from one entity to the next, as on the method industrialised for Engie.

(02)

An RTO proven, not declared

A recovery objective negotiated per service, then verified by a real exercise. An RTO that has never been replayed commits nobody.

(03)

NIS2 & GDPR

Full regulatory compliance with risk mapping and action plans.

(04)

SOC & SIEM 24/7

Continuous detection, investigation and response to security incidents.

Platforms in Production

A risk analysis on the whole information system
FNMFMutual insurance
EBIOS RM
Case(01)

A risk analysis on the whole information system

EBIOS RM, the ANSSI method · GDPR-compliant

The challenge

A federation holding health and social data on millions of members, where a risk analysis cannot stop at the perimeter of one application and where compliance has to hold over time rather than on audit day.

Our answer

An EBIOS RM analysis across the whole information system, feared events ranked by business impact rather than by technical severity, and a GDPR alignment carried by the same mapping instead of a separate exercise.

Read the case study
A reusable EBIOS RM method for group cloud compliance
EngieEnergy
Cloud compliance
Case(02)

A reusable EBIOS RM method for group cloud compliance

ISO 27005 compliant · Aligned with the group security policy

The challenge

A global energy group where each entity ran its own cloud risk analysis, with results nobody could compare and a security policy that stayed a document rather than a practice.

Our answer

An EBIOS RM method industrialised into something reusable: the same grid, the same scales and the same deliverables from one entity to the next, aligned with ISO 27005 and with the group policy.

Read the case study
GOC 2.0: an architecture audit on a critical system
SNCFTransport
Critical audit
Case(03)

GOC 2.0: an architecture audit on a critical system

Dynatrace instrumentation · Root cause analysis and action plan

The challenge

An operations control system on which national rail traffic depends, where a slowdown is not a support ticket but trains held at a standstill, and where the cause of an incident had to stop being a matter of opinion.

Our answer

An architecture audit, instrumentation that makes the system observable end to end, and root cause analysis turned into a ranked action plan rather than a report.

Read the case study
TALK TO AN EXPERT

Secure and strengthen your IT system

Join the organisations that have strengthened their security posture with Adservio.

By submitting this form, you agree to our privacy policy.

Frequently asked questions

Probably more than you think. The directive takes France from a few hundred operators to ten to fifteen thousand entities, split between essential and important. The criteria are sector and size, and it pulls in subcontractors who did not consider themselves concerned.

Up to ten million euros or two per cent of worldwide turnover, whichever is higher, and a liability that reaches the board. The French ANSSI supervises, audits and receives incident declarations.

Because a tool protects what you point it at. EBIOS RM starts from the events the business fears, not from technical vulnerabilities, which avoids heavily securing a system whose downtime costs little and ignoring the one whose downtime costs a lot.

To discover what the plan ignores. Circular dependencies, a secret held in a vault that authenticates against the very directory being restored, an on-call engineer nobody can reach: none of it appears on a diagram. A plan never replayed describes an intention.

No, except the first time. An announced exercise measures the quality of the preparation, not of the reaction. What counts in a crisis is the delay between detection and the first order given, and that can only be measured unannounced.

No. You start with identity and privileged access, which carry most of the risk, then segment where a lateral move would do the most damage. A full network redesign before any benefit is the surest way never to finish.

The analysis takes 2 to 6 weeks depending on scope, sector and the applicable framework, NIS2 or DORA, and produces ranked feared events and a costed treatment plan. The first exercise under real conditions follows in 4 to 10 weeks, with negotiated recovery objectives and the runbook.