Cyber Resilience
Zero Trust cybersecurity augmented by AI: EBIOS RM risk analysis, continuity proven by real exercises, structured crisis management, aligned with NIS2 and DORA.
A posture is only worth the number of times it has been replayed.
A continuity plan that has never been executed describes an intention. It holds on paper, it names owners, and it collapses at the first real exercise because a dependency no diagram showed turns up at the worst moment.
So we work the other way round. Risk analysis ranks by business impact, recovery objectives are negotiated service by service, then everything is replayed under production conditions, with no warning. What breaks during the exercise will not break on the day of the incident.
What we do
Four workstreams so resilience is demonstrated rather than announced.
EBIOS RM risk analysis
The ANSSI method applied to the real perimeter rather than to one application: feared events ranked by business impact, risk sources, and a costed treatment plan.
ranked by business impact, not by technical severity
- Feared events before technical scenarios
- A grid reusable from one entity to the next
- A treatment plan that can be arbitrated, not a report
Zero Trust
No implicit trust: every request verified, every access logged, every connection encrypted. Microsegmentation, identity-aware proxy, least privilege and strong authentication.
applied to network, identity, application and data
- Microsegmentation and least privilege
- Access logged, administrators included
- One directory of record, and only one
Proven continuity
Recovery objectives negotiated service by service, a runbook that names the roles, then an exercise under real conditions. An RTO that has never been replayed commits nobody.
in production, on the worst plausible scenario rather than the most likely
- RTO and RPO per service, not for the system
- A runbook that says who decides
- The gap to the objective measured, then closed
Detection and response
Continuous monitoring, signal correlation and tooled response. What makes the difference in a crisis is not detection but the delay between detection and the first order given.
decision time is measured just like detection time
- Detection, investigation and response, continuously
- Decision time measured as well
- Blameless post-mortems
What you get
One project runs through the four deliverables below: the recovery exercise of an operator in scope of NIS2. Each line states what is actually handed over, in the order it is handed over.
The perimeter and its recovery objectives
An RTO and an RPO per service, with dependencies declared. A single objective for the whole system never survives the exercise, because it ignores that some services wait on others.
The scenario, chosen for what it reveals
The worst plausible case rather than the most likely: online backups presumed compromised, the directory unavailable, and no shortcuts allowed. It is the prohibitions that make the exercise useful.
The crisis runbook
What is missing in a crisis is not competence, it is knowing who decides. The runbook names roles, lists the decisions that cannot be delegated, and sets the communication rhythm even when there is nothing new.
The exercise, in production and unannounced
Three services hold their objective, the fourth does not. What the exercise uncovers appears on no architecture diagram, and that is exactly why it had to be replayed for real.
How we deliver
Analyse
depending on scope, sector and the applicable framework, NIS2 or DORA
- EBIOS RM risk analysis
- Feared events ranked by business impact
- A costed, negotiable treatment plan
Put to the test
depending on the number of critical services and the depth of the scenario
- RTO and RPO negotiated service by service
- Crisis runbook with named roles
- A first exercise under real conditions
Harden
depending on the number of systems and accesses to rework
- Zero Trust extended to access and networks
- Detection and response tooled up
- Gaps from the exercise fixed and replayed
Hold
service commitment defined with you
- Exercises replayed, not just documented
- Continuous monitoring and response
- Compliance held between two audits
What 2026 requires
Enterprise Security
No implicit trust, continuous verification at every layer of the stack: network, identity, application and data.
EBIOS RM & ISO 27005
The ANSSI method for the analysis, ISO 27005 for the framework. That is what makes a result comparable from one entity to the next, as on the method industrialised for Engie.
An RTO proven, not declared
A recovery objective negotiated per service, then verified by a real exercise. An RTO that has never been replayed commits nobody.
NIS2 & GDPR
Full regulatory compliance with risk mapping and action plans.
SOC & SIEM 24/7
Continuous detection, investigation and response to security incidents.
Platforms in Production

A risk analysis on the whole information system
EBIOS RM, the ANSSI method · GDPR-compliant
A federation holding health and social data on millions of members, where a risk analysis cannot stop at the perimeter of one application and where compliance has to hold over time rather than on audit day.
An EBIOS RM analysis across the whole information system, feared events ranked by business impact rather than by technical severity, and a GDPR alignment carried by the same mapping instead of a separate exercise.

A reusable EBIOS RM method for group cloud compliance
ISO 27005 compliant · Aligned with the group security policy
A global energy group where each entity ran its own cloud risk analysis, with results nobody could compare and a security policy that stayed a document rather than a practice.
An EBIOS RM method industrialised into something reusable: the same grid, the same scales and the same deliverables from one entity to the next, aligned with ISO 27005 and with the group policy.

GOC 2.0: an architecture audit on a critical system
Dynatrace instrumentation · Root cause analysis and action plan
An operations control system on which national rail traffic depends, where a slowdown is not a support ticket but trains held at a standstill, and where the cause of an incident had to stop being a matter of opinion.
An architecture audit, instrumentation that makes the system observable end to end, and root cause analysis turned into a ranked action plan rather than a report.
Insights & Perspectives

Securing LLMs in 2026: attack vectors and self-hosted defense
A map of the 6 modern attack vectors against LLMs (prompt injection, GCG, PoisonedRAG, MCP exploit, agentic) and the build of a self-hosted defensive layer with a fine-tuned ModernBERT, at 35 ms latency and under $1 of training.

DevSecOps: 10 best practices for building security in from the start
DevSecOps bridges the gap between developers, security and operations by integrating security throughout the application lifecycle. Ten best practices to ship fast without sacrificing security.

Cloud security: challenges and solutions
The cloud brings scalability, cost reduction and fast deployment, but security remains critical. The five biggest cloud security challenges and the best practices to regain control of your environments.
Secure and strengthen your IT system
Join the organisations that have strengthened their security posture with Adservio.
Frequently asked questions
Probably more than you think. The directive takes France from a few hundred operators to ten to fifteen thousand entities, split between essential and important. The criteria are sector and size, and it pulls in subcontractors who did not consider themselves concerned.
Up to ten million euros or two per cent of worldwide turnover, whichever is higher, and a liability that reaches the board. The French ANSSI supervises, audits and receives incident declarations.
Because a tool protects what you point it at. EBIOS RM starts from the events the business fears, not from technical vulnerabilities, which avoids heavily securing a system whose downtime costs little and ignoring the one whose downtime costs a lot.
To discover what the plan ignores. Circular dependencies, a secret held in a vault that authenticates against the very directory being restored, an on-call engineer nobody can reach: none of it appears on a diagram. A plan never replayed describes an intention.
No, except the first time. An announced exercise measures the quality of the preparation, not of the reaction. What counts in a crisis is the delay between detection and the first order given, and that can only be measured unannounced.
No. You start with identity and privileged access, which carry most of the risk, then segment where a lateral move would do the most damage. A full network redesign before any benefit is the surest way never to finish.
The analysis takes 2 to 6 weeks depending on scope, sector and the applicable framework, NIS2 or DORA, and produces ranked feared events and a costed treatment plan. The first exercise under real conditions follows in 4 to 10 weeks, with negotiated recovery objectives and the runbook.
