You end up with architects who know cloud, identity and attack paths, a risk process that runs, and the day to day back under control, so your time goes to strategy and the business.
In a large company, security is your accountability. The process everyone else is supposed to follow isn't really written down anywhere. You hear about the new cloud platform the week it goes live, and whether it's safe is still your call to make, alone. That's the part I work on with you: getting the process written down, and training the people around you until asking the security question becomes their reflex too. Less of it ends up on your desk.
Your consultants find vulnerabilities well, but they aren't yet the profile a client's CISO wants leading the engagement. A client asks for someone senior, you have nobody free to put forward, and the mission goes to another firm. That's what I work on with your consultants: the technical depth, and the way a security decision gets made and defended in front of a client. The next senior profile you put forward is one you already employ.
Tell me your situation and I'll tell you where to start: the training, the custom IT risk management software, or the security consulting and coaching retainer.
Short on time? The whole argument, out loud, in 90 seconds.
Cyber risk management and Secure by Design don't get installed by a slide deck. People need to learn the reasoning, then they need something to run it with, and then they need someone to call the first few times it gets hard. Companies use one of these, or all three.
A four-week program for consultants and in-house engineers. They learn to structure a security posture instead of only finding problems, and they finish on a real engagement with me alongside them.
See the program ↓Risk Expert, the software I built to run risk assessments, keep a risk register your executive committee will actually read, and hold the Secure by Design checkpoints on every project.
See Risk Expert →Ongoing help on live work. I review the deliverables before they go out, prepare your people for the conversations that decide things, and sit in the reviews that matter.
Talk it through →Nothing on this list is theory I haven't lived myself inside large organizations and as a consultant. Each phase builds on the last. Each one produces a deliverable they keep.
Before you can protect anything, you need to understand what you're protecting and why. Most security people skip this and spend years fighting the wrong battles.
The CIA triad. Impact types: financial, operational, reputational, legal, physical. Real incident stories from 15 years inside enterprises: employees deleting servers, CISOs spying on CEOs, phishing attacks on Christmas Eve, call centers stealing customer data.
Then we go wider: every attack vector attackers actually use against Windows endpoints, Linux servers, Active Directory, and cloud infrastructure (Azure, GCP, M365), and the countermeasures (preventive, detective, corrective) that neutralize each one.
By the end of this phase your people will see the full spectrum of what can go wrong, know how attackers move on every major surface, and evaluate each risk by probability and impact.
Ask me for the sample case study On request →An example of the course material for this phase: how to audit a multicloud environment, every attacker technique paired with the control that stops it. This is the one I don't publish. I don't want AI assisted script kiddies reading it, because a complete intrusion chain written out step by step gives them far too much power. Ask me for it and I'll send it to you.
How to become the person everyone consults before making IT decisions. This is what turns a security professional into someone the business cannot route around.
How to get informed early about IT needs. How to evaluate risks of proposed solutions. How to propose security measures that get accepted. How to get formal risk acceptance from business owners. The documentation that saves your career the day something breaks.
We learn the process by dissecting the disasters that happen when it's missing: the first CISO who discovers shadow IT across the entire company, the security approval given over coffee that leads to a breach, the VPN failure costing 250,000 euros per day. Each case comes from inside enterprises I've lived through, and we rehearse the conversations against real stakeholders.
Your people will walk out of this phase running the exact process that turns them from "the security guy" into the security checkpoint no project can bypass.
Read the sample case study PDF · 4 pages ↗One of the cases we work through: the first CISO of a remote e-commerce start-up who finds shadow IT everywhere, and the moves that put security back in the room before the decision.
The 2026 architect problem: companies are racing to deploy AI agents inside IT support. Almost none have risk-analyzed them. This is the exact question your team will be asked to answer.
Identify the threat actors: the prompt injection attacker, the malicious end-user, the compromised third-party connector, the over-permissioned agent itself. Map attack scenarios: data exfiltration via tool calls, privilege escalation through ticket creation, social-engineering the model into resetting the wrong password, leaking PII through chat history. Design the full control taxonomy (preventive, detective, corrective, deterrent, compensatory) against each scenario. Build the risk register a risk owner will actually sign.
I review the work line by line.
Your people will leave this phase with a complete AI-agent risk analysis they can show any client, plus a methodology that transfers to any IT project they'll encounter.
Read the sample deliverable PDF · 3 pages ↗That memo is the condensed version, what a project committee reads. The phase itself goes much deeper: every attack scenario and every control taken apart technically, one at a time. It can also run as a lab in Azure or GCP, where your people deploy a real helpdesk agent and then secure it.
The last phase is different. No exercises. No structured content.
Your employees bring a real task from their current job or client engagement. We work on it together, me alongside them, not ahead of them. I watch how they think, where they hesitate, what they miss. I ask the questions that help them find the answer, rather than giving it.
This is where the framework becomes instinct. And the only way that happens is on real work, under real conditions.
The whole program in a single document, from the four phases to what your teams walk away able to do. Made to be forwarded to whoever else in your organization should see it.
1-on-1 or Small Group · 4-Week Program · Remote
I've spent fifteen years in cybersecurity, inside large and medium organizations across sectors: finance, retail, industry, public services, high-tech startups. I started as a consultant (IT financial auditor, compliance for internal control, forensic investigator, pentester, security analyst), then moved inside as a security architect. For the last 7 years I've been doing this for international retail companies across the globe (Americas, Europe, Asia, Africa, Australia), designing security for strategic projects: infrastructure core services, cloud and data platforms, API-first strategies, SAP migrations, and more.
I've taught this Secure by Design methodology at Paris 1 Panthéon-Sorbonne. I also build the software behind this work: Risk Expert, the tool I use to run risk assessments and Secure by Design reviews, and dmarc-expert.com, an email security SaaS used by large companies.
I know how hard it is to get security taken seriously before something breaks. I know what it takes to shift a team's habits.
This doesn't promise miracles. It gives your people a structured path and someone to work through it with them, and it leaves the result inside your company instead of inside a supplier's.
If they put the work in, the change is visible. If they don't, no program will fix that. That's the deal, and it's the only one I'd ever offer you.
Five situations your people will face. Pick the answer that honestly reflects what your team would do, not what the policy says. At the end you'll see how much of your own position is riding on their judgment. No email required, nothing saved.
Security consultants, in-house security engineers, or technical IT generalists who are expected to give security guidance but haven't been trained to structure it. They need to be technically comfortable but don't need to be senior. The program works best when they have at least one current project or client context to bring to the work.
If you can hire a senior security architect, hire one. The profile is scarce and expensive at any headcount, and the people who have it are already placed. So the realistic hire is a junior, and a junior needs exactly the thing this installs.
A consulting firm is the other honest answer, and it is the right one when you need the work done once and done now. It is the wrong one when the same question is going to come back at every renewal, every new client, every new project. Then you are renting a capability you should own.
And if what you actually need is someone to run security for you rather than teach your team to, that is a different offer: fractional CISO, three days a month.
Yes. I work in small groups of two or three when the participants come from the same team or firm. More than that and the work loses its depth: everyone needs real feedback on their actual reasoning, not a group presentation.
Roughly half a day per week for the structured phases, plus whatever time they put into the exercises. It's designed to run alongside their current work, not replace it.
Remote, via video call and shared documents. If you're based near the North of Spain, the South of France, or close to an international airport and prefer in-person for some sessions, that's something we can discuss.
You'll see it in how your people talk about security decisions, and how their clients respond. The clearest signal is when a project team starts consulting them before a problem appears, rather than after. That shift doesn't happen overnight, but it's visible within 3 months.
French, English, or Spanish. Most participants from French firms prefer French, but the written deliverables are often in English. We adapt to what's most useful for your team and your clients.
Other languages are possible. For those, I delegate to senior security architects in my international network: people I know personally and trust to deliver at the same level.
I've been a consultant inside a lot of companies. Finance, retail, industry, public services, startups. What works in one of them fails in the next, and I know where the difference comes from.
Or send me a message if you prefer.
Free, and no commitment after it. I'll tell you plainly if I think I can help or not.