What I actually do.

I take the people you already have and bring them up to security architect level, on your own projects.

You end up with architects who know cloud, identity and attack paths, a risk process that runs, and the day to day back under control, so your time goes to strategy and the business.

Fabien Soulis
that's me 👋
Two kinds of company call me.
In-house

In a large company, security is your accountability. The process everyone else is supposed to follow isn't really written down anywhere. You hear about the new cloud platform the week it goes live, and whether it's safe is still your call to make, alone. That's the part I work on with you: getting the process written down, and training the people around you until asking the security question becomes their reflex too. Less of it ends up on your desk.

Consulting firms

Your consultants find vulnerabilities well, but they aren't yet the profile a client's CISO wants leading the engagement. A client asks for someone senior, you have nobody free to put forward, and the mission goes to another firm. That's what I work on with your consultants: the technical depth, and the way a security decision gets made and defended in front of a client. The next senior profile you put forward is one you already employ.

Tell me your situation and I'll tell you where to start: the training, the custom IT risk management software, or the security consulting and coaching retainer.

Let's talk
A message. No sales deck, just a conversation.

Short on time? The whole argument, out loud, in 90 seconds.

three ways this works

Capability, tools, and support. One method behind all three.

Cyber risk management and Secure by Design don't get installed by a slide deck. People need to learn the reasoning, then they need something to run it with, and then they need someone to call the first few times it gets hard. Companies use one of these, or all three.

Tools
Run the process

Risk Expert, the software I built to run risk assessments, keep a risk register your executive committee will actually read, and hold the Secure by Design checkpoints on every project.

See Risk Expert
Support
When it gets real

Ongoing help on live work. I review the deliverables before they go out, prepare your people for the conversations that decide things, and sit in the reviews that matter.

Talk it through
the capability pillar

Four weeks. Real projects.

Nothing on this list is theory I haven't lived myself inside large organizations and as a consultant. Each phase builds on the last. Each one produces a deliverable they keep.

1
Week 1

Think like an attacker, defend like a strategist

Before you can protect anything, you need to understand what you're protecting and why. Most security people skip this and spend years fighting the wrong battles.

The CIA triad. Impact types: financial, operational, reputational, legal, physical. Real incident stories from 15 years inside enterprises: employees deleting servers, CISOs spying on CEOs, phishing attacks on Christmas Eve, call centers stealing customer data.

Then we go wider: every attack vector attackers actually use against Windows endpoints, Linux servers, Active Directory, and cloud infrastructure (Azure, GCP, M365), and the countermeasures (preventive, detective, corrective) that neutralize each one.

By the end of this phase your people will see the full spectrum of what can go wrong, know how attackers move on every major surface, and evaluate each risk by probability and impact.

Ask me for the sample case study On request

An example of the course material for this phase: how to audit a multicloud environment, every attacker technique paired with the control that stops it. This is the one I don't publish. I don't want AI assisted script kiddies reading it, because a complete intrusion chain written out step by step gives them far too much power. Ask me for it and I'll send it to you.

2
Weeks 2 – 3

Security By Design: becoming the security checkpoint

How to become the person everyone consults before making IT decisions. This is what turns a security professional into someone the business cannot route around.

How to get informed early about IT needs. How to evaluate risks of proposed solutions. How to propose security measures that get accepted. How to get formal risk acceptance from business owners. The documentation that saves your career the day something breaks.

We learn the process by dissecting the disasters that happen when it's missing: the first CISO who discovers shadow IT across the entire company, the security approval given over coffee that leads to a breach, the VPN failure costing 250,000 euros per day. Each case comes from inside enterprises I've lived through, and we rehearse the conversations against real stakeholders.

Your people will walk out of this phase running the exact process that turns them from "the security guy" into the security checkpoint no project can bypass.

Read the sample case study PDF · 4 pages

One of the cases we work through: the first CISO of a remote e-commerce start-up who finds shadow IT everywhere, and the moves that put security back in the room before the decision.

3
Week 4

Risk analysis of an AI helpdesk agent

The 2026 architect problem: companies are racing to deploy AI agents inside IT support. Almost none have risk-analyzed them. This is the exact question your team will be asked to answer.

Identify the threat actors: the prompt injection attacker, the malicious end-user, the compromised third-party connector, the over-permissioned agent itself. Map attack scenarios: data exfiltration via tool calls, privilege escalation through ticket creation, social-engineering the model into resetting the wrong password, leaking PII through chat history. Design the full control taxonomy (preventive, detective, corrective, deterrent, compensatory) against each scenario. Build the risk register a risk owner will actually sign.

I review the work line by line.

Your people will leave this phase with a complete AI-agent risk analysis they can show any client, plus a methodology that transfers to any IT project they'll encounter.

Read the sample deliverable PDF · 3 pages

That memo is the condensed version, what a project committee reads. The phase itself goes much deeper: every attack scenario and every control taken apart technically, one at a time. It can also run as a lab in Azure or GCP, where your people deploy a real helpdesk agent and then secure it.

4
Shadowing

Real work, under real conditions

The last phase is different. No exercises. No structured content.

Your employees bring a real task from their current job or client engagement. We work on it together, me alongside them, not ahead of them. I watch how they think, where they hesitate, what they miss. I ask the questions that help them find the answer, rather than giving it.

This is where the framework becomes instinct. And the only way that happens is on real work, under real conditions.

The full program in one PDF PDF · 3 pages

The whole program in a single document, from the four phases to what your teams walk away able to do. Made to be forwarded to whoever else in your organization should see it.

1-on-1 or Small Group · 4-Week Program · Remote

where the knowledge lands

The knowledge taught in this program is applied inside these organizations.

Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
the question I'd ask too

Why me, and not a consulting firm or a training company.

I've spent fifteen years in cybersecurity, inside large and medium organizations across sectors: finance, retail, industry, public services, high-tech startups. I started as a consultant (IT financial auditor, compliance for internal control, forensic investigator, pentester, security analyst), then moved inside as a security architect. For the last 7 years I've been doing this for international retail companies across the globe (Americas, Europe, Asia, Africa, Australia), designing security for strategic projects: infrastructure core services, cloud and data platforms, API-first strategies, SAP migrations, and more.

I've taught this Secure by Design methodology at Paris 1 Panthéon-Sorbonne. I also build the software behind this work: Risk Expert, the tool I use to run risk assessments and Secure by Design reviews, and dmarc-expert.com, an email security SaaS used by large companies.

I know how hard it is to get security taken seriously before something breaks. I know what it takes to shift a team's habits.

This doesn't promise miracles. It gives your people a structured path and someone to work through it with them, and it leaves the result inside your company instead of inside a supplier's.

If they put the work in, the change is visible. If they don't, no program will fix that. That's the deal, and it's the only one I'd ever offer you.

Fabien
Security Architect · 15 years in enterprise IT security
a 2-minute gut check

When your team makes the wrong call, you're the one the CEO calls.

Five situations your people will face. Pick the answer that honestly reflects what your team would do, not what the policy says. At the end you'll see how much of your own position is riding on their judgment. No email required, nothing saved.

before you reach out

A few things people ask.

Who exactly is this for in my organization?

+

Security consultants, in-house security engineers, or technical IT generalists who are expected to give security guidance but haven't been trained to structure it. They need to be technically comfortable but don't need to be senior. The program works best when they have at least one current project or client context to bring to the work.

Why this rather than hiring someone, or bringing in a consulting firm?

+

If you can hire a senior security architect, hire one. The profile is scarce and expensive at any headcount, and the people who have it are already placed. So the realistic hire is a junior, and a junior needs exactly the thing this installs.

A consulting firm is the other honest answer, and it is the right one when you need the work done once and done now. It is the wrong one when the same question is going to come back at every renewal, every new client, every new project. Then you are renting a capability you should own.

And if what you actually need is someone to run security for you rather than teach your team to, that is a different offer: fractional CISO, three days a month.

Can several people go through it at the same time?

+

Yes. I work in small groups of two or three when the participants come from the same team or firm. More than that and the work loses its depth: everyone needs real feedback on their actual reasoning, not a group presentation.

How much time does it take per week, for my team?

+

Roughly half a day per week for the structured phases, plus whatever time they put into the exercises. It's designed to run alongside their current work, not replace it.

What's the format?

+

Remote, via video call and shared documents. If you're based near the North of Spain, the South of France, or close to an international airport and prefer in-person for some sessions, that's something we can discuss.

How will I know it worked?

+

You'll see it in how your people talk about security decisions, and how their clients respond. The clearest signal is when a project team starts consulting them before a problem appears, rather than after. That shift doesn't happen overnight, but it's visible within 3 months.

In which language do you deliver?

+

French, English, or Spanish. Most participants from French firms prefer French, but the written deliverables are often in English. We adapt to what's most useful for your team and your clients.

Other languages are possible. For those, I delegate to senior security architects in my international network: people I know personally and trust to deliver at the same level.

Fabien Soulis
let's talk 👋

Before anything else, a free diagnostic of your context.

I've been a consultant inside a lot of companies. Finance, retail, industry, public services, startups. What works in one of them fails in the next, and I know where the difference comes from.

  • A call: you tell me how security decisions really get made, where your teams lose ground, what your clients and auditors are asking for.
  • A written action plan: how a Security by Design process fits your context, and in which order to build it.
  • The point of it: give your security teams back their visibility, their control, and their soft power.
Ask for your free diagnostic

Or send me a message if you prefer.

Free, and no commitment after it. I'll tell you plainly if I think I can help or not.