Cybersecurity

A security posture you can defend.

Active Directory, Microsoft 365 and Azure audits, Zero Trust architecture, Defender and Sentinel, incident response: I raise your security level with clear priorities and measurable results.

Security audit

AD, M365, Azure: misconfigurations, inappropriate access, technical review and management review, detailed report.

Zero Trust architecture

Identities, devices, applications, data: a coherent framework measured against the CISA model.

Detection and response

Defender XDR, Sentinel, SOC integration, incident response plan, alert interpretation.

Active Directory

Secure (tiers, PAW, silos, LAPS) and modernise (hybrid identity, Cloud Sync, gradual decommissioning).

AI agents

Inventory, frame and monitor the agents and connectors acting with your data and identities.

Email

Anti-phishing filtering, SPF, DKIM and DMARC, awareness and simulations for your teams.

What I do for you

Cybersecurity

Audit

AD, M365, Azure audit

  • Technical review of identified findings
  • Management overview with presentation deck
  • Detailed report and prioritised action plan
Foundations

Active Directory: secure and modernise

  • Tiering model, admin workstations, authentication silos
  • On-premises and cloud restoration plan, incident readiness
  • Hybrid identity towards Entra ID and modernisation trajectory
New

Protecting against AI agents

  • Inventory of agents, connectors and related identities
  • Scope, least privilege, logging, guardrails
  • Detection of uncontrolled usage (shadow AI)
Email

Email security

  • SPF, DKIM, DMARC testing and remediation
  • Advanced anti-phishing and anti-spoofing filtering
  • Awareness and Phishing simulations
Strategy

Cybersecurity roadmap

  • Global strategy and frameworks: NIST, ISO, threat modelling
  • Entra, M365, Azure governance; Well-Architected and Cloud Adoption
  • CISO support, committees and indicators
On demand

Alert interpretation

  • Help reading the alerts from your detection tools
  • False positive / true positive qualification
  • On-demand technical back office

The method, applied

Six steps, one thread.

Containment, hardening, monitoring: the three-phase plan.

What is exposed, what is protected, what remains.

An agent is just one more identity: the same rigour applies.

Method

  1. 01Scoping

    Understand the need, the stakes and the constraints. Set the scope, the actors and the expected results.

  2. 02Audit

    Observe the current state without assumptions: configurations, usage, documents, interviews and tool-based measurements.

  3. 03Analysis

    Confront the findings with frameworks and your objectives. Measure the gaps, qualify the risks, prioritise.

  4. 04Design

    Design the target and the path to reach it: architecture, governance, budget, licences, milestones.

  5. 05Transcription

    Translate the target into operational documents your teams and vendors can execute without me.

  6. 06Delivery

    Present, get stakeholder sign-off, transfer knowledge and support the implementation.

Regain control after AD compromise

Three-phase recovery planCrisis
1 · ContainmentDone
2 · HardeningDone
3 · Monitoring and go-liveIn progress

Isolated bubble · Tiering · PAW · XDR · SIEM

Workshops and knowledge transfer

Dense, practical sessions that make your teams autonomous.

Privileged access hardening in Active Directory Securing identities and access in M365 Azure security best practices Defender and Sentinel solutions review Active Directory restoration plan, on-premises and cloud Privileged Access Workstation (PAW) Passwordless strategy Zero Trust architecture Preparing an incident response plan

Watch

What is moving on this topic

An automatic selection of recent articles from trusted sources, filtered to keep only what touches this specialty.

Loading the watch…

The CT Conseil briefing

Get this watch every week

One edition a week: the deadlines you must not miss, what is moving on Entra, Purview, Defender and compliance, and one practical tip. No advertising, one-click unsubscribe. Editions are written in French.

Gauge my level in 5 questions

Five questions to gauge your posture. Honesty recommended, nobody is watching.

Two minutes, no tricks. You leave with a level and concrete leads.

Question 1 of 5

AI agents and assistants in your organisation…

Secured? Let's move on to acceleration.

Trusted AI starts where security stops being a brake.