Cybersecurity Lab — Saint-Pierre-des-Corps, France

Find the gap
before someone
else does.

We test your infrastructure the way attackers would. Then we help you close what we find — and stay compliant with NIS2 and GDPR while doing it. The specialists who sign your contract are the ones who do the work.

0 Operating since 2021
0 Engagements completed
0 In-house delivery

What brings you here?

0
Engagements delivered
0
Certified specialists
0
EU countries served
0
Subcontractors used

What it looks like in practice

There are things we do differently — not as selling points, but because we think they produce better results.

No subcontracting

The people named in your contract run the engagement. No handoffs to freelancers or partner firms you've never met.

Findings your team can act on

Reports written for developers and IT managers, not just compliance officers. Each finding includes a remediation path, not just a severity score.

NIS2 and GDPR aligned

We scope every engagement with the regulatory context in mind, so pentest evidence also supports your compliance documentation.

Certifications, not claims

OSCP, CEH, ISO 27001 Lead Auditor, CompTIA Security+. Credentials that mean something in court and in front of a client's audit committee.

From first call to final report

01

Scope definition

We discuss your environment, regulatory obligations, and risk tolerance. No upselling — if something is outside what you actually need, we'll say so.

02

Authorised engagement

Testing begins only after written authorisation is signed. We follow OWASP, PTES, and OSSTMM methodologies depending on scope.

03

Actionable deliverables

You receive a findings report, executive summary, and a prioritised remediation checklist. We're available for a debrief call with your team.

Standards we work against

Every engagement produces documentation that contributes to your compliance posture — not just a technical report filed away in a drawer.

NIS2 Directive
Article 21 security measure requirements and incident reporting obligations
ISO 27001
Information security management system gap analysis and Annex A controls
GDPR Security
Article 32 technical security measures and data breach risk assessment
DORA (FS sector)
Digital Operational Resilience Act — ICT risk and TLPT requirements
OWASP Top 10
Web application and API security testing against current threat categories
PTES / OSSTMM
Structured penetration testing methodology with reproducible and auditable results

Talk to the team that does the work

Free initial assessment. We'll look at your current setup, identify what actually needs attention, and tell you what we'd do — and what we'd skip.