The people doing the work

ThreatVigil Labs was founded in 2021 in Saint-Pierre-des-Corps, France. We're a small team of certified security specialists. The people listed here are the ones who run your engagement — not account managers, not subcontractors.

Luc Bertrand
Founder & Lead Penetration Tester

Luc spent eight years in network security roles at a French telecoms operator before founding ThreatVigil Labs. His background is in infrastructure and internal network assessments, with a focus on Active Directory attack paths and lateral movement techniques. He leads all external and internal infrastructure engagements.

OSCP CompTIA Security+ CEH
Nadia Kowalczyk
Compliance Lead & ISO 27001 Auditor

Nadia joined ThreatVigil Labs in 2022 after five years in information security consulting at a Brussels-based firm, where she led ISO 27001 implementation projects for healthcare and financial sector clients. She manages all compliance audit engagements and is the team's primary contact for NIS2 and GDPR security reviews.

ISO 27001 Lead Auditor CompTIA Security+
Arnaud Tessier
Web Application Security & Training

Arnaud worked as a software developer for six years before moving into application security. His development background makes him effective at identifying business logic vulnerabilities that automated scanners routinely miss. He also leads the security awareness training and tabletop exercise programmes.

OSCP CompTIA Security+
Fatou Diallo
Threat Intelligence & Reporting

Fatou handles threat intelligence research and report writing for ThreatVigil Labs. She previously worked in a CERT environment tracking threat actors targeting French critical infrastructure. Her role is to ensure that technical findings are placed in accurate risk context and that the intelligence behind each engagement reflects current attacker behaviour.

CompTIA Security+

Why we keep the team small

Larger cybersecurity firms often win contracts and distribute the work to junior consultants or subcontracted freelancers. The senior specialist you met in the sales call may not be the person who reviews your findings report.

At ThreatVigil Labs, every engagement involves the people named above. We don't have the capacity to run fifty concurrent projects — which is intentional. The limitation is also a guarantee.

We don't have case studies or named client references on this site. Our clients work in sectors where public acknowledgement of a security engagement is a liability. We can provide confidential reference conversations for serious procurement discussions.

Speak directly with the technical team

When you get in touch, you'll talk to Luc or Arnaud — the people who would run the engagement. Not a business development team.