Blog

Our experts' perspective

Analysis, regulatory explainers and field experience in cybersecurity, so you can decide with your eyes open.

The articles themselves are published in French. Titles and summaries below are translated.

Phishia vs Traditional
consulting

Why Phishia is not a cyber consulting firm like the others

Consulting plus the AI-driven GALEA platform: what the Phishia model changes compared with a traditional firm (analysis, cost, autonomy).

GALEA vs Tenacy

GALEA or Tenacy: which GRC platform should you choose to manage cyber compliance?

Sovereign AI automation, frameworks, human support and pricing: the full comparison of the two French GRC platforms.

DPIA: why the impact assessment is local government's legal shield in 2026

In a digital landscape where cyberattacks on the public sector keep multiplying, compliance can no longer be seen as a burden…

CTI: why intelligence is your best investment of 2026.

When it comes to cybersecurity, budgets are often built around “reaction”: firewalls, antivirus, tools that detect after the intrusion. And yet…

OSINT & ASM: do you know your company as well as the attackers do?

There is a chilling saying in cybersecurity: “Attackers only need to be right once. You have to be right 100% of the time.” But…

The cyber domino effect. Why EASA and Part IS oblige you to monitor your suppliers.

Aviation is a model of reliability, safety and traceability. Yet it has become a prime target for cybercriminals, not by…

Your password is worth $10: the underground economy of stealer logs

Forget the image of the hoodie-wearing hacker typing neon-green code all night to “brute-force” your servers. In 2025 the reality is…

CTI and local authorities: when a single domain name exposes the whole organisation

In a local authority everyone works under the same domain name: @ville-X.fr, @departement-Y.fr, @metropole-Z.fr… Staff, departments,…

BCP / DRP in medico-social organisations: turning a crisis into a managed incident

Cyberattack, major IT outage, fire, flood, staff shortage… In a hospital or a health charity, every interruption to operations…

What is the dark web, and why can your data end up there?

The dark web is often described as a mysterious place reserved for hackers. In reality it is above all a space where stolen sensitive information…

How CTI could have prevented a cyberattack

When a large public organisation (a city, a hospital, a metropolitan authority…) suffers a massive cyberattack, the prevailing impression is often: “They came at us…

The CaRE programme – Domain 2: funding for your medico-social organisation.

Hospitals and healthcare organisations have become prime targets for cyberattacks: ransomware, data theft, critical services brought to a halt……

Running a cyber crisis management exercise for a hospital

Operating theatre paralysed, hospital information system down, A&E overwhelmed, calls from the media and the health authority one after another… This is what more and more teaching hospitals and centres…

Protecting workstations and infrastructure: a vital issue for hospitals and health charities

In a hospital or a health charity everything now depends on the information system: patient records, admissions, pharmacy, imaging, payroll,…

Cyber Threat Intelligence (CTI): a simple definition and concrete examples.

Cyber threat intelligence (CTI) is the ability to collect, process and analyse threat information in order to decide faster and better.…

Everything you need to know about ISO 27001

Why ISO 27001 still interests everyone. Your clients want evidence, not promises. ISO 27001 provides an internationally recognised framework…

NIS2 & DORA: EU obligations, key differences, a concrete roadmap

Why NIS2 and DORA are so widely discussed. Two European texts, two neighbouring objectives: reduce the impact of digital incidents and make organisations…

IEC 62443: ISO 27001 adapted… for industry

The idea in one sentence: IEC 62443 is the industrial equivalent of ISO 27001 — the same logic of risk management and controls… with extra constraints…

PART-IS: civil aviation's cyber course

What PART-IS changes, who it applies to and how to prepare. PART-IS in a nutshell: it is the first European regulation to mandate an ISMS (ISMS/ISO…

10 simple tips for spotting email attacks (phishing and ransomware)

Phishing and ransomware have become cybercriminals' weapons of choice. And their main way in is still often… our inbox…

The most common cyberattack scenarios against small and mid-sized companies

Why have small and mid-sized companies become the favourite targets of cyberattacks? They now find themselves on the front line…

Understanding EDR, SIEM, SOAR and XDR: how cyber defence fits together

Cybersecurity vocabulary can feel like a jungle of acronyms. Yet grasping the difference between EDR, SIEM, SOAR and XDR is essential: their role…

Antivirus vs EDR: why companies need to shift paradigm

For a long time traditional antivirus was the first line of corporate defence against IT threats. Easy to deploy,…

Everything you need to know about ISO 42001

ISO 50001 is an international standard established by the International Organization for Standardization (ISO) to provide guidelines on implementing…

Writing security policies

In a constantly changing business world, clear policies and procedures are essential to ensure smooth operation and compliance…

Best practice for securing Wi-Fi networks

Corporate Wi-Fi networks have become essential to business connectivity, enabling smooth communication and fast access to…

Securing premises

What does securing premises mean? It consists of putting physical security measures in place to protect…

Securing the mailbox

Email has become an essential part of professional communication, but it is also one of the main targets of…

Securing mobile devices (MDM)

What does securing mobile devices mean? In an increasingly connected world, where mobile devices have become essential tools for…

Why and how should you back up your company's data?

In the constantly changing digital landscape of business, preserving data is far more than a precaution; it is a necessity…

Running a cyber crisis management exercise

In a constantly changing digital environment, cyber crisis management has become imperative for companies keen to protect their…

Carrying out a risk assessment

What is a risk assessment? In cybersecurity, a risk assessment is a methodical evaluation of potential threats and…

What is a VPN?

The corporate VPN, everything you need to know in 2024. In today's digital world, online security and privacy are major concerns for…

Business Continuity Plan (BCP) & Disaster Recovery Plan (DRP)

In a world where disruption is ever more frequent and unpredictable, a company's ability to keep critical operations running and to…

Pentest

In today's digital landscape, where cyber threats never stop evolving, it is crucial for companies to test their security posture regularly…

Deploying detection tools

What is a detection tool? A detection tool is software or hardware designed to identify, monitor or report the presence or…

Social engineering

In the complex world of cybersecurity, social engineering has emerged as one of the most formidable tactics cybercriminals use to…

ISMS implementation

In a constantly changing digital world, information security is becoming a crucial issue for every organisation. Implementing a…

Access management

Why is access management crucial to your company's security? In a world where cyber threats have become commonplace and where…

Two-factor authentication

What is two-factor authentication? Two-factor authentication, also known as 2FA or…

Communicating during a cyber crisis: what should you say?

Managing communication is crucial during a cyber crisis. An effective, well-orchestrated response can soften the negative impact on…

Phishing campaign

What is phishing? Phishing is a form of cyberattack in which criminals try to deceive users by impersonating…

Secure messaging applications in business in 2024

France's then Prime Minister, Élisabeth Borne, recently made a bold choice to strengthen the security of government communications. She ordered…

Zero Trust, a permanent challenge

Zero Trust security has become an increasingly popular approach to protecting corporate networks and data against growing threats…

Micro-businesses: securing yourself, an imperative for lasting prosperity

Micro-businesses are increasingly exposed to cybersecurity risks, and need particular attention to protect their…

My CISO is away — what now?

On sick leave, on holiday, overloaded, or simply no CISO at all: how do you handle these transition periods in today's digital environment?

Choose an outsourced CISO

The CISO role plays a crucial part in protecting an organisation's data and digital assets…

Small and mid-sized companies: the 2024 cyber security guide

Small and mid-sized companies, the engine of the local economy, increasingly face cyber threats that can jeopardise their business. Cybersecurity is therefore becoming…

The main cyber threats facing companies in 2024

In a constantly changing digital landscape, companies face a multitude of online threats, from sophisticated attacks by…

What is OSINT (Open Source Intelligence)?

Open Source Intelligence (OSINT) is attracting keen interest among security leaders. What exactly does this field cover and what does it bring…

Passwords: the guide to creating strong passwords in 2024

In today's digital world, where every click and every keystroke can represent a potential security weakness, protecting…

Artificial intelligence in the service of cybersecurity

In this article we explore the growing role of artificial intelligence (AI) in cybersecurity. We look at the advances…

Emerging trends in cybersecurity

Cybersecurity is a constantly evolving field, with new threats and challenges appearing every year. In 2024 several major trends…

The security of connected devices

In a constantly changing digital landscape, the rise of connected devices represents a major technological advance. These smart devices,…

The 2024 Olympics: the great threat

As the world prepares to celebrate the 2024 Olympic Games in Paris, a shadow hangs over companies everywhere: the growing threat to…

Mid-cap companies: the 2024 cybersecurity guide

In today's digital world, cybersecurity has become a major issue for every organisation, and particularly for mid-cap…

Online reputation: the great threat hanging over companies

In the current digital era, where commercial interactions and information exchange happen largely online, a company's reputation…

Cyberbullying: how is that cybersecurity?

The digital world offers a myriad of opportunities to connect and collaborate but, unfortunately, it also carries inherent risks, such as…

CISOs: communicating with your teams & your executives

Communication between the Chief Information Security Officer (CISO) and the executive team is crucial to securing systems…