— Cybersecurity · NIS2 · Expert Cyber
Cybersecurity — anticipate rather than endure.
60% of companies hit by a major cyberattack go out of business within 12 months (source CPME, France). 80% of compromises remain avoidable with proper cyber hygiene. BISPRO audits what's exposed, hardens what needs to be hardened, and prepares you for NIS2 — accredited Expert Cyber by the French State.
— State recognition
BISPRO is accredited Expert Cyber and listed on Cybermalveillance.gouv.fr
Expert Cyber label — issued by Cybermalveillance.gouv.fr and AFNOR (France). Certifies our expertise on 7 cyber themes for SMBs and public bodies. Valid 2024 — 2026.
Listed on Cybermalveillance.gouv.fr — the French State platform (attached to ANSSI and the Ministry of the Interior) for assistance to cyber-incident victims. Listing reserved to qualified providers.
— Technical cyber certifications
— The numbers behind the urgency
Three figures to grasp the stakes.
60%
Of SMBs hit by a major cyberattack go out of business within 12 months (CPME, ANSSI).
17 days
Average business interruption after a ransomware attack on a French SMB (Sophos study).
+400%
Increase in ransomware attacks since 2020 on organisations under 250 employees (ANSSI).
01 · DIAGNOSTIC
Audit & diagnostic
Four assessment axes to map the cyber posture and prioritise remediations.
Organisational audit
Security policy, roles, processes, governance.
Technical audit
Active Directory, firewall, endpoints, servers, external exposure.
External attack surface
Mapping, OSINT, IP exposure, subdomains, orphan services.
Regulatory compliance
GDPR, NIS2, RGS, ANSSI hygiene measured and quantified.
02 · OFFENSIVE
Pentest & red team
We exploit technically to prove real risk — not just to tick boxes.
External pentest
Internet exposure, web apps, mail, leaks.
Internal pentest
AD, lateral movement, privilege escalation.
Simulated phishing
Targeted campaigns, awareness, click-rate measurement.
Deliverables
Executive report, technical report, priced remediation plan.
03 · HARDENING
Hardening
Four structuring workstreams. Measurable before / after.
Active Directory
Tiering, LAPS, gMSA, BloodHound / PingCastle audit.
Endpoints
EDR, GPO hardening, app whitelisting, USB control.
Firewall
Rule review, segmentation, centralised logging.
Backup
Isolation, immutability, documented restore tests.
04 · INCIDENT RESPONSE
Incident response
A rehearsed response plan. When it burns, we know what to do and in what order.
Rapid response
In hours, not days. Dedicated cyber on-call.
Containment & eradication
Targeted network cut, isolation of compromised accounts.
Recovery
Restore from validated backup, re-compromise avoided.
Post-mortem
Timeline, causes, recommendations. CNIL / ANSSI notification where required.
05 · COMPLIANCE
Regulatory compliance
NIS2, GDPR, ANSSI hygiene, cyber-insurance: we measure, we remediate, we document.
NIS2 readiness
BISPRO supports organisations and public bodies in Grand Est concerned by the NIS2 directive (transposed into French law in 2024). Positioning audit, gap analysis vs. ANSSI requirements, priced remediation plan, ISMS documentation, training, crisis exercises, 24-hour incident reporting to ANSSI.
GDPR compliance
Processing register, impact analysis (DPIA) for sensitive processing, exercise of rights, DPO training, sub-processor contracts, international transfers. Coordination with your internal or external DPO. 72-hour CNIL notification on incident.
ANSSI hygiene
The ANSSI hygiene guide lays out 42 basic but essential recommendations. BISPRO measures your current compliance, prioritises remediations by impact and proposes a 6–12 month execution plan with measurable indicators.
Cyber-insurance
Cyber-insurance contracts now require a minimum baseline: MFA, EDR, immutable backup, training, tested incident response plan. BISPRO documents your posture to ease underwriting or renewal at favourable conditions.
06 · FAQ
Frequently asked questions
Going further
— NIS2 readiness
Request a cyber audit.
ANSSI baseline, NIS2 posture, AD hygiene. Report in 10 business days.
Financing up to 63 months available* — *subject to approval

