Founded by a pioneer of EU cyber security

Founder and CEO
Dr Cédric LÉVY-BENCHETON
- Created and led the Internet of Things security programme at ENISA, the European Union Agency for Cybersecurity, in 2014.
- Member of ENISA’s ad hoc working group on security architecture engineering and vulnerability management.
- PhD in Telecommunications from INSA Lyon, University of Lyon.
We don’t just interpret EU cyber security regulations. We helped build the foundations they are based on.
Our mission
Our mission is to make cyber work: practical product security that fits your business, your teams and the regulations you must meet.
We work with connected-product manufacturers from the five-person start-up to the multinational group, from North America to South-East Asia, and have taken their products through RED, EN 18031, EN 303 645 and, today, the Cyber Resilience Act.
How we work
We are a pure player in product cyber security, and we work at both ends of the organisation. With engineers and developers, we bridge the gap between rigid regulations and operational reality. With executives and compliance managers, we turn legal requirements from a hurdle into a strategic capability.
Every engagement integrates four dimensions, because a control without a process, a process without a tool, or a tool without a strategy does not survive the next product:
- People: the skills and roles that carry product security, from engineering to the board.
- Processes: risk assessment, vulnerability handling and release gates that product teams can repeat.
- Tools: the tools that make the processes fast, several of which we publish.
- Strategy: the decisions only leadership can take, which risks to accept and what to fund first.
Every engagement, whatever its size, runs the same way:
Our methodology
From the first call to the next step
Six stages, the same for a three-week assessment and a year-long programme: you know where you stand before you commit, and your teams keep the capability once we leave.
-
Scoping
Thirty minutes to understand your products, your markets and your deadlines. We tell you honestly whether and how we can help, and agree the scope, the price and the dates before anything starts. -
Kick-off
We meet the teams who will carry the work: product, development, quality, compliance, support and, where it matters, the executive sponsor. Product security crosses all of them, and everyone leaves knowing what is expected of them and when. -
Analysis and input workshops
We read your existing documentation first, architecture, specifications, processes and test reports, then hold working sessions with your teams to fill the gaps. We start from what you already have, never from a blank page. -
Work on the deliverable
Risk assessment, gap analysis, roadmap, technical file or policy: we build it and share it as it takes shape, so there is no surprise at the end. -
Validation and training
We walk your teams through the deliverable, adjust it with them, and train each role that will use it, from product owners to support. The point is that your teams can run it themselves afterwards. -
Debrief and next steps
A closing session with the sponsor: what changed, what remains, and our honest recommendation for the next step, whether or not it involves us.
Our services follow this model. Most CRA compliance programmes start with the CRA portfolio assessment.
Why work with us
Our clients work with us to make cyber work for their business, their staff and their customers. We deliver senior advisory, and we keep four commitments:
Advisory
Research
Training and mentoring
Community contribution
Who delivers your work
Every engagement is led by one of our advisors, who stays with you from the scoping call to the debrief, and that name is in your statement of work. Behind them, a network of associates and partner firms we have worked with for years covers the specialist work a programme needs: penetration testing, hardware evaluation, certification support, and the regulations that sit alongside product security.
They work under our contract and our quality standard, so cetome stays your single counterpart: one proposal, one invoice, one point of accountability. We tell you before anyone else joins the work, and your teams always know who is doing what. If your programme needs more hands than we can staff, we say so at the scoping call rather than in the middle of the engagement.

