What I've found in the field
No theory. Facts. Evidence. Scores. Real, anonymized and reproducible audits. OWASP, CVSS 3.1 methodologies. PDF reports 40+ pages with archived material evidence. Scoring out of 100, risk matrix, prioritized remediation plan.
Why cybersecurity can't wait any longer
France cybersecurity budget 2026
≈ 0.07% of national budget
US cybersecurity budget
125× more per capita
France Travail profiles leaked
2024–2026
These figures don't come out of nowhere. They come from institutional reports, specialized press, and continuous technical monitoring. I've cross-checked them with what I see in the field: WordPress sites abandoned since 2023, publicly exposed backups, domains expiring in 10 days, API keys buried in frontend code. France is at the back of the pack. And the worst part? Most decision-makers don't know it.
What I can audit
Each domain corresponds to real missions, with concrete deliverables and internationally recognized methodologies.
Web Security & Pentest
OWASP WSTG v4.2, OWASP Top 10 2021, CVSS 3.1. Black-box and grey-box testing, CVE identification, risk scoring, realistic attack scenarios. From reconnaissance to controlled exploitation.
GDPR & Legal Compliance
Privacy policies, cookie and consent management, legal notices, right to be forgotten, data traceability, processing registers. Business-specific analysis (notaries, e-commerce, local authorities).
Architecture & Infrastructure
Secure HTTP headers, SSL/TLS, HSTS, server configuration, WAF, rate-limiting, DNS and certificate analysis. Audit of interconnections and attack surfaces exposed to the Internet.
Factual Territorial Audit
Cross-referencing public data (INSEE, Météo-France, institutions), quantitative projections, quantified scenarios, interdependency matrices. Rigorous method: ~39 archived evidence files per study.
Cyber Investigation
Malware analysis (wipers like AcidRain), cyberwarfare, attack attribution, network forensics. Study of real incidents: Viasat KA-SAT, structured phishing campaigns.
Comparative Strategic Analysis
International benchmarks (France, US, UK, Germany, Japan), cyber budget studies, roadmaps for public decision-makers and businesses. Translating complex data into actionable decisions.
Audit Examples — Anonymized
No client names, no URLs. Only site typologies, measured scores, and findings that could apply to yours.
Institutional Site — Outdated CMS
9/100~4h
16 confirmed
5 critical
WordPress abandoned since 2023. 11 critical plugins with known RCE and XSS flaws. Domain name expiring in 10 days. GDPR compliance at 0%. Finding: this site is an open door.
B2B/B2C E-commerce — Technical Debt
24.5/100~14h
36 files
22+ identified
Database backups exposed since 2010 (2.1 MB + 62.4 MB compressed). Historical CMS Joomla! 1.5 still accessible. Current PrestaShop with vulnerable theme. Finding: 15 years of security technical debt.
SaaS Platform — API & Extranet
56/100~5h30
998 products
17 identified
Mass scraping of 998 products in 11 minutes (237.77 MB). Ably API key exposed in frontend. Critical CORS flaws enabling cross-origin access. Finding: the API is an open tap.
Notary Office — Enhanced Compliance
32.5/100~5h
20+ files
13 identified
Notary business analysis: professional secrecy protection, deed traceability. Rudimentary rate-limiting triggering IP block on auditor. No intelligent WAF. Finding: the profession is exposed, not just the website.
Rental App — Mobile + Web Stack
65/100~8h
25 files
17 identified
Modern architecture but 5 high-severity flaws in authentication and session management. Missing security headers on API. Sensitive forms without anti-CSRF protection. Finding: well-built, poorly secured.
Local Authority
71.4/100~3h
30+ files
11 identified
Overall posture average but 2 critical vulnerabilities in administrative authentication. User data and administrative documents exposed. No robust password policy. Finding: the average hides serious flaws.
« People think I'm a fabulist »
When I say a site can be compromised in 20 minutes, that a database of 43 million profiles has leaked, or that France spends 0.07% of its budget on cybersecurity... people look at me wide-eyed. Sometimes they call me a fabulist.
Yet, every finding I present is sourced, timestamped, and reproducible. Here's how I work:
Recognized Methodologies
OWASP, CVSS 3.1, GDPR, ISO 19011. No opaque home-grown methods.
Material Evidence
20 to 36 timestamped artifacts per audit: screenshots, logs, HTTP responses, SHA-256 hashes.
Reproducibility
You can redo the test yourself with the same open-source tools. No black magic.
I don't predict the future. I measure the present.
Artificial Intelligence: a tool, not a monster
People are afraid of AI. That's normal — we fear what we don't know.
How I use AI
I use it like I use an oscilloscope or a NMEA protocol analyzer: it's a tool that lets me go faster and further. It doesn't replace my judgment. It amplifies it.
- Analyze 10,000 lines of logs in seconds
- Cross-reference data from multiple and contradictory sources
- Generate realistic, documented attack scenarios
- Produce structured reports without losing rigor
What it cannot do
The real threat isn't AI. It's ignorance of what it can do — and what it cannot do.
- It doesn't replace business expertise (notary, marine, healthcare)
- It doesn't validate material evidence by itself
- It doesn't make ethical decisions for you
- It doesn't protect your site if you don't fix the flaws
The audit makes visible what was hidden. AI is the flashlight. You're the one looking.
Want to know where you stand?
An audit doesn't judge. It measures. And measurement is the first step toward mastery.
Request an auditFirst exchange without commitment. Response within 24h.