TEBICOM · CYBER MATURITY ANALYSIS
Map and manage your cyber defense.
Your infrastructure is solid, but without a standardized framework, it's impossible to effectively manage your cyber budget. SENTRA CYBERSTART is the maturity audit that transforms your posture into a strategic action plan, aligned with ISO 27001 and the Minimum ICT Standard.
The missing strategic brick.
You have top-tier equipment, but without a standardized framework to drive your overall posture.
The current foundation
Your company has a significant level of technological equipment. The infrastructure foundations are robust and well-sized. Firewalls, backups, antivirus/EDR/XDR. The technical building blocks are in place.
The strategic challenge
An essential component is missing: a standardized framework for optimizing the overall cyber defense posture and effectively managing budgets with objective and comparable metrics.
Three strategic objectives.
Plan & Prioritize
Focus efforts and budgets where they will have the maximum impact on your security. Eliminate waste on non-priority investments.
Defend a Vision
Establish and maintain best practice principles at all levels of the organization, from management to operational teams.
Aligning with Standards
Ensure that each cyber defense choice adheres to a recognized and sustainable standard. Prepare your organization for regulatory requirements (ISO, NIS2, DORA).
12 domains. A complete vision.
The CYBERSTART framework covers your entire cyber posture, structured around the TIC Minimum Standard and ISO 27001.
Security policy, risk management, asset classification.
Network architecture, segmentation, firewall, remote access.
Patch management, configuration hardening, endpoints.
Classification, encryption, backup, retention, and destruction.
MFA authentication, access management, privileged accounts.
Monitoring, SIEM, incident response procedures.
Physical access control, data center, workstations.
Awareness programs, cyber culture, phishing.
M365, Azure/AWS, SaaS, secure cloud configurations.
Third-party evaluation, contracts, supply chain.
Use of AI tools, data processed, usage policies.
Business continuity plan, disaster recovery plan, restoration tests, resilience.
Minimum ICT Requirements · ISO 27001 · NIS2 · DORA
4 to 6 weeks. A proven pipeline.
Each phase is structured to maximize the quality of the analysis and minimize the impact on your business (some weeks are merged depending on the company).
WEEK 1
Preparation
Project launch, team formation, initial document collection.
WEEK 2
Analyze Active
Stakeholder interviews + optional deployment of monitoring probes (Nessus).
WEEK 3
In-depth Analysis
Continuation of interviews, in-depth technical analysis, and data cross-referencing.
WEEK 4
Initial Restitution
Initial analysis and presentation of findings to key stakeholders.
WEEK 5
Report
Final report writing and adjustments based on feedback from the presentation.
WEEK 6
Fence
Final presentation to management and handover of all deliverables.
The value/impact matrix.
Our proprietary tool to prioritize every cyber action by cross-referencing security value and required effort.
QUICK WINS ★
Maximum value, minimum effort — absolute priority
MAJOR PROJECTS
Max value, high effort — plan
EASY GAINS
Moderate value, minimal effort — opportunities
TO RECONSIDER
Low value, high effort — deprioritize
Measured Cyber Value
Maturity index gain for each identified action, scored on a scale of 0-5.
Impact of Change Assessed
Organizational friction and estimated costs to deploy each measure in your context.
Strategic Action Plan
Result: a prioritized plan that optimizes every franc invested in cybersecurity, validated with your management.
What you get.
Two concrete and actionable deliverables, submitted at the project's closure.
Analysis Report (PDF)
Detailed current situation for each of the 12 domains, comprehensive diagnosis with maturity index, and reasoned architectural recommendations. Reference document for your management and insurers.
Action Plan (Excel)
Interactive steering tool listing all recommended actions with: internal effort estimate, positioning on the Value/Impact Matrix, and strategic prioritization for your 12-24 month cyber roadmap.
Prerequisites to start.
Signing of a Non-Disclosure Agreement (NDA)
Availability of key client stakeholders (management, IT, legal)
Provision of all necessary technical documentation
Official start of workshops
Go further with CISOaaS.
Tebicom offers two levels of support after the delivery of the CYBERSTART deliverables.
OPTION A
CISO Coaching
Support for your internal CISO or IT manager to implement the CyberStart action plan. Regular coaching sessions, progress reviews, and strategic adjustments. Ideal if you already have an internal IT resource.
OPTION B
CISO as a Service
Tebicom takes on the role of outsourced CISO for your organization. Definition and steering of the cyber roadmap, management of audits and compliance, representation to management and the board of directors.