Industrial group
Connected product
NIS2 / CRA / GDPR
The challenge
A major European industrial group needed to assess and secure a connected product before launch,
without delaying a non-negotiable commercialization schedule.
- Protect sensitive information and intellectual property.
- Secure web, mobile, firmware, hardware and communication components.
- Support regulatory evidence before market release.
Cyberwings response
A multidisciplinary team was mobilized to run several workstreams in parallel, directly with the client's
development teams and laboratories.
- Physical intrusion scenarios and product component testing.
- Web, mobile, hardware, firmware and protocol security assessments.
- Continuous remediation support and compliance review.
01Scope risks and feared events
02Test all exposed technical components
03Map findings to regulatory expectations
04Support remediation and decision-making
Results
The client secured the product before commercialization, obtained a clear view of vulnerabilities and remediation
priorities, and strengthened security-by-design practices for future developments.
25+mission days in 2.5 weeks
7+Cyberwings experts mobilized
10+client-side contributors
150+pages in the final report
Financial services
Data breach
Forensics / Dark web / OSINT
The challenge
A regulated financial organization detected abnormal access to internal systems followed by suspected data leakage.
The priority was to establish facts quickly while preserving evidence and limiting operational, legal and reputational risk.
- Qualify the intrusion path and identify compromised assets.
- Assess whether client, employee or business data had been exposed.
- Document evidence in a form usable by legal counsel and authorities.
Cyberwings response
Cyberwings combined incident forensics, dark web monitoring, targeted OSINT and legal coordination to support both
technical containment and the preparation of possible proceedings.
- Collection and analysis of logs, endpoints, servers and exposed accounts.
- Dark web investigation to identify traces of leaked datasets or threat actor claims.
- OSINT on suspicious profiles, with escalation to a licensed detective agency when field investigation was required.
01Freeze and preserve digital evidence
02Reconstruct the intrusion timeline
03Investigate exposure on dark web channels
04Coordinate legal and investigative follow-up
Results
The client obtained a documented understanding of the incident, actionable remediation priorities, a clear assessment
of exposed data and structured evidence to support regulatory, legal and insurance exchanges.
72hto stabilize the first findings
18systems and evidence sources reviewed
6suspicious profiles investigated
1licensed detective agency coordinated
Foreign bank
Recurring pentest
Phishing / Awareness
The challenge
A foreign banking institution wanted to maintain continuous pressure on its exposed systems without turning security
testing into a yearly snapshot. Each month, a new attack surface had to be selected, tested and translated into
practical lessons for business and technical teams.
- Prioritize the most relevant exposed services, applications and user journeys every month.
- Include phishing scenarios to assess human and procedural exposure.
- Use findings to feed awareness campaigns instead of producing isolated audit reports.
Cyberwings response
Cyberwings structured a recurring operating model combining monthly scoping, offensive testing, remediation review
and awareness content derived from real findings observed in the client's environment.
- Monthly selection of an attack surface with the bank's security stakeholders.
- Penetration testing, phishing scenarios and risk-based restitution.
- Awareness campaigns adapted to the vulnerabilities, behaviors and decisions identified during testing.
01Select the monthly attack surface
02Run technical and phishing tests
03Share findings and remediation priorities
04Build targeted awareness actions
Results
The bank moved from punctual audits to a continuous security improvement rhythm, with recurring offensive evidence,
better remediation tracking and awareness campaigns grounded in its own risk reality.
12attack surfaces assessed per year
1monthly offensive cycle
3technical, human and process angles
100%awareness based on real findings
IT sector
External CISO
DevSecOps / Governance / Stakeholders
The challenge
An IT company needed senior cybersecurity leadership across technical, organizational and business dimensions,
without placing a single consultant in staff augmentation. Security topics involved production, development,
DevSecOps, client commitments, partners and investor confidence.
- Address infrastructure, application, operational and governance topics with the right expertise.
- Support client, partner and investor discussions with clear cybersecurity positions.
- Coordinate priorities without overloading internal teams.
Cyberwings response
Cyberwings provided a dedicated mission lead as the single interface, then mobilized the wider team depending on
each subject: architecture, DevSecOps, compliance, incident preparation, supplier security and executive reporting.
- One pilot responsible for steering, priorities and daily interface with management.
- Cyberwings experts activated on demand instead of a fixed on-site staffing model.
- Security roadmap covering technical, organizational and stakeholder-facing requirements.
01Clarify risks and governance priorities
02Build the security roadmap
03Mobilize experts by domain
04Support business-facing cybersecurity decisions
Results
The client gained an operational external CISO function, backed by a multidisciplinary team rather than an isolated
consultant, with clearer priorities, stronger client commitments and a more credible cybersecurity posture.
1single mission pilot
6+expertise domains mobilized
360°technical, organizational and business coverage
0staff augmentation model