Independent cybersecurity consultant
I help IT teams secure their systems, detect attacks, and respond when they happen.
I'm Loris Sefsaf. I'm an ENSIMAG-trained engineer with more than ten years in IT, eight of them in cybersecurity, in France and Canada. I now work independently with CIOs, CISOs and SMB leaders, on site or remotely.

From recent engagements
- ~500endpoints monitored in a SOC I deployed for an MSSP
- 28 Mevents analysed per day on that SOC
- 10SMB clients onboarded to the platform
- 1 B+events per day on another XDR I set up
What I do
“We don’t know how an attacker would get in.”
Audit & pentest
Internal, external and cloud penetration tests, plus a maturity assessment against ISO 27001, NIST CSF and ANSSI guidance. You get a remediation roadmap ranked by risk that your leadership can read.
“Alerts pile up and nobody handles them.”
SOC / XDR
I design, integrate and run your SOC/XDR (Sekoia.io, SentinelOne, HarfangLab): detection rules tuned to your environment, playbooks, procedures. Fewer false positives, and procedures your team actually follows.
“Our workloads are moving to the cloud faster than security.”
Cloud & Kubernetes
I audit Azure, Entra ID and AWS, harden your Kubernetes clusters (RBAC, network policies, admission control, image scanning) and set up their monitoring.
“We don’t have a CISO, or ours is on their own.”
Fractional CISO
I advise your CISO, or take on the role a few days a month: governance, security policy, NIS2 and ISO 27001 compliance, staff awareness. No full-time hire needed.
“We’ve been attacked, or we think we have.”
Incident response
Containment, EDR and identity investigation, service restoration, BCP/DRP, then hardening. If the attack is ongoing, message me directly on Signal and describe what’s happening.
















