Skip to content
Loris Sefsaf

Independent cybersecurity consultant

I help IT teams secure their systems, detect attacks, and respond when they happen.

I'm Loris Sefsaf. I'm an ENSIMAG-trained engineer with more than ten years in IT, eight of them in cybersecurity, in France and Canada. I now work independently with CIOs, CISOs and SMB leaders, on site or remotely.

Loris Sefsaf
CISSP · OSCP · CPTS · CKAFR / EN

From recent engagements

What I do

  • “We don’t know how an attacker would get in.”

    Audit & pentest

    Internal, external and cloud penetration tests, plus a maturity assessment against ISO 27001, NIST CSF and ANSSI guidance. You get a remediation roadmap ranked by risk that your leadership can read.

  • “Alerts pile up and nobody handles them.”

    SOC / XDR

    I design, integrate and run your SOC/XDR (Sekoia.io, SentinelOne, HarfangLab): detection rules tuned to your environment, playbooks, procedures. Fewer false positives, and procedures your team actually follows.

  • “Our workloads are moving to the cloud faster than security.”

    Cloud & Kubernetes

    I audit Azure, Entra ID and AWS, harden your Kubernetes clusters (RBAC, network policies, admission control, image scanning) and set up their monitoring.

  • “We don’t have a CISO, or ours is on their own.”

    Fractional CISO

    I advise your CISO, or take on the role a few days a month: governance, security policy, NIS2 and ISO 27001 compliance, staff awareness. No full-time hire needed.

  • “We’ve been attacked, or we think we have.”

    Incident response

    Containment, EDR and identity investigation, service restoration, BCP/DRP, then hardening. If the attack is ongoing, message me directly on Signal and describe what’s happening.

Recent work

Details →

Certifications

Let's talk about your situation.

In thirty minutes we go over your risks and priorities, and I'll tell you whether I can help. No commitment.

Book a 30-minute call