CyberAct

What our clients say

CISO & DSI Reviews — SOC, Red Team, Pentest

Since 2008, CAPVALUE CYBER SECURITY has helped clients raise their cyber maturity: Red Team, SOC, pentest and NIS2 compliance.

15+

Years of experience

100+

Missions completed

4.9/5

Average satisfaction

98%

Recommendation rate

5/5 — 2026

Our development teams build several critical applications exposed online. We needed an objective external view of our real security posture. CAPVALUE CYBER SECURITY conducted a full Red Team exercise simulating an attacker attempting to penetrate our information system through our applications. Findings were presented to our management with concrete business impact scenarios — the effect on budget priorities was immediate. The source code audit on our main application uncovered several serious vulnerabilities our internal teams had missed. The application security engagement then enabled us to build a secure development reference framework. A demanding and thoroughly professional collaboration.

CISO

National bank — Banking sector

Services delivered

  • Red Team
  • Source Code Audit
  • Application Security
5/5 — 2026

We needed to demonstrate a documented maturity level across our infrastructure and information systems security. CAPVALUE CYBER SECURITY intervened on three complementary fronts: a full security audit — with detailed findings and a prioritised remediation plan — a restructuring of our information security governance, and a phishing simulation campaign across all staff. The initial click rate was concerning; after two awareness waves designed by their teams, we saw a 70% reduction. Our maturity level was recognised during an independent external audit. A structured and thoroughly professional engagement.

CIO

Insurance company — Insurance sector

Services delivered

  • Security Audit
  • Information Security
  • Phishing Simulation
5/5 — 2026

We launched a client portal and a mobile application giving access to sensitive data. Before go-live, we commissioned CAPVALUE CYBER SECURITY for a full web and mobile security audit: penetration testing, data flow analysis, authentication mechanism review. Several vulnerabilities were identified and remediated before launch. The configuration audit of our servers uncovered hardening gaps on default settings. The application security engagement produced a secure development guide that our vendors must now comply with contractually.

Head of Cybersecurity

Financial institution — Mutual funds & provident funds

Services delivered

  • Web & Mobile Security
  • Configuration Audit
  • Application Security
5/5 — 2026

We expose critical APIs to a large number of users and B2B partners. CAPVALUE CYBER SECURITY conducted a black-box penetration test on our web client portal and mobile application, then an in-depth audit of our APIs. The teams detected injections, session management issues and authorisation flaws that our internal teams had not caught. The report was directly actionable for our developers — step-by-step reproductions, no unnecessary jargon. The quality of the work enabled us to obtain the security validation required by our partners. I recommend them without reservation.

CISO

Telecom operator — Telecommunications sector

Services delivered

  • Web & Mobile Security
  • Application Security
  • Black-box penetration test
5/5 — 2026

With a large number of stores, point-of-sale terminals and a permanently exposed e-commerce platform, we could no longer operate without an organised detection capability. CAPVALUE CYBER SECURITY set up a SOC tailored to our architecture: defining priority use cases, structuring L1/L2 tiers and providing concrete training for our analysts on real-world scenarios from our sector. Within a few months, our mean detection time was significantly reduced. We now have genuine visibility into what is happening in our IT environment — not just when it is already too late.

CIO

Large-scale retail — National chain

Services delivered

  • Managed SOC setup
  • SOC team training (L1/L2)
  • Security incident supervision
5/5 — 2026

The security of our transaction flows is a critical obligation and a matter of trust for our clients. CAPVALUE CYBER SECURITY first conducted a full security audit of our payment platform, then an application security engagement on our payment initiation APIs — a particularly exposed attack surface. Findings led to a partial redesign of our authorisation architecture. We then entrusted them with building our SOC: use cases oriented towards real-time fraud detection, alerts on abnormal flows, runbooks for our analysts. The maturity of our security setup is now recognised by our partners and external auditors.

CISO

Payment institution — Fintech sector

Services delivered

  • SOC setup
  • Application Security
  • Security Audit

These testimonials are anonymised at clients' request. Roles, sectors and services are accurate; company names are intentionally omitted.

Want to learn more about our approach?

Let's discuss your context and challenges in a confidential conversation.