Table of Contents
Discover how Tenacy structures your cybersecurity
Schedule a demo
1/ Establish a single repository rather than piling up files
Over the course of six years as a consultant, Yves Bonelli came to understand the limitations of static files—such as Excel—for managing multi-compliance: forms in different formats, information that needed to be constantly reprocessed, time-consuming updates, and limited visibility over time. Each risk analysis was in one file, each action plan in another, with no link between the two.
With Tenacy, compliance, risks, and action plans are all in one place. The connection between a gap assessment, the associated risk, and remediation becomes dynamic: an updated action item automatically updates the tracking, without the need for re-entry.
“When you conduct a risk assessment and then create a separate file for the action plan, at some point these static elements are no longer in sync. It’s an incredible waste of time. It’s all the behind-the-scenes coordination that makes our lives easier.”
Yves Bonelli, Chief Information Security Officer at Orange Concessions
Covered objective
The Tenacy platform has become Orange Concessions’ single source of truth, used four to five times a week by its CISO. Yves Bonelli now manages governance from a single platform and is able to refocus on his core business, rather than maintaining files.

2/ Map NIS2 compliance onto a three-year roadmap
NIS2 sets a high bar that must be anticipated. For a Critical Entity, which has three years to achieve compliance after the regulation takes effect, the path forward is just as important as the current state of affairs. Yves Bonelli reviewed the framework, redefined the measures, established action plans, and developed a multi-year roadmap, prioritizing the most sensitive issues.
The Gantt chart allows him to sequence major projects and present clear projections to management.
“NIS2 is a fairly demanding regulation. Managing it manually would be really complicated.”
Yves Bonelli, CISO at Orange Concessions
Covered objective
Compliance gaps translate into a clear, three-year roadmap—manageable within Tenacy—from the initial audit through to full compliance.
3/ Rely on methodological guidance
Tenacy is a feature-rich platform, and some of its mechanisms take time to master. Rather than proceeding on his own, Yves Bonelli maintained regular communication with the Customer Success Manager assigned to Orange Concessions. This support goes beyond mere technical assistance: it provides a methodological perspective on the solution, the priorities to address, and the potential pitfalls to anticipate.
“It’s a guided approach to getting started with the tool and developing my strategy. Laura (Customer Success Manager at Tenacy) was able to guide me on the essential steps and next actions.”
Yves Bonelli, CISO at Orange Concessions
A Guided Tour
Guidance ensures a smooth transition and prevents missteps. The CISO structures the scope in the correct order, without skipping any key steps.
4/ Demonstrate the cybersecurity roadmap to management
Gaining the executive committee’s buy-in requires making cybersecurity easy to understand. Tenacy ties together compliance, risks, and action plans into a cohesive view, which Yves Bonelli incorporates directly into his presentations and quarterly committee meetings without having to rebuild a PowerPoint presentation from scratch.
“I provide an overview that includes the gaps and the action plans to be implemented. It’s a pretty smooth process; they really like it, and I can present it fairly easily.”
Yves Bonelli, Chief Information Security Officer at Orange Concessions

Covered objective
Reporting to the Executive Committee is based on up-to-date data and a clear framework: compliance, risks, actions, and follow-up. Management reviews the trajectory and provides its approval.

.png)
.png)
