Table of Contents
Discover how Tenacy structures your cybersecurity
Schedule a demo
1/ Standardize the monitoring of heterogeneous information systems
Excel files quickly reach their limits in an environment with many stakeholders: it’s difficult to collaborate, assign and track tasks, and—above all—ensure consistency. Everyone customizes their own spreadsheet, and the metrics lose their meaning.
Tenacy applies the same control plans and recurring tasks to each information system. Environments are evaluated using a common framework, enabling valid comparisons and reliable metrics.
“This allows us to manage our heterogeneous environments in a consistent manner. We apply the same recurring tasks to our various information systems, so we can compare like with like and develop consistent metrics.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense
Covered objective
Monitoring is standardized across the entire infrastructure. Orange Cyberdefense uses consistent metrics that are comparable across information systems, whereas Excel left room for interpretation.
2/ Drive change to establish consistent practices
To ensure a smooth rollout of the platform, Orange Cyberdefense decided to start with two pilot projects, allowing time to become familiar with the tool, model use cases, and document best practices. Vincent Nogues established a framework early on to define what to include in the tool, the level of granularity, how to name the records, and to formalize a clear process.
The company relied on responsive support throughout the project, from launch through to production: chat, support, and CSM follow-up.
“If we had launched this with twenty drivers without a framework, each one would have used the logs in their own way, and we would have lost all consistency in the metrics and in tracking the various actions.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense
Covered objective
Scaling up is under control. Standardized and documented practices ensure consistent metrics, regardless of the number of pilots on the platform.
3/ Centralize compliance, audits, and corrective actions
Vincent Nogues uses Tenacy across the entire GRC spectrum: risk management, compliance, audit programs and related remediation efforts, project security, gap resolution, control plans, and exception management. All of this is managed centrally, allowing everyone to view the history, progress status of a remediation, or the status of a specific action.
This centralization also has an impact on continuity. The work performed is documented, structured, and reusable, regardless of who performs it. Furthermore, document and evidence management remains secure: sensitive documents remain on the organization’s internal systems, linked to Tenacy via simple hyperlinks.
“If I’m absent tomorrow or leave, in theory, everything I’ve done could easily be taken over by someone else. There’s the aspect of collaboration, and the aspect of reusing the work.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense
Covered objective
The RCMP relies on a single, collaborative, and sustainable repository. Knowledge is no longer stored in individual files but on a shared platform.
.webp)
4/ Manage recurring and one-time tasks on a daily basis
Once the NIS2 or ISO 27001 assessment is complete, the day-to-day work of a CISO shifts to another area: tracking actions. These actions stem from the annual plan, project security assessments, or audits, as well as recurring tasks such as access reviews. This is the feature that Vincent Nogues uses the most, and the one that accounts for the bulk of the operational workload.
“On a day-to-day basis, it’s tracking actions that takes time. Tenacy allows me to do exactly what I need to do.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense
Covered objective
Action tracking is centralized and collaborative. The operational workload is measurable, enabling rigorous management and monitoring.

5/ Provide management with an objective assessment of the workload
In a fragmented IT environment, even a seemingly trivial task can become a significant burden when repeated across multiple systems. A semi-annual access review may seem simple, but when repeated across multiple IT systems and combined with other tasks, it can place a significant burden on teams. By assigning a workload to each task, Vincent Nogues makes this volume measurable: he tracks his backlog, verifies whether the team is adequately staffed, and identifies long-term trends.
“We assign a man-hour to each action, and we find that when all these actions are added up, they amount to several dozen man-days. The tool helps us bring this kind of information—which is often invisible to management—to light.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense
Covered objective
The IT workload is becoming a governance issue. Management can see the actual volume of activity and allocate resources based on facts.


.png)
.png)
