ESN
x

Standardizing GRC monitoring across a heterogeneous IT infrastructure with multiple repositories

As Head of Internal Security at Orange Cyberdefense, Vincent Nogues moved away from Excel to provide consistent oversight of about ten information systems at various levels of maturity.
“With an Excel file, it’s so customizable that you can make it say just about anything. Here, we manage our information systems consistently, so we’re comparing like with like.”
Vincent Nogues
Head of Internal Security at Orange Cyberdefense
The challenge
The Challenge: Multi-Regulatory Compliance in a Fragmented IT System

Orange Cyberdefense is the Orange Group’s subsidiary dedicated to cybersecurity and the European leader in cybersecurity services. With more than 3,000 experts in a dozen countries, it protects more than 8,700 clients worldwide. Vincent Nogues (Head of Internal Security) is responsible for overseeing the entity’s GRC.

His playing field is demanding:

‍

  • A highly fragmented information system, consisting of numerous subsystems with varying levels of maturity and sensitivity.
  • A wide range of standards imposed on the organization: ISO 27001, NIS2, ANSSI regulations, the Orange Group’s security policy, etc.
  • And, initially, management was done manually using Excel files and meetings, with a great deal of time spent justifying the evidence to the auditors.

‍

In-house tools quickly reveal their limitations. They don’t support collaborative work: it’s difficult to assign tasks, track them as a team, and share a common view. This created a clear need for Orange Cyberdefense: to implement a platform that would improve visibility, save teams time, and:

Standardize monitoring
Treat IT systems at different stages of maturity using the same criteria, in order to gain a consistent view and develop coherent metrics.
Centralize CRM
Bring together compliance, risks, audits, and corrective actions in a single location that is accessible and reusable by all stakeholders.
Make the load visible
Assign a cost and an expense to each action to objectively determine the resources needed for management.
The objective
To standardize the RCMP’s operational monitoring across a heterogeneous, multi-repository IT environment while improving collaboration, consistency, and visibility—without increasing the workload on teams. The decision was based on a market study comparing in-house solutions, commercial products, and open-source solutions. Tenacy was selected based on three criteria.
The solution

A French, collaborative, multi-repository GRC platform

Multi-repository Management

A framework capable of addressing ISO 27001, NIS2, and the group's requirements within a single framework.

‍

Operational granularity

A tool that enables collaborative management of operational activities.

A French solution

A French publisher that reassures management and meets expectations regarding sovereignty.

Table of Contents
Discover how Tenacy structures your cybersecurity
Schedule a demo

1/ Standardize the monitoring of heterogeneous information systems

Excel files quickly reach their limits in an environment with many stakeholders: it’s difficult to collaborate, assign and track tasks, and—above all—ensure consistency. Everyone customizes their own spreadsheet, and the metrics lose their meaning.

Tenacy applies the same control plans and recurring tasks to each information system. Environments are evaluated using a common framework, enabling valid comparisons and reliable metrics.

“This allows us to manage our heterogeneous environments in a consistent manner. We apply the same recurring tasks to our various information systems, so we can compare like with like and develop consistent metrics.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense

Covered objective

Monitoring is standardized across the entire infrastructure. Orange Cyberdefense uses consistent metrics that are comparable across information systems, whereas Excel left room for interpretation.

 

2/ Drive change to establish consistent practices

To ensure a smooth rollout of the platform, Orange Cyberdefense decided to start with two pilot projects, allowing time to become familiar with the tool, model use cases, and document best practices. Vincent Nogues established a framework early on to define what to include in the tool, the level of granularity, how to name the records, and to formalize a clear process.

The company relied on responsive support throughout the project, from launch through to production: chat, support, and CSM follow-up.

“If we had launched this with twenty drivers without a framework, each one would have used the logs in their own way, and we would have lost all consistency in the metrics and in tracking the various actions.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense

Covered objective

Scaling up is under control. Standardized and documented practices ensure consistent metrics, regardless of the number of pilots on the platform.

 

3/ Centralize compliance, audits, and corrective actions

Vincent Nogues uses Tenacy across the entire GRC spectrum: risk management, compliance, audit programs and related remediation efforts, project security, gap resolution, control plans, and exception management. All of this is managed centrally, allowing everyone to view the history, progress status of a remediation, or the status of a specific action.

This centralization also has an impact on continuity. The work performed is documented, structured, and reusable, regardless of who performs it. Furthermore, document and evidence management remains secure: sensitive documents remain on the organization’s internal systems, linked to Tenacy via simple hyperlinks.

 “If I’m absent tomorrow or leave, in theory, everything I’ve done could easily be taken over by someone else. There’s the aspect of collaboration, and the aspect of reusing the work.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense

Covered objective

The RCMP relies on a single, collaborative, and sustainable repository. Knowledge is no longer stored in individual files but on a shared platform.

Gaps are turned into collaborative action plans

‍

4/ Manage recurring and one-time tasks on a daily basis

Once the NIS2 or ISO 27001 assessment is complete, the day-to-day work of a CISO shifts to another area: tracking actions. These actions stem from the annual plan, project security assessments, or audits, as well as recurring tasks such as access reviews. This is the feature that Vincent Nogues uses the most, and the one that accounts for the bulk of the operational workload.

“On a day-to-day basis, it’s tracking actions that takes time. Tenacy allows me to do exactly what I need to do.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense

Covered objective

Action tracking is centralized and collaborative. The operational workload is measurable, enabling rigorous management and monitoring.

The completion of recurring tasks is tracked and used to generate metrics

‍

5/ Provide management with an objective assessment of the workload

In a fragmented IT environment, even a seemingly trivial task can become a significant burden when repeated across multiple systems. A semi-annual access review may seem simple, but when repeated across multiple IT systems and combined with other tasks, it can place a significant burden on teams. By assigning a workload to each task, Vincent Nogues makes this volume measurable: he tracks his backlog, verifies whether the team is adequately staffed, and identifies long-term trends.

“We assign a man-hour to each action, and we find that when all these actions are added up, they amount to several dozen man-days. The tool helps us bring this kind of information—which is often invisible to management—to light.”
Vincent Nogues, Head of Internal Security at Orange Cyberdefense

Covered objective

The IT workload is becoming a governance issue. Management can see the actual volume of activity and allocate resources based on facts.

You can assign a cost and a man-hour allocation to your projects
Results

The results: consistent and objective GRC management

Consistent handling

The same tasks and metrics applied to all information systems, to compare like with like.
“If we were to go back to using Excel tomorrow, we would lose out in terms of both quality and quantity. It’s like asking a finance professional to manage invoicing without an ERP system, using only Excel files and emails.” Vincent Nogues, Head of Internal Security at Orange Cyberdefense

A reusable central point

Centralized compliance, audits, and remediation, and the ability to easily resume work, even if an employee leaves.

A load made visible

The scope of work, expressed in person-days, to determine the required resources for management.
Conclusion
This case study demonstrates that Tenacy enables organizations to manage compliance at scale and optimize resources within a complex, multi-repository information system without compromising rigor or collaboration.
Do these issues resonate with you?
Schedule a demo

Regain Control of Your Cybersecurity

Schedule My Personalized Demo
30 minutes with no obligation