ESN
x

Simplifying cybersecurity management across a multi-country group

How did Tessi industrialize its cyber management and save 12 weeks per year thanks to Tenacy?
“Tenacy allowed us to regain control over our cyber assets.”
Jérôme Farrouil
Group Director of Compliance, Risk, and Cybersecurity at Tessi
The challenge
Simplify and centralize cybersecurity for a multi-entity organization

With a presence in 15 countries and 13,900 employees, the Tessi Group manages massive volumes of sensitive data (personal, health, financial) on a daily basis.

The group's cyber organization is complex: more than 10 different information systems to manage, local CISOs and dispersed operational teams, working on different tools and in different ways. The teams work mainly in Excel, with heterogeneous data, sometimes obsolete, and could only obtain reports that were difficult for management to use.

This manual approach resulted in considerable time wasted, a fragmented view of the security posture, and a lack of traceability of audit evidence.

It was in this context that Jérôme Farrouil realized that their current methods had their limitations and that acquiring a new tool was necessary.

Internal security
Maintain a consistent level of safety across all subsidiaries, complying with applicable standards and regulations.
Application security
Ensure continuous protection for critical applications at the heart of the business.
Reporting
Quickly produce reliable reports for the Executive Committee and operational teams.
The objective
Industrialize these three key processes to ensure data reliability, increase responsiveness, and manage the group's cybersecurity at scale.
The solution

Why did you choose Tenacy?

Its proven reliability

on multi-subsidiary organizations

Its ability to evolve

without disrupting existing practices

Its ease of adoption

and its clear interface

Table of Contents
Discover how Tenacy structures your cybersecurity
Schedule a demo

1/ Centralize for better management

To effectively manage the group's cybersecurity and prioritize its actions, it was essential to have a clear and granular view of Tessi's entire organization:

  • Complete mapping of the organization and its 53 areas of operation.
  • Consolidated view of security levels at the group, BU, and subsidiary levels.
  • Implementation of 22 automated monthly and quarterly indicators, with associated evidence.

Objectives covered:

A clear visualization of internal security and critical applications.

The cyber department now has a consistent view, updated in real time, and each critical application has a dedicated cyber score.

2/ Automate to increase efficiency

Each month, consolidating indicators required a full week of work, just to aggregate the data. Thanks to Tenacy's intelligent modeling and feedback from their connectors, Jérôme Farrouil is able to speed up data processing and make it more reliable.

  • Industrialization of level 1 and 2 controls, with integrated workflows.
  • Monitoring of more than 500 actions and remediation plans.
  • Automation of recurring tasks and automated approvals between local and central teams.

Objectives covered:

Reliable data refreshed in real time.

"Automation means reliability: you know where you stand at all times, without having to chase after Excel files."
Jérôme Farrouil, Group Director of Compliance, Risk, and Cybersecurity at Tessi

3/ Optimize multi-level reporting

The centralization and automation of cyber activities in Tenacy have led to an overall increase in efficiency for operational monitoring and reporting that is always up to date.

  • Monitoring changes in indicators over time using historical data
  • Dashboards tailored to the needs of the Executive Committee: overall security levels, risk levels
  • Operational monitoring and reporting: dashboards dedicated to operational teams to prioritize critical actions

Objectives covered:

Dashboards tailored to each stakeholder and editable in just a few clicks.

"We all speak the same language, from the local CISO to the Executive Committee. It's a real cultural shift."
Jérôme Farrouil, Group Director of Compliance, Risk, and Cybersecurity at Tessi

4/ Facilitate collaboration between teams

With the multitude of tools used by cyber teams and the geographical distance from local CISOs, ensuring smooth communication between teams was a real challenge:

  • Centralization of all cyber projects in a single collaborative tool.
  • Instant reporting by BU: subsidiary or group, available "live" for audits and clients.
  • Cyber committees without PowerPoint: Tenacy dashboards are used directly for dialogue with management.
"If I had to do the same thing with people and Excel files, I would easily need four more people. And above all, I would have a much higher turnover because that would be all the teams would be doing."
Jérôme Farrouil, Group Director of Compliance, Risk, and Cybersecurity at Tessi

5/ Finally, controlled multi-compliance management

{{3-cards}}

Results

Results after 5 years of use

Only 2 administrators

to manage 53 areas, 22 indicators, and over 500 actions.
"Tenacy has become our driving force: quality, efficiency, stability." Jérôme Farrouil, Group Director of Compliance, Risk, and Cybersecurity at Tessi

12 weeks/year earned

On the consolidation of reporting.

5 minutes

To obtain a gap analysis between two frameworks
Conclusion
The Tessi case illustrates the successful transformation of a large multi-country group toward cybersecurity becoming a real business lever for the company.
Do these issues resonate with you?
Schedule a demo

Regain Control of Your Cybersecurity

Schedule My Personalized Demo
30 minutes with no obligation