Cybersecurity Officer for VSEs and SMEs
Satisfaction rate
4.8
Success rate
4.8
Become the cybersecurity pillar of your company and effectively manage operational security
The target audience for training
- Cybersecurity / ISS Officers
- DSI, RSI, RSSI in SME environment
- IT Managers
- Compliance or RGPD managers
- Technical or business leaders
Training programme
- Duration: 5 days
Day 1: Fundamentals, issues, legal framework
- Definition of cybersecurity / cyberdefence / cybercrime
- Typologies: ransomware, phishing, APT, supply chain
- Human vulnerabilities (social exploits)
- Players: ANSSI, CNIL, DGSI, gendarmerie
- Legal framework: RGPD, CNIL, responsibilities, proof
Day 2: Digital hygiene & basic security
- Password policy, MFA
- Monitoring and updates (patching, obsolescence)
- BYOD, open networks, uncontrolled peripherals
- Data mapping and value
- ANSSI SME hygiene rules
Day 3: Risk analysis and PSSI for SMEs
- Introduction EBIOS / MEHARI simplified version
- Identification of assets, threats and scenarios
- Criticality matrix
- Drawing up a PSSI: scope, objectives, charter
Day 4: Outsourcing, innovation, crisis
- Cloud: SaaS, IaaS, essential clauses, SecNumCloud
- Innovation: protection of property (patents, recipes)
- Crisis management plan
- Reporting ANSSI, CNIL, contracts, evidence
Day 5: Web security, the cybersecurity officer's toolbox& Summary project
- WordPress, Prestashop: configuration, common vulnerabilities
- Databases: rights, logs, sessions
- Payment security : PCI-DSS
- Scanning & OSINT tools: Shodan, WPScan, TheHive
Teaching methods
- Action-based approach: concrete cases, simulations, co-construction
- Feedback from our PASSI audit assignments in the field, with examples of recurring vulnerabilities in SME IS; our regional cybersecurity support as part of the "Diag Cyber" or "Plan France Relance" schemes; our SOC & CSIRT interventions on real incidents (ransomware, data leakage, IT service provider impersonation); lessons learned from our active monitoring within the Cyber Campus and the ANSSI/CERT-FR ecosystem.
- Contributors to national working groups (Campus Cyber, France Num, etc.)
- Reverse teaching with online resources to explore before/after
- Access to the ACG Cyber Academy platform for workshops and interactive exercises
Training objectives
- Understand the issues and threats associated with cybersecurity in the VSE/SME context.
- Identify specific risks and respond with pragmatic measures.
- Be able to structure a security policy (PSSI) adapted to the size of the organisation.
- Develop operational reflexes in the event of a security incident.
- Integrate cyber security into business processes, governance and corporate culture.
- Be autonomous in implementing regulatory compliance (RGPD, NIS2, etc.).
- Build up a toolbox for monitoring and responding to threats.
Training prerequisites
- Mastery of the corporate digital environment
- Basic knowledge of networks and systems (advanced user level)
- An interest in technical and regulatory issues
- Language : French
- Level : Fundamental
- Certification body : ACG CYBERACADEMY
- Certification: No
- Accessibility : Yes
- Duration: 5 days
Important information:
Our courses are not registered with the Répertoire National des Certifications Professionnelles (RNCP), but they do comply with the requirements of the Répertoire Spécifique (RS).