Skip to content

Independent Cybersecurity Consultant — France & International

Gérard Levicki — Cybersecurity Consultant

Identify your top risks, secure your business, and invest where it really matters. I help small and medium-sized businesses, mid-market companies, and organizations address their challenges in governance, auditing, penetration testing, compliance, incident response, and awareness training.

  • Outsourced Chief Information Security Officer (CISO), Cybersecurity Consulting and Management
  • Audits, Penetration Tests, and Risk Assessments
  • Support for NIS2, DORA, ISO 27001, and EBIOS Risk Manager
  • Incident Response and Crisis Management
  • Action plans prioritized based on risks, resources, and business imperatives

Security should support business, not the other way around.

25+ yearsof experience
+10 Mof protected data
+40trusted partners
24/7depending on the service requirements

Cybersecurity Consultant: Securing the Company Based on Its Actual Risks

A cybersecurity consultant helps an organization identify, assess, and mitigate its digital risks. Their role may encompass governance, audits, technical security, compliance, crisis management, and the coordination of initiatives, while taking into account business, human, and budgetary constraints.

Cybersecurity isn't about accumulating tools. It's about protecting what enables the company to operate: its data, its critical systems, its employees, its partners, its processes, and its customers' trust.

My role is to provide an independent perspective that can be directly applied by both management and IT teams: understanding what is truly at risk, distinguishing between what is urgent and what is important, and developing a roadmap tailored to your organization.

In what situations should you hire a cybersecurity consultant?

A company may hire a consultant when it lacks in-house expertise, wants to assess its security posture, needs to prepare for compliance, secure a transformation, or respond to an incident. The appropriate level of support depends primarily on the situation and the risk at hand.

Common Situations and Appropriate Support Measures
Your Situation Appropriate support
You do not have an in-house CISOOutsourced Chief Information Security Officer
You lack visibility into your security postureCybersecurity Audit
You need to verify whether vulnerabilities are actually exploitablePenetration Test
Are you preparing for NIS2, DORA, ISO 27001, or a risk management initiative?Compliance and Risk Management
You have been the victim of an attack or suspect that your system has been compromisedIncident Response and Crisis Management
You need to secure a project, make decisions, or structure your strategyCybersecurity Advisory
Do you want to reduce human error?Awareness and Training

Cybersecurity services tailored to your priorities

An organization does not necessarily need to do everything at once. Each initiative must address an identified need, with a scope and level of commitment that are appropriate.

Outsourced Chief Information Security Officer

Take advantage of senior-level security management without necessarily hiring a full-time CISO: governance, risk management, roadmap development, stakeholder coordination, and reporting to senior management.

Learn About Outsourced CISO Services

Cybersecurity Advisory

Defining project scope, prioritizing investments, designing architecture, making trade-offs, and providing decision support when security must support business operations without hindering them.

Learn About Cybersecurity Consulting

Cybersecurity Audit

Assess your organization, practices, and technical environments to identify gaps, vulnerabilities, and risks that truly require action.

Learn About Cybersecurity Audits

Penetration Testing and Intrusion Testing

Conduct practical testing of a system's resilience and the exploitability of specific vulnerabilities to distinguish between theoretical vulnerabilities and attack scenarios that are truly concerning.

Learn About Penetration Testing

Compliance and Risk Management

Organize your NIS2, DORA, ISO 27001, or EBIOS Risk Manager initiatives by linking requirements, risks, governance, and operational actions.

Learn About Compliance Support

Incident Response and Crisis Management

In the event of an attack or suspected compromise, the goal is to limit the impact, preserve evidence useful for analysis, coordinate decisions, and prepare for remediation.

Under attack? See the related support

Awareness and Training

Prepare executives, IT teams, and employees for real-world scenarios: phishing, best practices, responsibilities, reporting procedures, and a culture of security.

Explore Cybersecurity Training Programs

View all cybersecurity services

How does cybersecurity consulting work?

Effective support begins with critical assets and business risks before any technical recommendations are made. Actions are then prioritized based on their impact, urgency, cost, and the organization’s actual capabilities.


  1. Understanding Business Operations and Critical Assets

    Identify the processes, data, applications, infrastructure, vendors, and dependencies that are essential to business operations.


  2. Assess Exposure and Risks

    Analyze the organization, existing safeguards, vulnerabilities, dependencies, and scenarios that could affect operations.


  3. Prioritize

    Distinguish between emergencies, structural improvements, and low-value measures in order to focus resources on the most significant risks.


  4. Developing the Roadmap

    Define the actions, responsible parties, dependencies, deadlines, necessary resources, and monitoring metrics.


  5. Support the implementation

    Oversee initiatives, facilitate decision-making, coordinate service providers, and help teams implement the selected measures.


  6. Measure and Improve

    Monitor progress, reassess residual risk, and adjust the roadmap as the environment, the organization, or the threats change.

Which cybersecurity risks should we really prioritize?

Not all vulnerabilities are equally significant. A technical vulnerability becomes a priority when it significantly increases the likelihood or impact of a scenario that could affect business operations.

Business Interruption

System downtime, production stoppages, operational delays, or an inability to serve customers.

Data Loss or Disclosure

A breach of the confidentiality, integrity, or availability of sensitive or strategic data.

Fraud and Financial Losses

Misappropriation of payments, account compromise, CEO fraud, or exploitation of privileged access.

Regulatory and Contractual Risk

Deviations from applicable obligations, customer commitments, partner requirements, or compliance frameworks.

Trust and Reputation

Business and relationship implications of an incident involving customers, partners, employees, or authorities.

A realistic goal is not to eliminate all risks, but to identify those that the organization cannot accept and to prioritize investments where risk reduction is most beneficial.

Cross-functional expertise, from strategy to technical matters

A coherent cybersecurity strategy must bridge the gap between governance and technical realities. I work across the main environments encountered in the enterprise to prevent siloed approaches and gaps in coordination among teams, tools, and responsibilities.

Governance and Risk Management

ISI strategy, policies, risk mapping, roadmap, metrics, governance, vendor management, and support for business units.

Identities, Roles, and Systems

Windows, Linux, Active Directory, IAM/PAM, and EDR/XDR: protecting identities, privileged accounts, endpoints, and servers against compromise and lateral movement.

Networks and Infrastructure

Firewalls, network segmentation, VPNs, IDS/IPS, and Wi-Fi: controlling network traffic, reducing exposure, and limiting the spread of a security breach.

Application Security & DevSecOps

Web Applications, APIs, OWASP, CI/CD, and DevSecOps: Integrating Security into Development, Architectures, and the Delivery Cycle.

Cloud

AWS, Microsoft Azure, and Google Cloud: identities, configurations, resource exposure, governance, and risk management specific to cloud environments.

Data Protection

Encryption, access control, DLP, backups, and resilience: protection of sensitive information and the ability to restore operations after an incident.

Industrial Environments & IoT

Consideration of availability constraints, legacy systems, third-party access, and interactions between IT environments, connected devices, and industrial systems.

Compliance and Standards

NIS2, DORA, ISO 27001, EBIOS Risk Manager, and ANSSI recommendations, when these frameworks are relevant to the organization’s context and obligations.

Support Tailored to Your Organization

An SME, a mid-sized company, a local government, or a highly regulated organization cannot apply exactly the same security model. The level of protection must take into account the business, dependencies, obligations, maturity level, and the resources actually available.

Small and Medium-Sized Enterprises (SMEs) and Mid-Sized Companies

Prioritize investments, establish a governance structure, and move forward without replicating the resources of a large corporation.

Local Governments

Protect critical services, data, and business continuity in environments that are often heterogeneous.

Health

Take into account system availability, data sensitivity, and business continuity requirements.

Industry

Balancing production continuity, legacy environments, third-party access, and the security of connected systems.

Finance and Insurance

Balance risk management, operational resilience, governance, and applicable regulatory requirements.

E-commerce and SaaS

Secure availability, accounts, customer data, APIs, the cloud, and the development pipeline without slowing down business operations.

Cybersecurity consultant, outsourced CISO, or IT service provider?

These roles are not necessarily overlapping. A consultant or an outsourced CISO can work with IT teams and existing service providers to set priorities, manage risks, and oversee security without taking over the day-to-day operations of the information system.

Differences Between a Cybersecurity Consultant, an Outsourced CISO, and an IT Service Provider
Need Cybersecurity Consultant Outsourced Chief Information Security Officer IT Service Provider
One-time diagnosis or assessmentYesYesVariable
Ongoing Cybersecurity ManagementDepending on the assignmentYesUsually partial
Governance and Risk ManagementYesYesVariable
Audit or Specialized AssessmentYesDepending on the scopeVariable
Day-to-Day IT OperationsNo, unless there is a specific assignmentNo, unless otherwise agreed uponYes
Regular communication with managementDepending on the assignmentYesVariable

Why Choose Mobhitech?

Profile of Gérard Levicki, Cybersecurity Consultant

Gérard Levicki

Cybersecurity Consultant — Founder of Mobhitech

More than 25 years of experience and a point of contact who is directly involved

Gérard Levicki directly oversees every Mobhitech project, from the initial analysis to the implementation of recommendations. He has more than 25 years of experience in the cybersecurity field, having held leadership roles in major technology organizations prior to founding Mobhitech.

2000Early Career
2006BT Interview · Monaco Conference
9+ yearsFreelancer · Mobhitech

This length of service is also documented in public statements: Gérard Levicki was notably introduced as Head of Security and Mobility at BT during an interview conducted at the Conference on Security and Information Systems in Monaco in 2006.

Learn about Gérard Levicki's career Watch the 2006 interview

A Vision for Risk and Business

A security measure is only valuable if it actually protects the business. Each recommendation is therefore evaluated in terms of the reduced risk, its operational impact, and the resources required.

Prioritized Recommendations

The goal is not to produce a long list of findings. The actions are contextualized, prioritized, and translated into a roadmap to help management and teams make decisions.

Appropriate Budgets

An SME does not have the same resources as a large corporation. Action plans are tailored to the level of risk, maturity, constraints, and actual capacity for implementation.

View Gérard Levicki's LinkedIn profile

What You Actually Get

Deliverables depend on the assignment. They may include, among other things:

  • an assessment that is understandable to management and the technical teams;
  • identification and prioritization of the main risks;
  • priority vulnerabilities, gaps, or scenarios;
  • immediate action when the situation requires it;
  • a short-, medium-, and long-term roadmap;
  • the resources, dependencies, and responsibilities associated with the actions;
  • indicators for tracking progress and residual risk.

A penetration test, an outsourced CISO assignment, an audit, or NIS2 support obviously do not produce the same deliverables: the format must be tailored to the expected decision.

Cybersecurity Consultant in the Île-de-France region, throughout France, and internationally

Based in Cachan, in the Île-de-France region, I work with companies and organizations on-site when the assignment requires it, or remotely throughout France. Some assignments can also be carried out internationally.

The approach depends on the context: governance workshops, audits, ongoing support, technical projects, or crisis situations do not all require the same approach.

Frequently Asked Questions About Cybersecurity Consulting

What is a cybersecurity consultant?

A cybersecurity consultant helps an organization identify, assess, and mitigate its digital risks. They may provide expertise in strategy, governance, audits, technical security, compliance, incident response, or the management of a security program.

When Should You Conduct a Cybersecurity Audit?

An audit is particularly useful when an organization lacks visibility into its security posture, is preparing for a major transformation, must comply with new requirements, is experiencing recurring incidents, or wants to verify the effectiveness of its existing security measures.

What is the difference between a cybersecurity consultant and an outsourced CISO?

A consultant may be brought in on an ad hoc basis for a diagnostic assessment, an audit, a project, or a targeted expert analysis. An outsourced CISO typically provides more ongoing oversight: governance, risk management, roadmap development, coordination, and reporting to senior management.

Is an IT service provider enough to manage cybersecurity?

It depends on the scope and responsibilities of the role. An IT service provider can effectively manage operations and certain security measures, while a consultant or CISO often provides a distinct role in governance, independent assessment, risk management, and prioritization.

How much does a cybersecurity consultant cost?

The cost depends on the scope, duration, level of expertise required, whether the assignment is one-time or recurring, any operational constraints, and the level of urgency, if any. An initial assessment helps define the need before determining the scope of support.

How can you prioritize cybersecurity on a limited budget?

Start with critical assets and processes, then prioritize risk scenarios based on their likelihood and impact. Investments can then be focused on the measures that most effectively reduce the highest-priority risks.

How long does it take to improve your cybersecurity?

There is no one-size-fits-all timeframe. Some vulnerabilities can be fixed quickly, while governance, architectures, processes, and security culture require ongoing work. A roadmap helps distinguish between immediate actions and structural improvements.

Can we work with Mobhitech without replacing our current service providers?

Yes. The consultant’s role may be to supplement existing skills, challenge certain decisions, set priorities, and coordinate the stakeholders already involved—without taking over their operational responsibilities.

Free Initial Assessment — Identify Your True Priorities

Are you unsure about your security level, have a project that needs to be secured, a regulatory requirement to prepare for, or an incident to manage? Let’s start by discussing your situation, your constraints, and what absolutely must continue to function.

The goal of this initial discussion is to clarify the situation and identify the next useful steps, without automatically steering you toward an overly ambitious project.

Privacy: Information provided during our communications is treated confidentially and is not shared with third parties without consent.