Skip to content
Skip to content

Mobhitech — Gérard Levicki

Cybersecurity Services for Businesses and Organizations

Outsourced CISO services, consulting, auditing, penetration testing, compliance, incident response, and training: Choose the support that best fits your risks, your level of maturity, and your business priorities.

Each service can be deployed separately or integrated into a more comprehensive approach. The goal is not to increase the number of services, but to identify what is truly useful, in what order, and with what level of effort.

Which cybersecurity service should you choose based on your needs?

The right starting point depends on your situation. A company lacking governance, an organization subject to NIS2, and a team dealing with a security breach do not share the same sense of urgency or the same needs.

Need, recommended service, and desired outcome
Your needs Recommended Service Main Objective
You don't have a structured cybersecurity management frameworkOutsourced Chief Information Security OfficerGovernance, Roadmap, and Long-Term Monitoring
You need to make a decision or finalize a projectCybersecurity AdvisoryArbitrating with a focus on risk, technical aspects, and business
You don't know where your main weaknesses lieCybersecurity AuditAssess the current situation and prioritize corrections
Do you want to test the strength of a perimeter?Penetration TestIdentify exploitable attack vectors
Are you preparing for NIS2, DORA, ISO 27001, or a risk management initiative?Compliance and Risk ManagementTurning Requirements into Actionable Steps
You are experiencing or suspect a cyberattackIncident ResponseContain, Understand, Decide, and Restore
Do you want to reduce the risk associated with human behavior?Awareness and TrainingDevelop reflexes suited to real-life situations

Mobhitech Cybersecurity Services

Our services address the key needs of an SME, a mid-sized company, or an organization seeking to structure, assess, or strengthen its cybersecurity. Each page below details the scope, use cases, and deliverables specific to the project.

Outsourced Chief Information Security Officer

A part-time security leadership role to define strategy, manage risks, assign responsibilities, and monitor action plans—without necessarily hiring a full-time CISO.

  • SSI strategy and governance;
  • risk mapping and management;
  • roadmap and dashboards;
  • coordination of teams and service providers;
  • reporting to management.

This is the best option if: you need ongoing oversight and a clearly designated safety contact.

Learn about the outsourced CISO service

Cybersecurity Advisory

Ad hoc or targeted support to ensure the security of a decision, an architecture, a transformation, or a business project, without disconnecting security requirements from operational constraints.

  • project scoping and risk mitigation;
  • architecture and structural design choices;
  • evaluating solutions and investments;
  • governance and the organization of responsibilities;
  • Prioritization of cybersecurity measures.

A good choice if: you need to make a decision or secure a project, without needing a full-service outsourced CISO role.

Learn About Cybersecurity Consulting

Cybersecurity Audit

An audit transforms impressions into verifiable findings. It evaluates the organization, processes, configurations, or specific environments to identify gaps and high-priority risks.

  • maturity audit;
  • organizational audit;
  • technical and configuration audit;
  • review of sensitive areas;
  • priority-based remediation plan.

This is the best option if: you need to assess the current situation before making investments or developing a roadmap.

Learn About Cybersecurity Audits

Penetration Testing and Intrusion Testing

A penetration test seeks to simulate controlled attack scenarios in order to determine whether certain vulnerabilities can be exploited and how far an attacker could penetrate the tested environment.

  • external penetration test;
  • internal penetration test;
  • web applications and APIs;
  • operational scenarios;
  • Review and prioritization of corrections.

This is the best option if: you already know the scope of your test and want to measure its resilience in practical terms.

Learn About Penetration Testing

Compliance and Risk Management

Regulatory and standards-based requirements are meaningful only when they are translated into decisions, responsibilities, and actionable measures. Support bridges the gap between compliance, risks, and the actual level of security.

  • NIS2 and DORA;
  • ISO 27001 ;
  • EBIOS Risk Manager;
  • risk mapping and assessment;
  • Supplier and Third-Party Security.

A good choice if: you need to organize your compliance efforts, demonstrate risk management, or develop a plan for compliance upgrades.

Learn About Compliance and Risk Management

Incident Response and Crisis Management

When an incident occurs, the priority is to minimize its impact on operations, coordinate decision-making, and ensure access to sufficiently reliable information to contain the situation and then prepare for recovery.

  • cyber crisis management;
  • coordination of the investigation;
  • containment and remediation;
  • PCA / PRA, when applicable;
  • post-incident support.

Recommended if: a security breach has been confirmed or is suspected, or if your organization needs to build its capacity to manage a crisis.

Under attack? See the incident response

Awareness and Training

Human behavior is part of the safety system. Awareness-raising efforts must be tailored to individuals’ roles, the risks they face, and the decisions they may be called upon to make.

  • employee awareness;
  • executive training;
  • workshops for IT teams;
  • phishing campaigns and exercises;
  • conferences and safety culture.

Recommended if: you want to improve reflexes, reduce preventable errors, and better prepare teams for incidents.

Learn About Awareness and Training

Should you combine multiple cybersecurity services?

Yes, when the needs are related, but not as a matter of principle. For example, an audit may reveal the need for a penetration test, an NIS2 initiative may lead to the establishment of an outsourced CISO role, and an incident may result in a remediation and awareness program.

Mobhitech’s approach is to start with the risk and the desired objective, and then draw only on the expertise that is necessary. A one-time service should not be artificially turned into a long-term program if the need does not warrant it.

Building a Cybersecurity Framework That Is Still in Its Early Stages

Initial audit → risk prioritization → roadmap → outsourced CISO if ongoing oversight is required.

Securing a Project or a Critical System

Consulting and Scope Definition → Architecture Review → Penetration Test or Targeted Audit Before Going Live.

Preparing for NIS2 or DORA

Scope analysis → gap assessment → risk management → action plan → governance and monitoring.

After a cyberattack

Incident response → remediation → lessons learned → targeted audit → strengthening of governance and awareness-raising as needed.

How Can We Develop the Right Cybersecurity Support?

The service is not selected from a catalog, but rather based on the problem to be solved and the associated level of risk.


  1. Defining the Need

    Understanding your business, your context, your constraints, and what drives demand.


  2. Identify priorities

    Distinguish between immediate risks, structural needs, and issues that can wait.


  3. Choosing the Right Scope

    Define the specific service required: audit, project management, testing, compliance, consulting, training, or incident response.


  4. Produce actionable results

    Present findings, decisions, responsibilities, and actions in a format that is understandable to the relevant parties.


  5. Follow when it's helpful

    Support corrective action, monitoring, or continuous improvement when the circumstances warrant ongoing follow-up.

Support provided directly by Gérard Levicki

Mobhitech is an independent cybersecurity consulting firm. Gérard Levicki is directly involved in projects using an approach that integrates technical expertise, risk management, governance, and business considerations. He has more than 25 years of experience in the cybersecurity field.

Learn about Gérard Levicki's career and expertise

Frequently Asked Questions About Cybersecurity Services

Which cybersecurity service should you start with?

If your priorities aren't clear yet, an assessment or audit can usually help you take stock of the situation. If the issue has already been identified—compliance, an incident, a penetration test, or a governance need—it's best to start directly with the relevant department.

What is the difference between a cybersecurity audit and a penetration test?

An audit may cover the organization, processes, configurations, or overall maturity. A penetration test is a targeted offensive test that seeks to exploit vulnerabilities within a defined scope in order to assess realistic attack vectors.

What is the difference between cybersecurity consulting and an outsourced CISO?

Consulting typically addresses a specific issue, decision, or project. The outsourced CISO takes charge of more regular oversight of governance, risks, the roadmap, and the stakeholders involved.

Can we order a single service without long-term support?

Yes. An audit, a penetration test, a consulting engagement, or training can be conducted independently. Follow-up services are offered only when they address an identified need.

Can Mobhitech work with our IT service provider or our in-house team?

Yes. These assignments can complement existing skills, provide an independent perspective, and coordinate efforts without replacing the teams or service providers responsible for day-to-day operations.

Are the services tailored to small and medium-sized businesses?

Yes. The scope and level of effort are determined based on the risks, the organization’s size, its maturity, its obligations, and its available resources.

Do you only serve the Île-de-France region?

No. Mobhitech is based in Cachan and provides on-site services as needed, as well as remote services throughout France. Some projects can also be carried out internationally.

Still not sure which service to choose?

The initial assessment we offer helps us understand your situation, identify the top risks, and determine whether an audit, an outsourced CISO, a penetration test, a compliance engagement, consulting, or other support is truly necessary.

The goal: to choose the right procedure before selecting the service.