<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jules Haddad, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/jules-haddad/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/author/jules-haddad/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 08 Oct 2024 14:22:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Jules Haddad, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/author/jules-haddad/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>IRM, a tool to better manage internal risks in the M365 ecosystem</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/03/irm-a-tool-to-better-manage-internal-risks-in-the-m365-ecosystem/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/03/irm-a-tool-to-better-manage-internal-risks-in-the-m365-ecosystem/#respond</comments>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Thu, 02 Mar 2023 10:00:00 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[IRM]]></category>
		<category><![CDATA[M365]]></category>
		<category><![CDATA[User]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19911</guid>

					<description><![CDATA[<p>M365 is a true catalyst for collaborative work, having to respond to the increase in internal threats that result. The importance of the M365 suite in business The Microsoft 365 software suite offers a critical set of collaborative services for...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/03/irm-a-tool-to-better-manage-internal-risks-in-the-m365-ecosystem/">IRM, a tool to better manage internal risks in the M365 ecosystem</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1>M365 is a true catalyst for collaborative work, having to respond to the increase in internal threats that result.</h1>
<h2>The importance of the M365 suite in business</h2>
<p>The Microsoft 365 software suite offers a critical set of <strong>collaborative</strong> <strong>services </strong>for businesses (<em>Figure 1</em>). These collaborative services handling a large volume of potentially sensitive data need to be secured, thanks to tools. Microsoft has therefore made available a range of security products, to reduce these risks.</p>
<p> </p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-19934 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN.png" alt="" width="4135" height="2176" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN.png 4135w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN-363x191.png 363w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN-768x404.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN-1536x808.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image1-EN-2048x1078.png 2048w" sizes="(max-width: 4135px) 100vw, 4135px" /></p>
<p style="text-align: center;"><em>Figure 1 &#8211; The features of the M365 suite.</em></p>
<p> </p>
<h2>Internal threats are often forgotten but increasingly present</h2>
<p>The M365 tenants, like any computer system, obviously represent a <strong>potential target for external attackers</strong>. However, the <strong>internal threat</strong> should not be underestimated, especially since the proportion and impact of the latter is not negligible.  Indeed, in 2020 in North America, nearly <strong>19%<a href="#_ftn1" name="_ftnref1">[1]</a> of threat actors come from inside the</strong> <strong>company</strong>. Different categories of insider threats can be distinguished:</p>
<ul>
<li><strong>Sabotage </strong>designates an internal employee using legitimate access to damage or destroy company systems or data in order to harm the company;</li>
<li><strong>Fraud</strong>, represented by the modification or destruction of data by an insider for personal gain;</li>
<li><strong>Data</strong> <strong>theft</strong> where the insider steals the company&#8217;s intellectual property in order to resell it or keep it for himself or for an upcoming job. The insider may also steal information for another organization (competitors or governments for example), for the purpose of carrying out industrial or government espionage;</li>
<li><strong>Clumsiness</strong> that comes from mistakes or unintentional actions performed by a negligent employee.</li>
</ul>
<p>These threats are also associated with potential actors:</p>
<ul>
<li><strong>Malicious employees</strong> with the aim of carrying out acts of sabotage (e.g. modification or deletion of data).</li>
<li><strong>Employees leaving a company</strong>, especially if they leave it forcibly. In this case, the biggest associated threat is data theft. According to a study<a href="#_ftn2" name="_ftnref2"><sup>[2]</sup></a>, 70% of employees say they take with them the work they have produced for the company, even though it does not belong to them.</li>
<li><strong>The internal agent</strong> who is a person working for an external group to allow them to access company resources. These people may have been subjected to methods of corruption or even blackmail.</li>
<li><strong>Disobedient people</strong> who circumvent company&#8217;s security policies, for example by using personal online data storage solutions, creating a risk of data leakage.</li>
<li><strong>External workers who </strong>are <strong>not employees</strong> but who have access to the company&#8217;s information system (service providers, suppliers, partners, etc.).</li>
<li><strong>Careless</strong> workers, who are not aware that their actions lead to vulnerabilities for the company. Indeed, in most cases, security breaches involving an employee are not intentional, but come from negligent workers (in 56% of cases in 2021<a href="#_ftn3" name="_ftnref3"><sup>[3]</sup></a>). For example, an employee may lose or have an unencrypted device with sensitive data stolen that could put the business at risk. Or just share files to the wrong people or delete important items without realizing it.</li>
</ul>
<p> </p>
<h2>Microsoft&#8217;s response to these insider threats</h2>
<p>One of Microsoft&#8217;s challenges today is to help its customers protect themselves against internal risks. Currently, Microsoft offers a group of solutions to combat insider threats called:  &#8220;<strong>Microsoft Purview</strong>&#8220;, formerly known as &#8220;compliance center&#8221; (<em>see Figure 2<a href="#_ftn4" name="_ftnref4"><strong>[4]</strong></a></em>).</p>
<p>This group includes</p>
<ul>
<li>&#8220;<strong>Communication compliance</strong>&#8220;: minimizing communication risks by making it possible to detect, capture and act on risky messages within an organization;</li>
<li>&#8220;<strong>Information barriers</strong>&#8220;: restrict communication and collaboration between 2 groups to avoid internal conflicts of interest;</li>
<li>&#8220;<strong>Privileged access management</strong>&#8220;: control access to administrator tasks in Exchange Online to avoid access rights that are too high.</li>
</ul>
<p>Finally, Microsoft Purview is also newly composed of the   &#8220;<strong>Insider Risk Management</strong>&#8221; (IRM) module. This module helps minimize internal risks by detecting, investigating and acting on malicious or unintentional activities within an organization.</p>
<p><img decoding="async" class="aligncenter wp-image-19961 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN.png" alt="" width="4307" height="1500" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN.png 4307w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN-437x152.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN-71x25.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN-768x267.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN-1536x535.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image2-EN-2048x713.png 2048w" sizes="(max-width: 4307px) 100vw, 4307px" /></p>
<p style="text-align: center;"><em>Figure 2 &#8211; Microsoft&#8217;s insider threat management modules.</em></p>
<p> </p>
<h1>Insider Risk Management, the Microsoft solution that helps organizations address some of these insider threats.</h1>
<p>As explained earlier, IRM helps minimize internal risks. Concretely, the tool works in different phases (which will be detailed later) and is based on proven data from Microsoft workflows. It has pre-established data leakage scenarios such as an employee&#8217;s resignation or dissatisfaction. These scenarios facilitate the analysis of risky activities by providing context. The tool will be able to use metadata related to the targeted scenario, such as the dates of departure or annual maintenance of an employee for example. Thus, it will be able to assess the level of risk of users and generate alerts at the appropriate time.</p>
<p>For this, Insider Risk Management uses different modules of M365. IRM is an advanced solution and therefore requires specific licenses. To be able to use this module, there are several licensing possibilities:</p>
<p> </p>
<p><img decoding="async" class="aligncenter wp-image-19938 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN.png" alt="" width="3839" height="2082" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN.png 3839w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN-352x191.png 352w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN-768x417.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN-1536x833.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image3-EN-2048x1111.png 2048w" sizes="(max-width: 3839px) 100vw, 3839px" /></p>
<p style="text-align: center;"><em>F</em><em>igure 3 &#8211; Three ways to get Insider Risk Management with Microsoft licenses.</em></p>
<p> </p>
<h2>A tool that works in 6 phases</h2>
<p>The first is the <strong>strategy</strong> creation phase, which defines the triggering events and risk indicators leading to the generation of alerts.</p>
<p>The second is<strong> detection</strong>, when a user&#8217;s activities begin to be analyzed by IRM as a result of suspicious activity (triggering event).</p>
<p>The third is a phase <strong>of generation of alerts</strong>, they are automatically generated by the risk indicators defined in the strategies.</p>
<p>Once an alert is lifted, IRM provides a <strong>triage</strong> step that allows administrators to classify alerts based on severity and other parameters.</p>
<p>Then comes the <strong>inspection</strong> phase which allows to analyze in depth all the activities related to a user and an alert thanks to the creation of a deep analysis file (&#8220;case&#8221;).</p>
<p>Once the alert has been processed, the <strong>action</strong> phase intervenes. It consists of resolving the analysis case, either by alerting the user to unusual behavior, or by alerting the organization&#8217;s stakeholders (legal, IS, human resources, etc.) who can take appropriate action.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-19959 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN.png" alt="" width="4393" height="1624" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN.png 4393w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN-437x162.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN-768x284.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN-1536x568.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image4-EN-2048x757.png 2048w" sizes="auto, (max-width: 4393px) 100vw, 4393px" /></p>
<p style="text-align: center;"><em>Figure 4 &#8211; The 6 phases of IRM operation.</em></p>
<p> </p>
<p>To work, Insider Risk Management <strong>fully integrates with the M365 components of the tenant</strong> on which it is deployed<em> (see diagram in Figure 5).</em>  Indeed, the data received from other modules allows the <strong>analysis of workflows and different activities.</strong></p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-19942 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN.png" alt="" width="4290" height="2386" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN.png 4290w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-343x191.png 343w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-768x427.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-1536x854.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-2048x1139.png 2048w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image5-EN-1170x650.png 1170w" sizes="auto, (max-width: 4290px) 100vw, 4290px" /></p>
<p style="text-align: center;"><em>Figure 5 &#8211; Overall IRM architecture diagram</em></p>
<p> </p>
<h2>To begin, define detection strategies</h2>
<p>As presented above, the first step is the definition of strategies, which are based on one of the 5 scenarios established by Microsoft: </p>
<ul>
<li><strong>Data theft</strong>: Combating the theft of company data for the purpose of profiting or personal interest. This scenario applies to users leaving the company (voluntarily or not).</li>
<li><strong>Data</strong> <strong>leakage</strong>: Fight against the intentional or unintentional sharing of sensitive information.</li>
<li><strong>Misuse of health data</strong>: Combatting the illegal exploitation of health information by employees.</li>
<li><strong>Violation of security policies</strong>: Combating the installation of malware and the uninstallation or disabling of certain services.</li>
<li><strong>Dangerous use of browsers</strong>: Detects browsing behavior that may not be acceptable by the company&#8217;s charter (visiting sites that incite hatred, with adult content) or present a threat (phishing sites).</li>
</ul>
<p>These scenarios are available as templates to feed strategies and can include any type of user in an organization, but IRM allows for more precision and more meaning and context by targeting specific categories of users. Here are the 3 types of actors offered by Microsoft:</p>
<ul>
<li><strong>Disgruntled users</strong>: Employee’s behavior can be influenced by many events such as performance evaluation or organizational changes (including &#8220;demotion&#8221; in the organization). To do this, IRM allows you to import data related to performance and organization.</li>
<li><strong>Employees leaving the company</strong>: An employee can change companies or be fired and therefore become a threat to the organization they worked for.</li>
<li><strong>Priority users</strong>: Users with privileged access or with high-risk responsibilities.</li>
</ul>
<p>To detect these cases, IRM allows you to import data from HR tools (evaluation, organization, resignations, dismissal), and data related to user authorizations.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-19946 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN.png" alt="" width="3432" height="1797" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN.png 3432w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN-365x191.png 365w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN-768x402.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN-1536x804.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image6-EN-2048x1072.png 2048w" sizes="auto, (max-width: 3432px) 100vw, 3432px" /></p>
<p style="text-align: center;"><em>Figure 6 &#8211; Components of an Internal Risk Management Strategy</em></p>
<p> </p>
<p>The definition of detection strategies (scenarios and actors) allows you to configure the associated list of triggering.</p>
<p>If we take as an example, the &#8220;data leak&#8221; scenario, it includes a <strong>set of indicators and triggering events</strong> to prevent accidental and intentional data leaks. But <strong>depending on the users targeted by this strategy</strong>, the indicators and triggering events will be different<em> (see table below).</em> In this example, the policy can apply to all users, to priority users (for example, a group of users working on sensitive data), or to disgruntled users (for example, a focus on users who have been denied their promotion).  The detection mechanism and the importance of indicators and triggering events specific to the selected user profiles are detailed in the rest of this article.</p>
<table style="width: 100%;" width="720">
<tbody>
<tr>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 14.4048%;" width="104">
<p> </p>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 27.1429%;" width="198">
<p><strong><span style="color: #ffffff;">All users</span></strong></p>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 27.1429%;" width="198">
<p><strong><span style="color: #ffffff;">Priority users</span></strong></p>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 30%;" width="219">
<p><strong><span style="color: #ffffff;">Disgruntled users</span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 14.4048%;" width="104">
<p><span style="color: #ffffff;"><strong>Triggering events</strong></span></p>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 27.1429%;" width="198">
<ul>
<li>The user performs selected exfiltration activities that exceed specific thresholds.</li>
<li>The user performs an activity that matches the specified DLP policy.</li>
</ul>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 27.1429%;" width="198">
<ul>
<li>The user performs selected exfiltration activities that exceed specific thresholds.</li>
<li>The user performs an activity that matches the specified DLP policy.</li>
</ul>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 30%;" width="219">
<ul>
<li>Detection of dissatisfaction in messages.</li>
<li>Detection of changes in user&#8217;s performances and attributed task level.</li>
</ul>
<p> </p>
</td>
</tr>
<tr>
<td style="border-style: solid; border-color: #ffffff; background-color: #503078; width: 14.4048%;" width="104">
<p><span style="color: #ffffff;"><strong>Indicators</strong></span></p>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 27.1429%;" width="198">
<ul>
<li>File sharing from SharePoint.</li>
<li>Printing files.</li>
<li>Copy data to personal cloud storage services.</li>
</ul>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 27.1429%;" width="198">
<ul>
<li>File sharing from SharePoint.</li>
<li>Printing files.</li>
<li>Copy data to personal cloud storage services.</li>
</ul>
</td>
<td style="border-style: solid; border-color: #ffffff; background-color: #f1eef4; width: 30%;" width="219">
<ul>
<li>Downloading files from SharePoint near a triggering event. ​</li>
<li>Printing files near a triggering event.</li>
<li>Copy data to personal cloud storage services near a triggering event.</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p> </p>
<p> </p>
<h2>Next, detect suspicious activities</h2>
<p>Once the policy creation phase is complete, the <strong>detection phase</strong><em> (Figure 7)</em> is used to generate alerts.  This step is the most important for detecting malicious behavior. It should be noted that <strong>without a triggering event</strong> present in an internal risk management strategy, user activities <strong>are not analyzed by IRM</strong>.  The triggering events are related to the chosen detection scenario. As said before, this can be a resignation date or massive exfiltration activities (printing, downloading, copying to USB, sending email, etc.) or deletion.  Triggering events can also be a <strong>sequence of actions</strong>, such as when a file is downloaded, then exfiltrated and finally deleted.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-19950 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN.png" alt="" width="3914" height="594" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN.png 3914w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN-437x66.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN-71x11.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN-768x117.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN-1536x233.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/03/Image7-EN-2048x311.png 2048w" sizes="auto, (max-width: 3914px) 100vw, 3914px" /></p>
<p style="text-align: center;"><em>Figure 7 &#8211; Focus on the detection process.</em></p>
<p>After a user performs a triggering event, he become the target of the associated detection policy. From then on, the activities of the users defined in this strategy by the<strong> risk indicators</strong> are analyzed. Risk indicators can be indicators related to <strong>Office</strong> activities (manipulating files on SharePoint, OneDrive, Teams &#8230;), activities <strong>on devices</strong> (printing, renaming, creating hidden files, using USB keys, installing software&#8230;), <strong>browsing activities</strong> (accessing malicious sites, dangerous content&#8230;) and <strong>activities</strong> of other <strong>cloud applications</strong> (thanks to Microsoft Defender for Cloud Apps).  If one of these indicators exceeds a certain threshold (defined via the policy), then an alert is <strong>generated</strong> and if the <strong>alert is confirmed</strong> by an IRM administrator as not a false positive, a <strong>case</strong> is opened to be able to <strong>analyze</strong> in <strong>detail </strong>the <strong>activities</strong> of the targeted user.</p>
<p> </p>
<h2>Finally, process the generated alerts</h2>
<p>When a <strong>threat is confirmed</strong> and an <strong>in-depth scan file has been opened</strong>, IRM and global admins can then observe the content that has been downloaded, shared, printed, viewed, etc. This then allows stake holders to <strong>decide on the action to be taken in the face of the threat</strong>. We can either send a notification to the user concerned or escalate the case for investigation. However, it is important to remember that Insider Risk Management, <strong>does not allow to restrict the actions of a malicious user</strong>, it remains a <strong>tool of alert and inspection</strong> facilitating decision-making.  </p>
<p> </p>
<h1>IRM is a powerful and promising solution but is not yet sufficiently mature</h1>
<p>While Insider Risk Management requires a <strong>good understanding of all M365 services and Azure AD,</strong> it leverages <strong>the capabilities of security services</strong> to provide a better protection against insider threats.  As described earlier, Insider Risk Management is a very effective tool, which <strong>analyzes all workflows</strong> and easily <strong>adapts to the activities</strong> of companies and users.</p>
<p>However, some points remain to be clarified and improved.  Indeed, the effectiveness of IRM is contrasted by its <strong>rather high reaction time</strong> (about 12 hours to detect activities) and its <strong>interface which is not intuitive enough</strong>. Also, Microsoft <strong>documentation can be complicated</strong> to understand or even false in some cases (wrong date format for HR data for example). In addition, in the current situation, the scenarios presented<strong> could be</strong> monitored<strong> by a company&#8217;s SOC teams</strong> (via specific scripts, or alerts for example). Therefore, the tool is still <strong>less used by companies</strong>.  Nevertheless, the evolution of the <strong>maturity of this tool needs to be carefully monitored</strong>, as <strong>regular</strong> <strong>changes are made</strong> (such as the addition of new detection scenarios).</p>
<p> </p>
<h1>In conclusion, what questions should be asked at the outset?</h1>
<p>Define the <strong>concrete use cases to be covered</strong> and evaluate the <strong>added value compared to existing alerting</strong> (within the SOC).</p>
<p>Evaluate the impact <strong>of this tool on personal data, given its operating power.</strong></p>
<p><strong>Think about the organization to implement (responsibilities</strong>, <strong>alert handling</strong> process<strong>, strategy evolution process).</strong></p>
<p> </p>
<p> </p>
<p><a href="#_ftnref1" name="_ftn1">[1]</a> Source: Verizon&#8217;s 2021 Data Breach Investigations Report (<a href="https://www.verizon.com/business/resources/reports/2021-data-breach-investigations-report.pdf">link</a>).</p>
<p><a href="#_ftnref2" name="_ftn2">[2]</a> Source: Article &#8220;What happens to your data when a departing employee leaves? » on S2|DATA (<a href="https://s2data.com/employee-exit-process/">link</a>).</p>
<p><a href="#_ftnref3" name="_ftn3">[3]</a> Source: 2022 Cost of Insider Threats Global Report from Ponemon Institute (<a href="https://www.proofpoint.com/sites/default/files/threat-reports/pfpt-uk-tr-the-cost-of-insider-threats-ponemon-report.pdf">link</a>).</p>
<p><a href="#_ftnref4" name="_ftn4">[4]</a> Based on Microsoft documentation for the Insider Risk Management product.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/03/irm-a-tool-to-better-manage-internal-risks-in-the-m365-ecosystem/">IRM, a tool to better manage internal risks in the M365 ecosystem</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/03/irm-a-tool-to-better-manage-internal-risks-in-the-m365-ecosystem/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MS365 101: Manage Azure AD B2B Guest Identities</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/08/ms365-101-manage-azure-ad-b2b-guest-identities/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/08/ms365-101-manage-azure-ad-b2b-guest-identities/#respond</comments>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Wed, 03 Aug 2022 13:21:16 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure AD]]></category>
		<category><![CDATA[Collaboration]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[O365]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=18362</guid>

					<description><![CDATA[<p>The use of &#8220;guest&#8221; identities to facilitate collaboration externally   The need for collaboration externally entails risks for companies Companies have always needed to collaborate with each other by sharing resources and exchanging data. To do this, their collaborators must...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/08/ms365-101-manage-azure-ad-b2b-guest-identities/">MS365 101: Manage Azure AD B2B Guest Identities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1 style="text-align: justify;">The use of &#8220;guest&#8221; identities to facilitate collaboration externally</h1>
<h2> </h2>
<h2 style="text-align: justify;">The need for collaboration externally entails risks for companies</h2>
<p style="text-align: justify;">Companies have always <strong>needed to collaborate</strong> with each other by sharing resources and exchanging data. To do this, their collaborators must be able to <strong>interact securely </strong>with users outside their environment.</p>
<p style="text-align: justify;">Several<strong> use cases</strong> can be applied, including <strong>time-bound collaboration with partners</strong>, external service providers, suppliers or B2B customers.</p>
<p style="text-align: justify;">Additionally, it is common to observe<strong> continuous collaboration between subsidiaries</strong> of the same group that have access to the resources and data of the company whilst not necessarily requiring to share the same Information Systems.</p>
<p style="text-align: justify;">Historically, collaboration could be achieved in several ways. However, collaboration also comes with certain disadvantages:</p>
<ul style="text-align: justify;">
<li>By <strong>successive exchange of emails</strong> &#8211; which can be inefficient and can result in a loss of control of the data exchanged;</li>
<li>By <strong>using solutions dedicated</strong> to share documents with third parties &#8211; which can be costly and unsuitable from a user experience point of view;</li>
<li>By <strong>creating a new identity in legacy systems</strong> (Active Directory, etc.), and by providing third-party entities with a means to access the company&#8217;s IS (VPN, virtual machines, physical machines, etc.) &#8211; which can significantly increase the company&#8217;s attack surface.</li>
</ul>
<h2> </h2>
<h2 style="text-align: justify;">Microsoft introduced Azure AD B2B to address the need for collaboration</h2>
<p style="text-align: justify;">Today, using Azure AD B2B allows two or more entities to <strong>collaborate within the host company&#8217;s Azure tenant</strong>.  Shared resources can be apps, documents, SharePoint sites, OneDrive, or Teams teams.</p>
<p style="text-align: justify;">In effect, the Azure B2B solution allows an external user to <strong>access the host company tenant through their regular account by</strong> creating a &#8220;guest&#8221; identity within the company&#8217;s Azure Active Directory (AAD).</p>
<p style="text-align: justify;">The &#8220;client&#8221; tenant then fully or partially trusts the &#8220;external&#8221; tenant for authentication via a token exchange mechanism.</p>
<p style="text-align: justify;">There are three native possibilities for creating a &#8220;guest&#8221; identity:</p>
<ul style="text-align: justify;">
<li>Directly from the <strong>Azure portal</strong>;</li>
<li>Via <strong>document sharing</strong> on OneDrive/SharePoint/Teams;</li>
<li>Through the use of the<strong> GRAPH API.</strong></li>
</ul>
<p> </p>
<p><em><img loading="lazy" decoding="async" class="wp-image-18366 size-full aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1.png" alt="" width="4150" height="2385" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1.png 4150w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-332x191.png 332w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-768x441.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-1536x883.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image1-2048x1177.png 2048w" sizes="auto, (max-width: 4150px) 100vw, 4150px" /></em></p>
<p style="text-align: center;"><em>Figure 1 &#8211; Native Operation: Authentication and Identity Creation</em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">At the level of the host tenant, the owner can choose to authorize the sharing of data to external users while also being able to administer guest accounts (creation, deactivation, deletion etc.).</p>
<p style="text-align: justify;">A direct benefit of this solution is the <strong>ease of use</strong> for users who are familiar with Microsoft environments.</p>
<p style="text-align: justify;">The second advantage is the<strong> cost of the solution</strong>. A &#8220;guest&#8221; identity has a licensing cost whereby up to a ceiling of 50,000 &#8220;guest&#8221; identities, their license is free. Beyond this and depending on the company&#8217;s subscriptions, a license may cost between €0.003 and €0.015 / month / user, which is then added on to a fixed fee of €0.029 for each multi-factor authentication attempt. This pricing policy is out of step with the usual price of an M365 license, which is between €10 and €50 / month / user depending on the license plan.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">However, Azure AD B2B has a default configuration that is too open, which creates risks for the company</h2>
<p style="text-align: justify;">Azure AD B2B introduces several factors that can lead to <strong>risk</strong>:</p>
<ul style="text-align: justify;">
<li>The <strong>creation of</strong> guest identities is very simple and uncontrolled (no identity manager, no traceability, no restrictions etc.);</li>
<li>The <strong>number of</strong> guest identities may increase in an uncontrolled manner, which makes managing their lifecycles difficult.</li>
<li>The company does <strong>not control the security</strong> of the initial holder of the &#8220;guest&#8221; identity;</li>
<li>No <strong>conditional access rules</strong> are set up by default (no strong authentication, no restriction of access to the Azure A D portal, etc.);</li>
<li>The &#8220;guest&#8221; identity <strong>has access to the Azure AD attributes</strong> of other users.</li>
</ul>
<p style="text-align: justify;">These factors create risks for the company&#8217;s data since the &#8220;guest&#8221; identity may have rights to a significant number of documents and information about its host owner.</p>
<p style="text-align: justify;">We can consider two triggering events for the different threat scenarios:</p>
<ul style="text-align: justify;">
<li>A <strong>malicious</strong> &#8220;guest&#8221; identity;</li>
<li>A &#8220;guest&#8221; identity <strong>compromised</strong> by an attacker.</li>
</ul>
<p style="text-align: justify;">An attacker would then have the opportunity to:</p>
<ul style="text-align: justify;">
<li><strong>Retrieve confidential data </strong>that the identity has access to;</li>
<li><strong>Destroy all data</strong> accessible by this identity;</li>
<li><strong>Compromise AD</strong> by assigning roles to this identity;</li>
<li><strong>Perform social engineering</strong> through their access to all user data.</li>
</ul>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Depending on the level of maturity of the company and the willingness to hedge risk, it is necessary to implement a number of measures</h1>
<h2> </h2>
<h2 style="text-align: justify;">To get started: harden the default configuration</h2>
<h4> </h4>
<h4 style="text-align: justify;">Master the means to add &#8220;guest&#8221; identities on the tenant</h4>
<p style="text-align: justify;">The first step is to <strong>cut off access to the Azure portal</strong> to non-administrator employees of the company so that it is no longer a vector for creating &#8220;invited&#8221; identities.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18370 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1.png" alt="" width="1595" height="761" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1.png 1595w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1-400x191.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1-768x366.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen1-1536x733.png 1536w" sizes="auto, (max-width: 1595px) 100vw, 1595px" /></p>
<p style="text-align: center;"><em>Figure 2 &#8211; Restricting access to the Azure AD console</em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">It should be noted that it is also possible <strong>to restrict the population who can invite external users to collaborate</strong>. However, this will not be applicable to all companies &#8211; especially those wishing to decentralize the management of this population. The idea of restricting this population forces the creation of a service dedicated to the creation of these identities. This goes against the very principle of this service, which is to leave it in the hands of the user.</p>
<p style="text-align: justify;">Finally, there is a feature to<strong> apply constraints to the email addresses of &#8220;guest&#8221; identities</strong>, via white-listing or domain name blacklisting. However, before embarking on this action, it is necessary to consider the complexity of its implementation and the potential low level of associated risk reduction.</p>
<h4> </h4>
<h4 style="text-align: justify;">Restrict what these identities can access</h4>
<p style="text-align: justify;">It is also possible <strong>to restrict what can be accessed</strong> by the invited identities, so that they are unable to retrieve a large volume of information on the host tenant.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18374 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3.png" alt="" width="1603" height="647" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3.png 1603w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3-768x310.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen3-1536x620.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></p>
<p style="text-align: center;"><em>Figure 3 &#8211; Restrict access for &#8220;guest&#8221; identities</em></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Strengthen authentication and access control of &#8220;guest&#8221; identities</h2>
<p style="text-align: justify;">The <strong>multi-factor authentication (MFA)</strong> mechanism for a &#8220;guest&#8221; identity is almost native and reduces the risk of spoofing by an attacker. It is also possible to set up a <strong>conditional access policy</strong> that specifically targets these &#8220;guest&#8221; identities.</p>
<p> </p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18372 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen2.png" alt="" width="1063" height="446" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen2.png 1063w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen2-437x183.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen2-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Screen2-768x322.png 768w" sizes="auto, (max-width: 1063px) 100vw, 1063px" /></p>
<p style="text-align: center;"><em>Figure 4 &#8211; Multi-Factor Authentication</em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">However, challenges can still complicate this operation and need to be considered:</p>
<ul style="text-align: justify;">
<li>Managing <strong>change management</strong> on these &#8220;guest&#8221; populations remains complex to perform, even if user onboarding operations are simple and carefully guided.</li>
<li>Managing <strong>second-factor reset processes</strong> in the event of loss or theft can be costly and complex if left unchecked.</li>
</ul>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Educate users about risks and best collaboration practices</h2>
<p style="text-align: justify;">The major complexity of the Azure AD B2B solution is <strong>the lack of a mechanism for managing &#8220;guest&#8221; identities</strong>. Users are therefore the <strong>main actors</strong> of the management strategy and must be informed at the right level by emphasizing:</p>
<ul style="text-align: justify;">
<li>Collaboration <strong>best practices</strong>: when should they use the solution, how to create a guest, and more;</li>
<li><strong>Proper management of their access</strong>: they must be removed as soon as possible in order to avoid subsequent illegitimate access;</li>
<li><strong>Disabling identities when they are no longer in use</strong>, especially for service providers/partners, ensuring that the documents produced are not lost.</li>
</ul>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Protect the data that guests can access</h2>
<p style="text-align: justify;">We must also not forget to protect the data to which a legitimate guest can have access to, which gives rise to several measures:</p>
<ul style="text-align: justify;">
<li>It is possible to set up constraints for &#8220;guest&#8221; identities via <strong>conditional access rules </strong>that include: mandatory use of thin clients (web clients), the prohibition of data downloading, constraints on the terminals to be used, etc.</li>
<li>If the company has deployed the Azure Identity Protection (AIP) classification tool, an alternate solution is to <strong>create a privacy label</strong> that encrypts the data for &#8220;guest&#8221; identities. This label can also be used to restrict certain actions for this population: modification restriction (via associated permissions), download restriction (via a DLP rule), etc.</li>
</ul>
<p style="text-align: justify;">Moving a step further, a <strong>Cloud Access Security Broker</strong> (such as Microsoft&#8217;s MS Defender for Cloud Apps) can enable the implementation of advanced and targeted rules, such as preventing uploads to specific Sharepoint spaces as an example.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Managing the Lifecycle of Guest Identities: 3 Scenarios to Consider</h2>
<p style="text-align: justify;">As mentioned earlier, the key topic is <strong>managing the lifecycle of &#8220;guest&#8221; identities</strong> i.e., the creation, deletion, and review of access. As such, there are 3 scenarios to be considered. These scenarios depend on the desired <strong>risk coverage</strong>, <strong>the level of maturity </strong>of identity and access management, and the <strong>cost of implementing</strong> the scenario.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18368 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2.png" alt="" width="4457" height="2512" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2.png 4457w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-339x191.png 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-768x433.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-1536x866.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-2048x1154.png 2048w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/08/Image2-800x450.png 800w" sizes="auto, (max-width: 4457px) 100vw, 4457px" /></p>
<p style="text-align: center;"><em>Figure 5 &#8211; Guest Identity Lifecycle Management Scenarios</em></p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">Scenario 1 &#8211; Stay pragmatic on a budget: use native tools and configurations</h3>
<p style="text-align: justify;">In this scenario, the company <strong>creates a certain group typology for “External” groups</strong>, and therefore to the creation of guests. The distinction can be made by the use of language by the group. For example: all external groups must start with &#8220;X_&#8221;.</p>
<p style="text-align: justify;">It can thus carry out checks more easily on this limited perimeter of groups.</p>
<p style="text-align: justify;">The main prerequisite is <strong>to block the addition of &#8220;guest&#8221; identities to “Internal” groups. </strong>This is possible in two ways:</p>
<ul style="text-align: justify;">
<li>If the company has deployed the AIP classification tool on SharePoint and Teams spaces: a <strong>dedicated label</strong> can be used to prevent external sharing on these spaces. For example, the creation of an &#8220;Indull&#8221; label that blocks sharing with &#8220;guest&#8221; identities;  &#8211; <a href="https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels-teams-groups-sites?view=o365-worldwide">LINK</a></li>
<li><strong>Via a PowerShell script: </strong>block sharing with &#8220;guest&#8221; identities for &#8220;Internal&#8221; groups by identifying them via classifications. &#8211; <a href="https://docs.microsoft.com/en-us/microsoft-365/solutions/per-group-guest-access?view=o365-worldwide">LINK</a></li>
</ul>
<h4 style="text-align: justify;">Creating a &#8220;guest&#8221; identity</h4>
<p style="text-align: justify;">The only way to create a &#8220;guest&#8221; identity is to add<strong> them as external users to &#8220;External&#8221; group types.</strong></p>
<p style="text-align: justify;">If the company needs to give its tenant access to a subsidiary or an entire entity, it is possible to regularly synchronize their AD or Azure AD, and thus create their identities as a &#8220;guest&#8221; in the tenant of the company.</p>
<h4 style="text-align: justify;">Deleting a &#8220;guest&#8221; identity</h4>
<p style="text-align: justify;">The process of deleting identities is simple through the <strong>deletion of inactive &#8220;guest&#8221; identities. </strong>For example, using a PowerShell script based on the frequency of &#8220;Sign-In Activity&#8221;. Alternatively, it is also possible to remove &#8220;guest&#8221; identities that do not have access to any group via a PowerShell script.</p>
<h4 style="text-align: justify;">Review of &#8220;guest&#8221; access</h4>
<p style="text-align: justify;">It is possible <strong>to expire access for &#8220;guest&#8221; identities</strong> on SharePoint groups or OneDrives after 60 days. Note that the owner of the SharePoint or OneDrive group will be notified of the expiration 21 days beforehand.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18348 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture7.png" alt="" width="1027" height="372" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture7.png 1027w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture7-437x158.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture7-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture7-768x278.png 768w" sizes="auto, (max-width: 1027px) 100vw, 1027px" /></p>
<p style="text-align: center;"><em>Figure 6 &#8211; Guest Access Expiration</em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Finally, it is possible to use the &#8220;Guest Access Review&#8221; feature for external groups. It should be noted, however, that this feature requires advanced licenses (AAD P2) assigned to the users who carry out the reviews i.e. all the owners of the groups (normally a small number).</p>
<p style="text-align: justify;"><strong>This scenario is an efficient way that reduces guest risk, maintains a near-native solution, and doesn’t require too much investment.</strong></p>
<p style="text-align: justify;"><strong> </strong></p>
<h3 style="text-align: justify;">Scenario 2 &#8211; To go further in the level of security: develop a guest management application</h3>
<p style="text-align: justify;">In this second scenario, the company wants to <strong>have complete control over the lifecycle management of &#8220;guest&#8221; identities</strong>. To do this, the company <strong>creates an application</strong> (for example by using Power App) to manage this lifecycle, making it the single point of creation and deletion.</p>
<p style="text-align: justify;">Once this lifecycle is in place, it is necessary to set the SharePoint sharing setting to &#8220;Existing guest only&#8221; mode, allowing only content to be shared with &#8220;guest&#8221; identities that already exist in the Azure AD tenant. This prevents the creation of new identities through this vector.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18350 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture8.png" alt="" width="1048" height="585" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture8.png 1048w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture8-342x191.png 342w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture8-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/Picture8-768x429.png 768w" sizes="auto, (max-width: 1048px) 100vw, 1048px" /></p>
<p style="text-align: center;"><em>Figure 7 &#8211; Restricting Sharing Opportunities</em></p>
<h4 style="text-align: justify;">Creating a &#8220;guest&#8221; identity</h4>
<p style="text-align: justify;">In this scenario, users <strong>use the dedicated application to create the &#8220;guest&#8221; identities</strong> by entering an end date. The user then designates the owner of the identity created.</p>
<h4 style="text-align: justify;">Deleting an &#8220;invite&#8221; identity</h4>
<p style="text-align: justify;">To delete identities, it is possible <strong>to trigger an automatic workflow</strong> before the end date by asking the owner of the identity in question whether to delete it or extend its end date. It should be noted that if the owner has left the company without making the change of ownership, consideration can be given to reassigning the guest to his or her supervisor.</p>
<h4 style="text-align: justify;">Review of &#8220;guest&#8221; access</h4>
<p style="text-align: justify;">With this type of &#8220;in-house&#8221; application, it is complicated to go much further in the management of the lifecycle &#8211; especially when it comes to access review.</p>
<p style="text-align: justify;">It is still possible, as in Scenario 1, to expire guest access or to use the &#8220;Guest Access review&#8221; feature (with the same constraints as stated above).</p>
<p style="text-align: justify;">To go further, we can also consider the use of third-party tools such as IDECSI or Sharegate that make it possible to manage these access journals automatically and intuitively.</p>
<p style="text-align: justify;"><strong>This scenario changes the native behavior and enables better control of the lifecycle, but at a significant blow with regard to the deployment and the management of the change to be implemented.</strong></p>
<h3 style="text-align: justify;">Scenario 2&#8242; &#8211; Integrating &#8220;guest&#8221; identities into traditional IAM processes</h3>
<p style="text-align: justify;">The last scenario to consider is a variant of the previous scenario, where the company still wants to have control over the lifecycle management of &#8220;guest&#8221; identities. In this case, the company can<strong> integrate &#8220;guest&#8221; identity management into its identity and access management (IAM) tools</strong> in the same way as &#8220;external&#8221; identities.</p>
<p style="text-align: justify;">The IAM tool then becomes the <strong>authoritarian source</strong> for this type of population and its management is done directly there.</p>
<p style="text-align: justify;">In this scenario, as in the previous one, you must also set the SharePoint sharing setting to &#8220;Existing guest only&#8221; mode.</p>
<h4 style="text-align: justify;">Creating a &#8220;guest&#8221; identity</h4>
<p style="text-align: justify;">Identities are created on external <strong>creation forms</strong> from IAM tools by choosing the &#8220;guest&#8221; type for the identity. The &#8220;guest&#8221; identity can then be provisioned automatically in the Azure AD by IAM tools.</p>
<h4 style="text-align: justify;">Deleting a &#8220;guest&#8221; identity</h4>
<p style="text-align: justify;">The removal of the identity is also <strong>done by the IAM tool</strong> according to the positioned end date and the workflows already defined.</p>
<h4 style="text-align: justify;">Reviews of &#8220;guest&#8221; access</h4>
<p style="text-align: justify;">In the event that the company&#8217;s IAM tools are used to manage rights on Sharepoint spaces, it is possible to use the <strong>access review capabilities of these tools</strong> to review access to sensitive resources for which &#8220;guest&#8221; identities have access.</p>
<p style="text-align: justify;">Alternatively, a second option is to use access governance features via IAM solutions, such as Sailpoint OneIdentity, or via dedicated Identity and Access Governance solutions, such as Brainwave or Varonis. We can imagine retrieving the rights assigned directly in the Azure AD and having them verified to the owners of the resources through these tools.</p>
<p style="text-align: justify;"><strong>This scenario is a variant of Scenario 2, which allows the most mature companies in identity and access management to capitalize on existing tools and processes.</strong></p>
<h2> </h2>
<h2 style="text-align: justify;">Finally, do not neglect the surveillance of this exposed population</h2>
<p style="text-align: justify;">It is useful to build a form of <strong>adapted reporting using KPIs and dashboards</strong>. A pool of information is available natively in the Azure AD (date of last connection, activity on the tenant as well as on Office 365 via the &#8220;unified audit logs&#8221;). This information can be interacted with via visualization tools, like Power Bi, for the generation of dashboards.</p>
<p style="text-align: justify;">Secondly, it is important to <strong>monitor the activities of these particularly exposed populations</strong>. Two levels of detection can be set up depending on monitoring capabilities:</p>
<ul style="text-align: justify;">
<li>Implement <strong>native DLP rules</strong> or <strong>classic alert scenarios</strong> in the Microsoft console: some alert scenarios are preconfigured, such as mass deletion of documents, elevation of privilege etc.</li>
<li>Implement<strong> advanced DLP rules</strong> and detection scenarios or specific thresholds for guests<strong> with the support of the company&#8217;s SOC</strong>. For example, the data download threshold allowed for a guest may be lower than the threshold allowed for an intern.</li>
</ul>
<p style="text-align: justify;">We can imagine the use of the <strong>Azure AD Identity Protection</strong> module to trigger alerts for guests with a high level of risk.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">In conclusion, AAD B2B greatly facilitates collaboration, but its configuration needs to be hardened to reduce the level of risk induced by the solution</h1>
<p style="text-align: justify;">AAD B2B greatly <strong>simplifies</strong> collaboration with users outside the company, but entails risks<strong> related to the default operation</strong> of the solution. To control these risks, it is necessary to <strong>reduce </strong>the level of open access, and <strong>to control the lifecycle of these identities</strong> at a deeper level, depending on the potential level of investment that is planned. Finally, it is necessary to focus on <strong>monitoring</strong> via native tools or tools used by the company given the high exposure of these populations.</p>
<p style="text-align: justify;"> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/08/ms365-101-manage-azure-ad-b2b-guest-identities/">MS365 101: Manage Azure AD B2B Guest Identities</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/08/ms365-101-manage-azure-ad-b2b-guest-identities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The 2020 French Cyber-Security Startups Radar: our analysis (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-2-2/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Mon, 23 Nov 2020 08:00:52 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[fundraising]]></category>
		<category><![CDATA[radar startups]]></category>
		<category><![CDATA[scale-ups]]></category>
		<category><![CDATA[startups]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14660</guid>

					<description><![CDATA[<p>In a previous article, we shared an initial analysis of the dynamics of the cyber security startup ecosystem in France. The panorama of startups remains constant, with newly created startups already showing great promise. Others, with already several years of...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-2-2/">The 2020 French Cyber-Security Startups Radar: our analysis (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="heading-text el-text">
<p><em>In a previous article, we shared an initial analysis of the dynamics of the cyber security startup ecosystem in France. The panorama of startups remains constant, with newly created startups already showing great promise. Others, with already several years of activity to their credit, have continued to grow, to the point that we had to create a new category: scale-ups. However, this ecosystem is facing two major adversities, such as the current health crisis and the resulting slowdown in international trade. We have therefore tried to envisage the necessary evolutions for this startup ecosystem.</em></p>
<p>&nbsp;</p>
<h2 id="crisis">The health crisis: an activity slowdown but not a halt</h2>
</div>
<div class="uncode_text_column">
<p>Despite a major health crisis having a major impact, <strong>the vast majority of startups remain confident about their future</strong> (more than 80% of the startups surveyed).  Some client companies have even prioritized their cyber security activities to strengthen their position in this unprecedented context.</p>
</div>
<p>&nbsp;</p>
<figure id="post-14675 media-14675" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14675 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-2.png" alt="" width="1012" height="546" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-2.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-2-354x191.png 354w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-2-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-5-2-768x414.png 768w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p>&nbsp;</p>
<div class="uncode_text_column">
<p>Thus, 34% of the startups surveyed stated that they were balanced in terms of business opportunities, with those lost since mid-March having been able to make up for those lost. 21% of them have even seen an increase!</p>
<p>A reassuring figure, to be put into perspective, as more than a third (37%) of them have suffered losses in market share, notably due to investment halt for certain clients. Some still have trouble giving their opinion due to a lack of commercial visibility (8%).</p>
<p>On this last point, the relevance of the sector of activity of these startups to the new challenges brought about by the health crisis is probably related. The majority of those who resist are in fact addressing issues raised by the forced generalization of remote access to information systems: data protection and secure exchanges, monitoring and protection of assets, and access management. The reorientation of their commercial efforts towards resilient sectors, such as healthcare, is probably another factor in these results.</p>
<p>75% of the startups surveyed also took advantage of the period to refocus on R&amp;D or their products marketing.</p>
<p>These figures demonstrate <strong>the ability of startups to cope with the crisis, despite the adversity and uncertainty it brings, through their great flexibility and responsiveness capabilities</strong>. It also highlights <strong>the cybersecurity sector resilience</strong>, as it remains a key challenge for companies. Even in this period of economic crisis, they continue to seek ever more relevant and effective solutions to guarantee their security.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">A particularly visible slowdown in fund raising</span></h3>
</div>
<div class="uncode_text_column">
<p>We compare here two fundraising periods on the whole ecosystem (cybersecurity startups and scale-ups): period 2019-2020 (from July 2019 to June 2020) and period 2018-2019 (from July 2018 to June 2019).</p>
<p><strong>The qualitative resilience of the ecosystem noted above masks a more negative situation on fundraising</strong>. The 100 million euros raised in cyber security over the period 2019-2020 is far less compared to the more than 260 million euros raised in the previous one, 2018-2019.</p>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14677 media-14677" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14677 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-6-1.png" alt="" width="1431" height="769" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-6-1.png 1431w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-6-1-355x191.png 355w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-6-1-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-6-1-768x413.png 768w" sizes="auto, (max-width: 1431px) 100vw, 1431px" /></figure>
<p>&nbsp;</p>
<div class="uncode_text_column">
<div class="uncode_text_column">
<p>However, the 2018-2019 period had been exceptional: 7 radar startups had raised around 10 million euros, 2 were close to 200 million euros alone. Fundraising in previous years had never reached such levels.</p>
<p>2019-2020 has been exceptional as well, but in a very different way. Great fundraisings took place until February: the top 4 was achieved over this period. Unfortunately, the activity was quickly impacted by the health crisis. Several surveys planned between February and April were postponed.</p>
<p>However, a restart was observed in April (<strong>Stamus Networks</strong>) and interesting fundraisings followed in June (e.g. <strong>Didomi, Quarkslab</strong>). These results point to a more successful end of the year.</p>
<p>As also foreseen by ACE-Management (<a href="https://www.riskinsight-wavestone.com/en/2020/11/interview-with-ace-management-2020-french-cybersecurity-startups-radar/"><strong>please find here the interview</strong></a>), a lag effect of a few months in investments seems to be emerging, rather than a decrease, once again highlighting the dynamism of the cybersecurity market.</p>
<p><strong>Another interesting aspect of the 2019-2020 period is that weaker fundraising is on the rise</strong>. 7 startups have raised between 2.5 and 5 million euros compared to only 3 in the previous period. Is this a potential indicator of the growing willingness of startups to raise funds early in order to accelerate their development? Or perhaps we are witnessing the preparation of the next generations of scale-ups? In any case, it is a very positive sign for ecosystem dynamic.</p>
<p>Given the exceptional characteristics of the two periods, it sounds difficult to draw a definitive analysis. We hope to see you next year, as it will be necessary to put those findings in perspective.</p>
<p>&nbsp;</p>
<div class="heading-text el-text">
<h2 id="developments">Developments needed in all facets of the ecosystem to ensure its success</h2>
</div>
<div class="heading-text el-text">
<h3><span lang="EN-US">Clients: take the risk of going beyond POCs</span></h3>
</div>
<div class="uncode_text_column">
<p>Clients also have a key role to play in the development of French startups.</p>
<p>In this respect, we see that companies increasingly trust French startups and support them while testing them: 70% of them carry out “Proof of Concepts” financed by their clients against 67% last year. An increase that we can only welcome, as these investments allow French gems to develop faster.</p>
<p>However, <strong>to continue to support this ecosystem development, it is also necessary to accept the risk of transforming the trial by contracting with the solutions tested</strong>. This year, companies are finding it harder to do this quickly: 30% of them may take more than six months to sign a contract after a POC, compared with 25% in 2019. The health crisis may partly explain this situation.</p>
<p>Working with a startup can certainly be risky, but it is also a gamble on the future. They can provide solutions to problems to which the “traditional” market has not provided answers for many years, enable you to remain at the cutting edge, or even provide greater support for business innovation (e.g. by securing new uses), and ultimately provide major differentiators. Some countries are keen to take this type of risk, and this is less the case in France, but nothing is stopping us from transforming ourselves.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">Startups: know how to identify the next gems from your clients!</span></h3>
</div>
<div class="uncode_text_column">
<p>Even if it seems trivial, it is important to remember how crucial for a startup to position itself on issues that have few or no satisfactory answers on the “classic” market.</p>
<p>To do so, it is essential for startups to be attentive to the needs of their future clients and to position themselves on their crucial issues.</p>
<p>The identification should not only be technological but should also take into account criteria such as the difficulty of integrating the technology into the client’s information system, the existence of established competition or the willingness of the main principals to invest in a new technology. It is the combination of these criteria that makes it possible to identify the topics that will be the most successful on the market!</p>
<p>Products that require the installation of elements on many IS equipments (e.g. a new security agent on workstations) are particularly difficult to “sell” to large companies that are already equipped. More passive approaches are more attractive to them. This can be done even more easily for still rapidly evolving themes such as surveillance or analysis of IS logs.</p>
<p>Competition from large, well-established players can be difficult for a start-up to overcome. This is the case in the EDR market, for example, where strong differentiating arguments will be necessary to break through against major players that are already recognized. Conversely, themes such as cyber-resilience and cryptography, for example, remain under-addressed in relation to market expectations, and would therefore be easier to break through from this point of view.</p>
<p>Finally, the investment willingness of the principals should also be considered. Regarding cryptography, for instance, the arrival of quantum computers is still too far away for it to be part of their imminent concerns, as the horizon in the private sector is certainly around 2023/2024. Data anonymization, while keeping anonymized databases consistency (<em>synthetic data</em>), <em>Data Leakage Prevention</em> or <em>Passwordless</em> are also major concerns for companies, which still do not have satisfactory answers on the market. The rationalization of CISO tools, which are currently more in search of optimization than investment in nth security solutions, is a topic that will be much more considered in the short term.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">Startups: don&#8217;t forget to take advantage of financing and support opportunities!</span></h3>
</div>
<div class="uncode_text_column">
<p>This year, another 32% of the startups surveyed do not plan to raise funds, and more than half of them have never been supported in their development.</p>
<p>Financing and support are nevertheless interesting accelerators, even more in the extremely fast cybersecurity market, where speed of market conquest is a crucial asset.</p>
<p>This lack of willingness to accelerators, which has been observed for several years, can partly be explained by a historical lack of specialized cybersecurity structures in France, making it more complex for startups to exchange information and to make the most of them.</p>
<p>However, the situation has improved and the consideration of cybersecurity at the national level is particularly accelerating this year:</p>
<ul>
<li>The State is mobilizing funds for innovation, particularly in the cybersecurity sector, for which the economic recovery plan provides at least 136 million euros;</li>
<li>A major challenge dedicated to cybersecurity has been launched, the publication of its roadmap in July this year was followed by a call for projects from BPI France with investments of several tens of millions of euros;</li>
<li>The French fund Brienne III, officially launched in June 2019 with a first round of financing at 80 million euros and managed by ACE-Management, specializes in cybersecurity. Other investors do not hesitate today to finance initiatives in this field.</li>
</ul>
<p>So many opportunities to be used for the startups in the ecosystem, and it would be a shame to do without it today. <strong>Current events highlight even more the fact that now is the right time to turn to these accelerators, as cybersecurity appears to be an essential part of the “new world”, where teleworking will remain a long-term phenomenon</strong>.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">Ecosystem: let&#8217;s catalyze and amplify these promising initiatives!</span></h3>
</div>
<div class="uncode_text_column">
<p>As we have seen, initiatives for the development of cybersecurity are springing up: the State is mobilizing (cyberdefense factory, grand défi, sector contract, cyber campus…), investors and incubators are also launching private initiatives.</p>
<p>The state is opening up widely thanks to these initiatives and is adopting an increasingly innovative stance. We hope that this will encourage employees of concerned entities to embark on the entrepreneurial adventure. Indeed, our cyber state actors have unparalleled visibility of the threat and use tools or approaches that would be beneficial to offer to the private sector in the short or medium term. The creation of spin-offs is still too small in France compared to other countries, such as Israel and the United States, where state entities are among the first providers of startuppers.</p>
<p>The challenge now will be to make the most of this diversity of potential energizers of the French cyber ecosystem. The risk would be that these means of supporting the market would compete and disperse, operating in silos, to the point of causing confusion and “blurring” the messages to the players in the ecosystem.</p>
<p>And that would be really damaging. We are at the dawn of a pivotal year for our ecosystem: all the components seem to come together to achieve its transformation and allow it to scale up. The question now seems to be: will we collectively succeed in making this movement a reality? Because in order to do this, it seems essential to us to join forces in presence, to catalyze them towards this common goal. A role that the cyber campus could play?</p>
<p>And that would be really damaging. <strong>We are at the dawn of a pivotal year for our ecosystem: all the components seem to be coming together to achieve its transformation and allow it to scale up</strong>. The question now seems to be: will we collectively succeed in making this movement a reality? In order to do so, it seems essential to join forces and to catalyze them towards this common goal. Is it a role that the Cyber Campus could play?</p>
<p>&nbsp;</p>
<h2 class="heading-text el-text"><span lang="EN-US">2021: the year of fulfillment?</span></h2>
<div class="uncode_text_column">
<p>Despite the impacts of the global health crisis, cybersecurity remains a resilient sector, as the ecosystem of French startups in this field has also demonstrated. Their development projects are sometimes delayed, but they remain confident about their future despite the challenges they have faced and will continue to face.</p>
<p>In this context, it remains essential to continue to support the ecosystem development. Many specialized support services are being created, and <strong>2021 will be a pivotal year for the transformation of our ecosystem and for raising it to an international level</strong>.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-2-2/">The 2020 French Cyber-Security Startups Radar: our analysis (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The 2020 French Cyber-Security Startups Radar: our analysis (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-1-2/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Mon, 23 Nov 2020 07:00:59 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[scale-ups]]></category>
		<category><![CDATA[startups]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14659</guid>

					<description><![CDATA[<p>Towards realization despite adversity? Last year marked the beginning of the French cybersecurity startups ecosystem transformation. This year, many questions are being asked: has the momentum continued despite the health crisis? How has the ecosystem responded? What actions would support it...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-1-2/">The 2020 French Cyber-Security Startups Radar: our analysis (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 class="heading-text el-text"><span lang="EN-US">Towards realization despite adversity?</span></h2>
<div class="uncode_text_column vc_custom_1603380008714 border-color-gyho-color">
<p>Last year marked the beginning of the French cybersecurity startups ecosystem transformation. This year, many questions are being asked: <strong>has the momentum continued despite the health crisis? How has the ecosystem responded? What actions would support it towards scaling up?</strong></p>
<p>&nbsp;</p>
</div>
<figure id="post-14661 media-14661" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14661 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6.png" alt="" width="1143" height="811" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6.png 1143w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6-269x191.png 269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6-768x545.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-1-6-345x245.png 345w" sizes="auto, (max-width: 1143px) 100vw, 1143px" /></figure>
<p>&nbsp;</p>
<div class="heading-text el-text">
<h2 id="dynamic">A dynamic ecosystem where some startups are reaching maturity</h2>
</div>
<div class="heading-text el-text">
<h3><span lang="EN-US">An ever-changing panorama of startups</span></h3>
<p><strong>Our radar now lists 152 cybersecurity startups, which represents 18 more startups than in June 2019, representing a 13% growth</strong>. Regarding their size, there has been a sharp increase (73%) in the number of “medium-sized companies”, while the number of “very small companies” and “small companies” remains stable, which is a sign that the market is becoming stronger. In total, startups represent more than 1,400 employees, 17% more than last year, a figure that has increased for the 4<sup>th</sup> year in a row.</p>
</div>
<p>&nbsp;</p>
<figure id="post-14663 media-14663" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14663 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-6.png" alt="" width="1398" height="569" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-6.png 1398w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-6-437x178.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-6-71x29.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-2-6-768x313.png 768w" sizes="auto, (max-width: 1398px) 100vw, 1398px" /></figure>
<p>&nbsp;</p>
<div class="heading-text el-text">
<p><strong>In terms of geographical distribution, the findings are is quite similar to 2019: Paris remains the main hub (more than 60% of the radar startups have headquarters there).</strong> Rennes region comes in second position and continues to grow in volume to reach 10% of representativeness. Bordeaux region comes third, with 4% of startups.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">Still promising startup creations</span></h3>
</div>
<div class="uncode_text_column">
<p><strong>The radar shows 16 young</strong> startups created between early 2019 and August 2020. Among these startups, we can see that:</p>
<ul>
<li>More than a quarter focus on <strong>data protection topics</strong>: <strong>Olvid, Protected, Pineapple Technology, BusterAI</strong></li>
<li>Nearly another quarter on <strong>vulnerability management and operational security activities: Patrowl, V6Protect, Purplemet</strong>.</li>
<li>Endpoint protection <strong>(Nucleon Security, Glimps)</strong> completes the podium of the main themes addressed by these new startups.</li>
</ul>
<p>We want to raise your attention to <strong>Malizen</strong>, a startup which is positioned on threat hunting and assistance to investigations by incident response teams, a topic that is still little represented in today’s ecosystem. <strong>Moabi’s</strong> position on firmware security auditing (embedded software) is also interesting in terms of connected objects security.</p>
<p>These new startups most often originate from the identification of a gap in the market by one of the founders during a previous professional experience. This year, however, two companies, <strong>Malizen</strong> and <strong>CryptoNext</strong>, have emerged from research projects. This is a small but interesting figure compared to previous years, especially in a French context where the world of research and that of cybersecurity are still too separate.</p>
</div>
</div>
<p>&nbsp;</p>
<figure id="post-14665 media-14665" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14665 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6.png" alt="" width="1302" height="749" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6.png 1302w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6-332x191.png 332w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-3-6-768x442.png 768w" sizes="auto, (max-width: 1302px) 100vw, 1302px" /></figure>
<p>&nbsp;</p>
<div class="heading-text el-text">
<div class="uncode_text_column">
<div class="heading-text el-text">
<h3>Only 38% of French startups position themselves on emerging themes</h3>
</div>
<div class="uncode_text_column">
<p>The startups relationship to innovation remains stable compared to previous years. <strong>30% of startups are disruptive and create new security solutions and 8% secure new uses (IoT, Cloud, etc.)</strong>. However, the majority (62%) of startups reinvent existing solutions by proposing improvements. Despite the lack of direct innovation, these startups can be very successful if they demonstrate business agility. A perfect example is <strong>Egerie Software</strong>, which quickly tackled the issue of digitizing the Ebios Risk Manager risk analysis method developed by ANSSI.</p>
<p><strong>In terms of innovation, we can emphasize cryptography, as current encryption methods are threatened by quantum computing</strong>. This is precisely the aim of Cryptonext, a startup committed to providing robust encryption solutions in the face of these new threats, as it is focusing on post-quantum cryptography. Another startup, <strong>Cosmian</strong>, is focusing on the “confidential computing” trend, which makes it possible to encrypt data stored in the cloud using a homomorphic encryption algorithm, and then use encrypted data in the cloud without having to entrust the key to the service provider. <strong>Scille</strong> is another one to follow, as it introduced the CYOK concept (Create and Control Your Own Key) through its Parsec solution, that makes the user workstation the only trusted entity that automatically generates encryption keys.</p>
<p>Still at the center of the CISO’s concerns,<strong> the user is offered new innovative means of being made aware of security</strong>, with <strong>Cyberzen’s</strong> augmented reality, or <strong>HIA Secure’s</strong> new authentication methods using “human intelligence”, where the user himself generates single-use codes after solving challenges consisting of a sequence of symbols and characters.</p>
<p>With the generalization of teleworking for all employees, the health crisis of Covid-19 has also reinforced the need to <strong>secure the terminals</strong>. New French Endpoint Detection and Response (EDR) solutions continue to emerge, such as the Nucléon startup. Some are even going further regarding innovation, such as Glimps (created by four former DGA – the French Defence Procurement Agency – employees), which is trying to revolutionize malware detection and analysis by conceptualizing the compiled code, which allows them to free themselves from the modifications induced by the compilation, the target architecture and thus detect unknown threats on non-standard systems.</p>
<p>Many companies want to democratize the use of agile methodologies, while integrating security into these processes remains a real challenge in most cases. <strong>Intuitem</strong> tries to remedy this by providing the necessary tools to monitor their Agile Security Framework.</p>
<p>Finally, with the emergence of connected objects, <strong>the need for a secure IoT platform is more important than ever</strong>, this is what <strong>Tarides</strong> proposes through its OSMOSE solution.</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">As some startups are becoming more mature, the first « scale-ups » are being identified</span></h3>
</div>
<div class="uncode_text_column">
<p><strong>20 startups are leaving the radar this year, 6 less than last year</strong>. Of these exits, 5 are very fast growing (exceeding 35 employees in less than 7 years of existence) and 1 is due to a buyout. This continuity compared to last year demonstrates a growing capability of the French startup ecosystem, as some “scale-ups” are emerging in the cybersecurity field and can expect to attract the largest buyers or larger funds. As such, we are launching, together with BPI France, a first non-exhaustive monitoring of this category. The aim will be to complete the scale-ups list with the startups that will leave the radar in the coming years, due to very rapid growth.</p>
<p>A smaller proportion of startups are removed from the radar solely because of their seniority (20% this year compared to 37% in 2019). This year, we are seeing the first projects put “on hold” (20%, unrelated to the health crisis) and those shifting from cybersecurity to other fields (20%).</p>
</div>
</div>
</div>
<p>&nbsp;</p>
</div>
<figure id="post-14667 media-14667" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-14667 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-3.png" alt="" width="1011" height="530" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-3.png 1011w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-3-364x191.png 364w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-3-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/11/Image-4-3-768x403.png 768w" sizes="auto, (max-width: 1011px) 100vw, 1011px" /></figure>
<p>&nbsp;</p>
<div class="heading-text el-text">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="heading-text el-text">
<h2 id="ecosystem">An ecosystem in full renewal</h2>
</div>
<div class="heading-text el-text">
<h3><span lang="EN-US">International: a growing reality for startups</span></h3>
</div>
<div class="uncode_text_column">
<p>The health crisis does not seem to have shaken the willingness of startups to internationalize: this year, nearly 63% of the startups say they have customers abroad compared to 50% one year ago and 13% of the startups are thinking about going abroad. Cybersecurity is indeed a global issue <strong>and going international may prove to be an opportunity for startups</strong>, with countries where cybersecurity market is more mature or important than in France.</p>
<p>Regarding startup expansion targets, 55% want to expand beyond European markets. <strong>The US market is the preferred target for a third of startups wishing to expand on an international scale</strong>, and some French gems like <strong>Sqreen</strong> or <strong>Alsid</strong> have already taken this direction.</p>
<p>However, the Asian market should not be forgotten, which, even if it is less successful (only 18% of startups interested), can prove to be promising. It is a large market, where a targeted approach is necessary. Indeed, it may be interesting to start by <strong>targeting the economic centers of Hong Kong and Singapore</strong>, known to be good bridges between Europe and Asia. Singapore is particularly dynamic in cybersecurity with a historic investor (<strong>SingTel</strong>) and incubation structures widely mobilized, such as <strong>ICE71</strong> or the branch of the English incubator <strong>CylonLab</strong>. However, Hong Kong remains strong, with a significant number of acceleration programs such as <strong>Cyberport</strong> and the DIP (<em><strong>Design Incubation Program</strong></em>).</p>
<div class="heading-text el-text">
<h3><span lang="EN-US">2019-2020: The Year of National Initiatives</span></h3>
</div>
<div class="uncode_text_column">
<p>The French cybersecurity ecosystem is in full renewal. Numerous initiatives were launched between 2019 and 2020.</p>
<p>In October 2019, the Ministry of the Armed Forces inaugurated the “<strong>Cyber Defense Factory</strong>“. It is a place for cross innovation between the civilian and military worlds. Based in Rennes, this facility enables startups, SMEs and academics to work together with DGA experts and military operational staff on cybersecurity issues. It will also provide access for selected companies to certain data from the government.</p>
<p>In addition, <strong>the Strategic Committee for the “Security Industries”</strong> sector has seen its strategic contract signed with the State. The latter includes a dedicated section for cybersecurity aimed at bringing out France’s potential in terms of cybersecurity by aligning and mobilizing the various players on policies for education, innovation and technological development. Concretely, it will promote the private/public relationships, as well as initiatives on the innovation front. The first major results are expected in 2021.</p>
<p>The <strong>Grands Défis</strong> initiative, which stems from Cédric Villani’s work on artificial intelligence, saw the publication of its cybersecurity roadmap in July 2020. With a 30-million-euros budget, it highlights key themes such as cybersecurity automation, SMEs security and IoT security. A call for applications has been opened by BPI France and will close in 2021. The roadmap also highlights the importance of cybersecurity, pushing for the creation of a dedicated structure to help entrepreneurs get started and support them as early as possible.</p>
<p>Finally, the Cyber Campus project has been validated at the highest level of the State. The creation of this emblematic site aims at bringing together the driving forces of French cybersecurity, obviously to better protect our country and its strategic assets, but also to develop its economy and promote France abroad on this theme. Innovation should be widely represented, with the presence of start-ups, demonstration areas and even initiatives to accelerate or incubate cybersecurity startups. It is scheduled to open in 2021.</p>
<p>&nbsp;</p>
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<div class="uncode_text_column">
<p><em>This concludes the first part of our analysis of the dynamics of the cyber security startup ecosystem in France. The panorama of startups remains constant, with newly created startups already showing great promise. Others, with already several years of activity to their credit, have continued to grow, to the point that we have had to create a new category: scale-ups. However, this ecosystem is facing two major adversities, such as the current health crisis and the resulting slowdown in international trade. We will therefore see in a second part, what are the necessary evolutions for this startup ecosystem.</em></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/the-2020-french-cyber-security-startups-radar-our-analysis-1-2/">The 2020 French Cyber-Security Startups Radar: our analysis (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Interview with ACE Management &#8211; 2020 French Cybersecurity Startups Radar</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/11/interview-with-ace-management-2020-french-cybersecurity-startups-radar/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Fri, 06 Nov 2020 09:00:03 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[startups]]></category>
		<category><![CDATA[startups radar]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14523</guid>

					<description><![CDATA[<p>Every year, Wavestone conducts an in-depth analysis of the ecosystem of French cybersecurity startups. In this context, our team has organized an interview with the private equity firm ACE Management and represented by Quentin BESNARD and François LAVASTE. Find the...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/interview-with-ace-management-2020-french-cybersecurity-startups-radar/">Interview with ACE Management &#8211; 2020 French Cybersecurity Startups Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Every year, Wavestone conducts an in-depth analysis of the ecosystem of French cybersecurity startups. In this context, our team has organized an interview with the private equity firm ACE Management and represented by Quentin BESNARD and François LAVASTE. </em><em>Find the complete analysis </em><a href="https://www.wavestone.com/en/insights/"><em>here</em></a><em>.</em></p>
<p>&nbsp;</p>
<h2>Cybersecurity fundraising are slowing down in the 2019-2020 fiscal year (from June 2019 to June 2020), how can this be explained?</h2>
<p>There was indeed a sharp drop in the amounts raised by tech start-ups in France in March/April 2020. This is even more flagrant in comparison with the previous fiscal year, 2018-2019, which was particularly exceptional for the cybersecurity ecosystem (around €300 million raised, with great fundraisings, such as Vade Secure and Dashlane).</p>
<p>2019-2020 is, in our opinion, an extraordinary year in many ways:</p>
<ul>
<li>Significant fundraising was carried out at the end of 2019 and early 2020: 33 million euros for CybelAngel, great fundraising also for Trust-in-Soft, Egerie, Dust Mobile and Quarkslab that we were able to support;</li>
<li>Those planned for the first half of 2020 were quickly impacted by the health crisis: several planned between February and April were postponed.</li>
</ul>
<p>Nevertheless, a restart of fundraisings was initiated in mid-April at a steady pace, and we decided at the beginning of the year to invest in four new companies (three in France, one in Europe). Thus, even if the health crisis has led to a short-term slowdown, <strong>the end of 2020 should bring new fundraisings, and potentially reverse the trend</strong>, particularly in the field of cybersecurity, which is still growing despite the Covid-19 crisis.</p>
<p>&nbsp;</p>
<h2>Some start-ups decide not to raise any funds. What do you think about this?</h2>
<p>It is possible to create an “organic” self-financing business, especially in the service industry, but its development will be <strong>much slower.</strong></p>
<p>However, in the cybersecurity market, velocity seems to be essential for a startup: an innovative idea at a given moment can very quickly become obsolete and miss its chance on the market.  We believe that fundraising is an essential step for a company with a software/SaaS offer in cybersecurity that wants to reach the critical size to be a leader in a market that is by nature very international.</p>
<p>From our point of view, the particularly technical topic that is cybersecurity requires a specialized fund with cybersecurity knowledge and therefore able to understand the issues, the technology, the market, to make the right investment choices and to be relevant in supporting companies. This makes ACE Management positioning even more relevant (for entrepreneurs) and differentiating on the market (for investors in our funds).</p>
<p>On that topic, it is also important to note that if Brienne III is today the only fund specialized in cybersecurity in France, there are similar funds in other European countries, such as Germany, and the Netherlands, which are natural partners for us.</p>
<p>&nbsp;</p>
<h2>All investors have their own magic recipe for identifying gems to invest in, would you share some of yours with us?</h2>
<p>Concerning the Brienne III fund, we are targeting startups that have already reached a certain maturity level and are looking to raise significant amounts of capital (at least €5 million, rather Series A or B).</p>
<p>Without revealing the whole recipe, here are some of the key elements we are looking for:</p>
<ul>
<li>Ambitious management, knowing how to surround themselves with the right skills for the development of their structure;</li>
<li>A technically solid value proposition, potentially resulting from R&amp;D funding from large groups or research laboratories;</li>
<li>In adequacy with the needs of the market, answering a recurring unaddressed problem or protection issues highlighted by recent attacks.</li>
</ul>
<p>&nbsp;</p>
<h2>Speaking of market needs, what do you see as the next trends in cybersecurity?</h2>
<p>Our discussions with several CISO during the health crisis and our analyses of the market and current events lead us to identify the following:</p>
<ul>
<li><strong>Workstations security</strong> is back in the spotlight, especially with the generalization of remote access;</li>
<li><strong>Third party management</strong> in a more fluid way while remaining secure and limiting their access;</li>
<li><strong>Sovereignty questions</strong> are more important, but, barring regulatory constraints, should not remain the main selection criterion;</li>
<li>It also seems to us that <strong>the trend towards using the SaaS (Software As A Service) model for security solutions has been passed for a certain number of structures</strong>, which are more mature on Cloud models, and have a much lower grasp of them. An element to keep in mind for our start-ups!</li>
</ul>
<p>&nbsp;</p>
<h2>About Brienne III and ACE Management:</h2>
<p>In June 2019, with an initial closing of 80 million euros, ACE Management launched the Brienne III fund, the first French investment fund dedicated to the financing of innovative cybersecurity companies and the largest in continental Europe. The initial subscribers to this fund are Tikehau Capital (a shareholder of ACE Management), Bpifrance, EDF, Naval Group, Sopra Steria and the Nouvelle Aquitaine region. Other strategic investors and institutions wishing to support the emergence of cyber defense solutions are in advanced discussions with ACE Management to participate in the second closing.</p>
<p>ACE Management, a Tikehau Capital Company, is a private equity firm specializing in the industrial and technology sectors, with €1 billion in assets under management. Founded in 2000, ACE Management invests through sector strategies, such as strategic industries, cybersecurity and trusted technologies. ACE Management has built its model on partnerships with major groups investing in its funds (notably Airbus, Safran, EDF).</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/11/interview-with-ace-management-2020-french-cybersecurity-startups-radar/">Interview with ACE Management &#8211; 2020 French Cybersecurity Startups Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Radar des startups 2019 : Quels leviers de développement ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-23/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Thu, 17 Oct 2019 08:16:34 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[start-up]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12155</guid>

					<description><![CDATA[<p>Après un premier article sur l&#8217;écosystème 2019 des startups cyber, ce deuxième article couvre les différents défis auxquels doivent faire face les pépites françaises. Quelles actions concrètes permettraient à ces derniers d’intensifier le développement de leurs startups, d’acquérir une nouvelle...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-23/">Radar des startups 2019 : Quels leviers de développement ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Après un <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-13/">premier article sur l&#8217;écosystème 2019 des startups cyber</a>, ce deuxième article couvre les différents défis auxquels doivent faire face les pépites françaises. Quelles actions concrètes permettraient à ces derniers d’intensifier le développement de leurs startups, d’acquérir une nouvelle envergure et, d’ainsi, confirmer le changement d’échelle amorcé ?</em></p>
<p>&nbsp;</p>
<h2>Des challenges qui freinent la progression des start-ups</h2>
<p>Les échanges réalisés avec les équipes de startups présentes dans le radar permettent d’identifier des challenges concrets qui pour certains sont ambitieux à relever.</p>
<p>&nbsp;</p>
<h3>Les startups ont du mal à recruter des profils adéquats</h3>
<p>A l’instar de l’ensemble du marché, les startups cyber sont confrontées à une pénurie de main d’œuvre spécialisée. Les jeunes diplômés ne sont pas suffisamment formés à la cybersécurité dans les écoles françaises pour alimenter les effectifs ou être à l’initiative de création de startups. Cet état de fait, partagé par l’intégralité du marché en cybersécurité, est encore plus prégnant pour les startups qui ne peuvent pas souvent suivre la course salariale qui s’en suit.</p>
<p>&nbsp;</p>
<h3>Des fondateurs de startups peu enclins à la prise de risque</h3>
<p>66% des fondateurs ont déjà expérimenté une création d’entreprise, mais rarement plusieurs alors que la moyenne d’âge de ces entrepreneurs dépasse les 40 ans. Le profil des fondateurs révèle plutôt des experts que des serial entrepreneurs audacieux. Si on peut saluer la ténacité de certaines startups, il faut souligner la peur de l’échec qui est un problème récurrent en France et qui n’a pas lieu d’être à l’échelle international. Par exemple, un entrepreneur de la Silicon Valley ou israélien ne sera vraiment considéré qu’après plusieurs échecs de création d’entreprise.</p>
<p>&nbsp;</p>
<h3>Une stratégie marketing carencée…</h3>
<p>Les équipes des startups sont davantage composées de profils techniques et spécialisés sécurité que commerciaux. Il en résulte une difficulté des startuppers à rendre leur offre commerciale attirante auprès des prospects. Des efforts sont à faire sur le volet marketing, aussi bien au niveau du produit que du discours. A titre d’exemple, les incubateurs anglo-saxons déploient des programmes d’accélération business élaborés, comme l’incubateur londonien Cylon dédié à la cybersécurité qui forme à « pitcher » efficacement sa startup auprès de potentiels investisseurs, clients et partenaires. Les startups en récoltent les fruits et sont réputées pour leur force commerciale outre-Manche et outre-Atlantique.</p>
<h3>…qui se répercute sur les ventes</h3>
<p>Les startups françaises ne rencontrent pas de problèmes liés à leur phase de création, mais ont en revanche du mal à faire connaître leurs solutions et à vendre à court et moyen terme. Seul 15% des startups contactées nous a confirmé faire plus de 500 000 euros de chiffre d’affaires. Parmi ces startups, deux tiers ont déjà entre 4 et 7 années d’existence sur le marché de la cybersécurité.</p>
<p>&nbsp;</p>
<h2>Comment concrétiser cette transformation</h2>
<h3>Pour les startups, apprendre à se vendre</h3>
<p>Les startups doivent proposer des solutions sur étagère et ainsi atteindre un plus grand nombre de clients avec des coûts optimums. Pour ce faire, il est nécessaire que les fondateurs identifient et valorisent une proposition unique de vente plutôt qu’un segment de marché.</p>
<p>Un axe clé pour eux serait de se positionner sur des problématiques non résolues par les solutions traditionnelles. En effet, les grands groupes sont plus enclins à collaborer avec les startups lorsqu’elles adressent des problèmes pour lesquels aucune solution n’existe sur le marché. La startup Alsid, qui se distingue par son premier rang dans notre classement des levées de fonds, est un bel exemple puisqu’elle traite une problématique pour laquelle aucune solution n’existait auparavant : le monitoring de la sécurité d’Active Directory.</p>
<p>Savoir présenter un pitch clair et attirant se concentrant sur les différentiateurs est un axe d’amélioration clé du développement des start-ups. En effet, c’est une étape cruciale dans la relation avec les investisseurs, les partenaires et les clients afin de les convaincre de la valeur ajoutée de la solution.</p>
<p>Un autre élément à envisager est de penser au design et à l’expérience utilisateur dès la création de la solution. Dans un marché où ces critères ne sont pas forcément pris en compte par les concurrents, cela peut représenter un vrai atout. Exemple singulier sur le marché, la startup israélienne Cybereason l’a bien compris et a engagé un <em>VP Créative &amp; Head of Design</em> pour imaginer le design de ses produits parallèlement à la construction des fonctionnalités.</p>
<p>Pour finir, les startups ne doivent pas hésiter à réfléchir international dès leur lancement (langue de travail, documentation des codes sources, rédaction des documents produits…) afin de ne pas alourdir inutilement l’effort, déjà conséquent à fournir sur le plan commercial, pour accéder à des marchés plus matures et pouvoir ainsi accélérer le passage à l’échelle.</p>
<figure id="post-12164 media-12164" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-12164 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-1.png" alt="" width="848" height="517" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-1.png 848w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-1-313x191.png 313w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-1-768x468.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-1-64x39.png 64w" sizes="auto, (max-width: 848px) 100vw, 848px" /></figure>
<h3>Pour le marché</h3>
<p>Les avantages liés à l’incubation sont nombreux pour les startups (regard extérieur, service à prix réduit, proximité avec d’autres…), mais en même temps la cybersécurité est un domaine avec des besoins spécifiques (confidentialité, expertise scientifique, protection physique…). Ces raisons font que peu de startups en cyber trouvent leur place efficacement dans un incubateur standard. Cela exacerbe le besoin d’un incubateur spécialisé cybersécurité. De plus cet incubateur pourrait devenir un totem de l’innovation cyber « à la française » et un lieu d’accueil des investisseurs et des grands clients. La France réfléchit à se doter d’un hub dédié à la cybersécurité et les premières propositions seront remises à Matignon d’ici la fin du mois de novembre. Il faut espérer que ce lieu proposera réellement un environnement propice au développement des startups, ainsi que des services d’accompagnement qui ne soient pas seulement liés à de l’aide à la recherche.</p>
<p>Enfin, il serait pertinent de favoriser la création de startups par d’anciens membres de la cyberdéfense des Armées ou de l’ANSSI. En effet, leur réseau et leur expertise professionnelle acquis en début de carrière sont des facteurs de succès dans l’écosystème cyber, comme l’ont prouvé les ex-collaborateurs de l’ANSSI et désormais fondateurs des startups Alsid et Citalid.</p>
<p>&nbsp;</p>
<h3>Pour les clients</h3>
<p>Afin de permettre le développement de l’écosystème, les clients doivent accepter la prise de risque. Ils ont pour l’instant des difficultés à faire confiance et à contractualiser rapidement avec de jeunes structures innovantes. Pour un quart des startups interrogées, le temps de signature du contrat après la réalisation du POC est supérieur à 6 mois, et cette observation est particulièrement prégnante chez les grands groupes. Ces derniers peuvent s’inspirer des grandes entreprises israéliennes qui se tournent très vite vers les startups lorsqu’elles identifient des problèmes pour lesquels le marché traditionnel n’offre pas de solutions en acceptant les risques mais en négociant également des tarifs très attractifs pour le futur.</p>
<p>On pourrait également envisager la création d’un accompagnement à la prise de risque de la part de l’Etat afin d’encourager la collaboration des grands groupes avec les startups. En restant sur l’exemple israélien, l’Etat a créé une agence indépendante qui sélectionne des projets innovants pour lesquels à chaque Shekel investi par le secteur privé, l’Etat investit un Shekel sans contrepartie.</p>
<p>&nbsp;</p>
<p><em>2019 a montré une vraie embellie dans l’innovation cybersécurité en France. Pour que l’écosystème continue sur sa lancée et concrétise son passage à l’échelle, les axes d’améliorations évoqués se doivent d’être accompagnés par un changement d’état d’esprit de l’écosystème, qui demeure pour l’instant trop fermé. Avec la collaboration des différents acteurs, il n’y a nul doute que la dynamique amorcée se confirmera. Les grands projets entamés à l’échelle de l’état, en particulier le Campus cyber, sont une opportunité unique pour transformer notre écosystème. Mobilisons-nous tous pour que cela devienne une réalité !</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-23/">Radar des startups 2019 : Quels leviers de développement ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Radar des startups 2019 : Un écosystème de plus en plus dynamique</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-13/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Thu, 17 Oct 2019 08:16:31 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[start-up]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12152</guid>

					<description><![CDATA[<p>Cette année a montré l’amorçage d’une transformation de l’écosystème des cyber-startups françaises. Le dynamisme des startups n’est plus à prouver et les entrepreneurs français brillent par leur capacité à innover sur différents sujets de la cybersécurité.  &#160; +18% de croissance...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-13/">Radar des startups 2019 : Un écosystème de plus en plus dynamique</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Cette année a montré l’amorçage d’une transformation de l’écosystème des cyber-startups françaises. Le dynamisme des startups n’est plus à prouver et les entrepreneurs français brillent par leur capacité à innover sur différents sujets de la cybersécurité. </em></p>
<p>&nbsp;</p>
<h2>+18% de croissance en nombre de startups depuis janvier 2018</h2>
<p>Notre radar recense désormais 134 startups cybersécurité, ce qui représente 25 startups de plus qu’en janvier 2018. Il est intéressant de remarquer que leur taille évolue également de manière positive : si les « très petites entreprises » restent majoritaires, le nombre de « petites entreprises » a augmenté de près de 56%. Au total, les startups représentent plus de 1200 emplois, soit 9% de plus que l’année précédente, et ce pour la 3<sup>ème</sup> année consécutive !</p>
<p>Concernant les sorties, 27 startups ont quitté notre radar, soit seulement 4 de plus que l’année dernière. Parmi ces dernières, 37% sortent du radar à cause de leur ancienneté (&gt;7ans d’existence) et sans pour autant dépasser le critère de la taille limite (&lt;35 employés), ce qui est un signe de difficultés de croissance ou bien simplement d’un manque de volonté de croissance et de prise de risque par les fondateurs. Ce manque de prise de risque est appuyé par un faible taux de liquidation (30%). Cependant nous constatons cette année que les cas de croissance rapide (dépassant les 35 employés avant d’atteindre les 7 ans d’existence) sont plus nombreux (18%) et observons même les premiers rachats (15%), ce qui témoigne d’une attractivité plus forte des ces acteurs.</p>
<p>Au niveau géographique, peu de surprises par rapport aux années précédentes, avec un centre névralgique positionné sur le bassin parisien. L’écosystème reste néanmoins bien réparti avec des présences régionales issues des différents incubateurs. En particulier le pôle Rennais gagne en importance avec les nombreux investissements réalisés par le ministère des armées qui souhaite y créer un véritable deuxième pôle d’expertise en France sur les sujets cybersécurité, comme le montre la présence de l’activité cybersécurité de la DGA sur son campus de Bruz.</p>
<p>&nbsp;</p>
<figure id="post-12159 media-12159" class="align-none"></figure>
<figure id="post-12161 media-12161" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-12161 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image3.png" alt="" width="1614" height="757" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image3.png 1614w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image3-407x191.png 407w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image3-768x360.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image3-71x33.png 71w" sizes="auto, (max-width: 1614px) 100vw, 1614px" /></figure>
<p>&nbsp;</p>
<h2>Des signes particulièrement positifs pour la transformation de l’écosystème qui s’observent chez les clients …</h2>
<p>Identifié l’année dernière comme un axe essentiel au développement de l’écosystème, le financement des POC par les entreprises devient une pratique de plus en plus répandue puisqu’elle concerne 67% des startups que nous avons interrogées. Cette démocratisation est un signe particulièrement positif pour l’écosystème, car en plus de supprimer cet investissement initial pour les startups, cela montre que les grands groupes évoluent et font confiance à nos pépites françaises.</p>
<p>&nbsp;</p>
<h2>… du marché …</h2>
<p>On ne peut que saluer l’ampleur prise par les levées de fonds cette année. Au niveau de notre radar, le total est 4 fois supérieur à celui de 2017 et pas moins de 6 startups ont levé des montants supérieurs à 10 millions d’euros. Il est également intéressant de mentionner la structure française Vade Secure qui a levé 70 millions d’euros via le fond américain General Catalyst, et la startup franco-américaine Dashlane qui a levé 110 millions de dollars. Cette ampleur est le résultat d’un début de démystification de l’écosystème qui permet aux investisseurs d’être moins frileux sur le sujet. Une autre preuve de cette confiance est la création d’un fonds d’investissement dédié, Brienne III. Cette structure qui a déjà réalisé un premier closing de 80 millions va permettre de continuer à rassurer les investisseurs et contribuer à l’évangélisation de l’écosystème.</p>
<p>Nous observons aussi les premiers <strong>« exits » </strong>des startups françaises. Ils concernent 4 startups de notre radar cette année, dont notamment Trustelem acquise en juillet par Wallix, Sentryo qui est en négociation avancée avec Cisco pour une intégration d’ici le premier trimestre 2020, et Madumbo qui a été rachetée par l’éditeur franco-américain Datadog. Ils sont une preuve que ces startups françaises sont de plus en plus différenciantes, ce qui les rend plus attractives. En revanche, ces exits sont très souvent portés par des structures <strong>étrangères</strong> et dans la majorité des cas, ils entraînent la <strong>délocalisation</strong> des centres de décisions et de R&amp;D de ces startups, ce qui reste dommageable pour l’entretien du dynamisme de l’écosystème et la souveraineté technologique en France.</p>
<p>Autre signe positif de l’évolution du marché, on observe également l’ouverture de la Défense, notamment avec la fondation de l’« Innovation Défense Lab » qui sera accueilli au sein du « Starbust Accelerator » et qui favorisera la collaboration des startups avec la DGA. En parallèle, l’Etat a lancé un projet de campus de la cybersécurité. Cette entité aura pour vocation de créer des synergies entre les différents acteurs de l’écosystème en réunissant notamment des acteurs industriels, des startups, des universitaires, ainsi que certaines agences et ministères.</p>
<p>&nbsp;</p>
<h2>… et des startups</h2>
<p><strong>L’internationalisation</strong> des startups reste un gros levier de croissance, et les startups cybersécurité françaises l’ont compris. La moitié de celles que nous avons interrogées ont déjà des clients à l’étranger, et 15% sont en recherche d’opportunités à l’international : elles se donnent ainsi les moyens d’accéder à des marchés plus importants, plus stratégiques et potentiellement plus matures… et donc de trouver les leviers de croissances nécessaires à leur développement.</p>
<p>De plus, le positionnement de <strong>l’innovation</strong> change pour l’année 2019 grâce à une <strong>augmentation de la proportion de startup innovantes parmi les nouvelles créations.</strong> En effet, 44% des startups créées cette année proposent des solutions disruptives n’existant pas auparavant sur le marché.</p>
<p>Cela porte à 31% le nombre total de startup de notre radar appartenant à cette catégorie alors qu’il n’était que de 19% l’année dernière.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12157 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1.png" alt="" width="1656" height="1223" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1.png 1656w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-259x191.png 259w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-768x567.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image1-53x39.png 53w" sizes="auto, (max-width: 1656px) 100vw, 1656px" /></p>
<h2>Les entrepreneurs cybersécurité innovent dans les domaines matures de la cybersécurité</h2>
<p>On pourrait s’attendre à ce que ces domaines bien établis où la concurrence est rude soient moins attractifs. Cependant les entrepreneurs n’hésitent pas à les aborder sous un angle nouveau afin de gagner des parts de marché.</p>
<p>La <strong>sécurité de la donnée</strong> comporte ainsi son lot d’innovations. Les startups Binex et Ugloo ont par exemple conçu des solutions de stockage « décentralisé » en faisant la promesse aux entreprises de pouvoir récupérer le contrôle de leurs données aujourd’hui sauvegardées dans des Cloud de fournisseurs différents.</p>
<p>La <strong>gestion des identités et des accès</strong>, éternel casse-tête des entreprises, est un terrain où l’innovation est possible, comme le prouve ArmadAI qui optimise les habilitations des utilisateurs via l’utilisation de l’intelligence artificielle. La start-up Reachfive se positionne elle sur le CIAM (Customer Identity and Access Management) en fournissant une plateforme d’identité client répondant aux enjeux de sécurité et d’expérience utilisateur. Enfin des acteurs comme RubycatLabs n’hésitent pas à bousculer les segments où les parts de marché sont rares, ici la gestion des comptes à privilèges, en se différenciant non pas par la technologie mais par une simplicité d’utilisation et des modèles tarifaires attractifs.</p>
<p>Dans la même optique, la start-up Sqreen propose de révolutionner le domaine de la <strong>sécurité applicative</strong> en déployant son micro-agent au sein des applications, permettant ainsi de les monitorer et protéger. D’autres startups ont choisi des problématiques de niche dans ce domaine, comme Datadome avec sa solution qui empêche les « mauvais » robots (Scraping, DDoS, vol de compte …) de nuire aux applications des entreprises, tout en autorisant les robots légitimes (Googlebot…) à y accéder.</p>
<p>Que dire de la <strong>gestion des vulnérabilités</strong> où les quelques leaders du marché se partagent les parts du gâteau. Le constat est simple aujourd’hui : les entreprises sont très compétentes quand il s’agit de trouver des vulnérabilités, mais beaucoup moins quand il s’agit de les corriger, à cause des problèmes de criticité (d’un point de vue disponibilité) des ressources concernées. On observe ainsi deux approches intéressantes visant à modifier ce constat : celle de Cyberwatch qui propose d’évaluer les vulnérabilités dans un contexte métier afin de prioriser celles qu’il faut corriger ; et l’approche d’Hackuity qui suggère de centraliser et de normaliser les résultats des différents tests d’intrusion sur une même plateforme et d’implémenter une fonctionnalité de « rejeu » de la vulnérabilité afin de pouvoir suivre la résolution de cette dernière de façon automatique.</p>
<p>Les entreprises françaises, en particulier celle ayant le statut d’opérateur d’importance vitale (OIV), sont toujours à la recherche de souveraineté, et cela s’applique également à la <strong>sécurité réseau</strong>, où les entreprises étrangères comme Darktrace ou Vectra sont les leaders du marché. C’est ce qui explique, entre autres, la réussite de la startup Gatewatcher dont les sondes de détection d’intrusions ont été récemment qualifiées par l’ANSSI. C’est également le cas de la <strong>sécurité endpoint</strong>, où des EDR à la française voient le jour comme la jeune pousse Harfanglab et son EDR Hurukai.</p>
<p>Pour finir, la connaissance de la menace est devenue un atout stratégique pour les entreprises, faisant la part belle au domaine de la <strong>Threat Intelligence</strong>. Dans ce domaine, l’acteur français Citalid innove en commercialisant une plateforme d’anticipation des cybermenaces et de quantification des risques reposant sur l’utilisation de la méthodologie FAIR.</p>
<p>&nbsp;</p>
<figure id="post-12159 media-12159" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-12159" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2.png" alt="" width="500" height="356" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2.png 813w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2-268x191.png 268w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2-768x547.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/10/Image2-345x245.png 345w" sizes="auto, (max-width: 500px) 100vw, 500px" /></figure>
<h2>Les startups comprennent les enjeux du marché et se positionnent sur les sujets « porteurs ».</h2>
<p>Le domaine de la <strong>vie privée</strong> a fait parler de lui ces derniers mois en raison de la multiplication des fuites de données à caractère personnel et des premières sanctions vis-à-vis du RGPD. Les entrepreneurs cybersécurité l’ont bien en tête car c’est aujourd’hui une petite quinzaine de startups qui adressent ce sujet, comme la startup Smart Global Privacy dont la solution smart GDPR optimise la gestion des traitements de données à caractère personnel en automatisant certaines actions et en fournissant des templates préconstruit en fonction des métiers de l’entreprise.</p>
<p>Dans le même temps, le besoin de pouvoir <strong>collaborer de façon sécurisée</strong> est plus présent que jamais. Cependant, les solutions actuelles pâtissent d’un manque de simplicité de déploiement et d’ergonomie d’utilisation. C’est ce qui explique la multitude de solutions qui apparaissent sur le marché, et qui promettent à la fois un niveau de sécurité élevé et une expérience utilisateur acceptable. La messagerie mobile élaborée par la startup Olvid est un parfait alliage entre un modèle de sécurité cryptographique extrêmement robuste et les fonctionnalités standards d’une messagerie. Shadline et Twinlife proposent également des outils collaboratifs sécurisés. Mais il sera dur de se faire une place sur un marché déjà très concurrentiel.</p>
<p>La thématique de la <strong>gestion de crise</strong> fait son apparition sur le radar 2019. La startup Easylience a notamment conçu une solution permettant d’assister les entreprises dans la gestion des crises de grande ampleur.</p>
<p>Avec l’avènement de la <strong>digitalisation des parcours client</strong>, le besoin de pouvoir identifier et authentifier ces derniers sans avoir besoin de les rencontrer physiquement a émergé. Ubble et Serendptech adressent cette problématique, d’ailleurs encadrée par le règlement européen eIDAS, en distribuant une technologie de vérification d’identité basée sur des algorithmes de reconnaissance vidéo pour les premiers, et une application mobile qui aide à garantir l’authenticité d’un titre d’identité pour les seconds.</p>
<p>Enfin, le domaine de la <strong>sécurité de l’IoT</strong> n’a rien à envier à ceux mentionnés précédemment quand on considère l’avènement des objets connectés, pour les particuliers mais également pour les entreprises. La startup Acklio contribue à sécuriser les objets connectés en rendant compatibles les réseaux LPWAN (réseaux à longue portée et basse consommation comme Lora ou Sigfox) nécessaires au bon fonctionnement de ces objets et le protocole IP. Sa solution permet de comprimer les messages internet et d’ainsi assurer la communication native entre l’objet et les applications métier. La startup Moabi elle se positionne sur l’évaluation de la sécurité des firmwares intégrés dans ces objets, en utilisant notamment les technologies d’exécution symbolique.</p>
<p>En revanche, la <strong>sécurité par déception </strong>est encore trop peu adressée par les startups, bien qu’elle ait fait son apparition avec des startups comme SesameIT et Anozrway qui commencent à implémenter des fonctionnalités de ce type.</p>
<p>&nbsp;</p>
<p><em>Retrouvez dans ce <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-23/">deuxième article</a>, une analyse des actions concrètes qui permettraient aux acteurs d’intensifier le développement de leurs startups, d’acquérir une nouvelle envergure et, d’ainsi, confirmer le changement d’échelle amorcé.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/10/radar-startups-2019-13/">Radar des startups 2019 : Un écosystème de plus en plus dynamique</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber-security start-ups in France, a booming ecosystem (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-22/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-22/#respond</comments>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Sun, 15 Oct 2017 16:54:14 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[startup]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10106/</guid>

					<description><![CDATA[<p>After a first article on the cyber-security start-ups radar, this second article is about which means these start-ups can use to properly develop. How to acquire customers among large corporations? How to develop abroad? These are one of the many...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-22/">Cyber-security start-ups in France, a booming ecosystem (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>After a <a href="https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-12/">first article</a> on the cyber-security start-ups radar, this second article is about which means these start-ups can use to properly develop. How to acquire customers among large corporations? How to develop abroad? These are one of the many challenges to face. </em></p>
<h2>Corporate accounts: essential but complex targets</h2>
<p>The economic fabric of France relies heavily on big groups that have substantial investment capacity. For start-ups seeking to market their cyber-security offers, these are the prime customers. However, the rigid and complex processes of these large companies constitute a major obstacle for start-ups.</p>
<p>After all the pitfalls involved in identifying the multiple budget holders in the structure (ISSM, architect, expert, IT Manager, purchasing, etc.), it remains very difficult to sign the first contract. The purchasing process can take from three to six months, and is too complex for the way that start-ups operate, with them being asked for proof of profitability, years and years of experience, and references from other customers &#8211; impossible for the first contracts.</p>
<p>This situation is exacerbated for cyber-security as start-ups often cannot count on the innovation hubs created by the corporate accounts to facilitate their exchanges with the innovation ecosystem. On the one hand, because start-ups struggle to convince businesses of the benefits provided by their proposed solutions, and on the other because the innovation teams have difficulty understanding the practical benefits given the specific nature of the issues. Feedback on successes shows that cyber-security departments in the corporate accounts often have to be the driving force, or even develop the relationships with the cyber start-ups themselves.</p>
<h3>Attitudes that must change within the large companies</h3>
<p>Once contact has been established, there remains the step of carrying out tests in live conditions (Proof of Concept). It&#8217;s an example of the difficulty that start-ups have in competing with the established cyber-security developers in the corporate world. These tests are needed to evaluate the effectiveness of the new solution. The big developers, with substantial financial resources, offer &#8216;PoCs&#8217; free of charge to their customers, who in turn have become used to these &#8216;free&#8217; tests carried out for their benefit.</p>
<p>For start-ups, however, the situation is different as their working capital requirements are acute and carrying out such tests free-of-charge can endanger their very existence!</p>
<p>It is therefore necessary for the big groups to have suitable budgets, often in the order of only a few thousand euros, to test the innovative solutions proposed by the start-ups.</p>
<h3>Positive feedback from interactions between start-ups and corporate accounts in France</h3>
<p>However, successful collaboration between start-ups and corporate accounts shows that these two worlds can work together. And the effort made pays back in a big way. Start-ups like Alsid and Idecsi thus benefit from the testimony of large customers that are in a position to reassure other companies and the investors.</p>
<h3>A French cyber-security ecosystem that values innovation</h3>
<p>In France, the presence of an ecosystem that regularly promotes innovation by including corporate accounts and start-ups is highly visible: the &#8220;Assises de la Sécurité&#8221; with the Prize for Innovation, the International Cyber-security Forum (FIC) with the Innovative SME prize, and the competition devoted to cyber-security in the banking industry, jointly organized by Société Générale and Wavestone. These initiatives help to highlight cyber-security innovations, as well as promoting direct contact between the different players. They contribute to creating the relationship of trust needed for the corporate accounts to invest in the solutions proposed by start-ups.</p>
<h3>The importance of having a French offer for digital sovereignity</h3>
<p>Cyber-security is a global issue but also affects national security. The benefits of having reliable products in this area is obvious.</p>
<p>Even if much remains to be done to guarantee digital sovereignty, the initiatives of certain French start-ups have made it possible to import concepts that initially existed only in other countries. This is the case, for example, with Bug Bounty&#8217;s platforms. In France, three start-ups, Bug Bounty Factory, Bug Bounty Zone and Yogosha offer services in this field. Over time, this could make it possible to retain knowledge of sensitive vulnerabilities within Europe or indeed in France.</p>
<p>It is important to note that the French domestic market for cyber-security is largely driven by players in the defense sector, both public and private, who invest and help start-ups to grow. But these growth opportunities are, at the same time, an obstacle to exports and make it more difficult to communicate references.</p>
<h2>Tomorrow, successfully growing beyond national borders</h2>
<h3>The research sector is becoming structured</h3>
<p>Research in cyber-security is also very active in France with many  laboratories being involved and some leading-edge initiatives. The Allistene grouping, which includes INRIA, CEA, CNRS and a number of higher education institutions is just one example. Prominent chairs have been devoted to cyber-security issues and its practical applications, for example for autonomous vehicles. Together with the initiatives launched the big companies, this all adds up to the creation of fertile ground for numerous start-ups to bloom and grow.</p>
<h3>Overcoming purely French considerations to grow internationally</h3>
<p>France has much talent in terms of cyber-security, fertile ground to facilitate the emergence of start-ups, and a market that can support these structures. But this very positive situation must not be allowed to mask the principal difficulty currently faced by our start-ups: achieving international success and growth.</p>
<p>Apart from a few success stories, such as Qualys in the past, and more recently Linkurious in the United States, French start-ups struggle to go beyond their own borders. They face barriers in terms of their ability to communicate effectively in English, the weakness of French customer references, legal issues, and also psychological barriers to expatriation. Whereas the quality of French cyber-security specialists is widely acknowledged, the quality of the start-ups remains unknown.</p>
<p>Breaking through this glass ceiling requires joint initiatives with the government, large companies, and the strong entrepreneurial spirit of start-up founders.</p>
<p>Let&#8217;s start working together, pooling all our strengths, so that this becomes a reality in years to come.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-22/">Cyber-security start-ups in France, a booming ecosystem (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-22/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber-security start-ups in France, a booming ecosystem (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-12/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Sun, 15 Oct 2017 16:25:42 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[France]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[startup]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10093/</guid>

					<description><![CDATA[<p>Cyber-security is now the focus of everyone’s attention &#8211; the protection of personal data and defense against cyberattacks have become priorities for companies and governments alike. In a field where the nature of the threat is constantly evolving, innovation is...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-12/">Cyber-security start-ups in France, a booming ecosystem (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Cyber-security is now the focus of everyone’s attention &#8211; the protection of personal data and defense against cyberattacks have become priorities for companies and governments alike. In a field where the nature of the threat is constantly evolving, innovation is an absolute necessity. While the United States and Israel dominate, France is starting to make a name for itself thanks to the dynamism of its cyber-security start-ups and the diversity of the schemes set up to support them. This article takes a closer look at the specificities of the ecosystem in France.</em></p>
<h2>Cybersecurity in France</h2>
<h3>A dynamic base of over 100 start-ups</h3>
<p>There are currently over 100 innovative start-ups and SMEs active in the field of cyber-security in France. This constantly growing number reflects the dynamism of the sector in France and the advantages it offers in this area. The sector represents over 1,000 direct jobs. And while that may not seem a lot, this number is expected to increase significantly over the next few years.</p>
<h3>Most start-ups choose to reinvent security solutions that are already well established</h3>
<p>60% of start-ups enter the market with the intention of improving on security solutions that already have a proven track record (device security, network security, email security, identity management, etc.).</p>
<p>As a general rule, tackling an already consolidated market is not simple. But there are still windows of opportunity, particularly in application security. Many of the major players are present in this field, and yet they still do not offer truly satisfactory solutions. The innovative approaches taken by start-ups such as Sqreen, Ingen and Yagaan can provide new paths forward.</p>
<h3>Industrial security, cryptography and reverse engineering : innovative fields in which France is well-positioned</h3>
<p>In reality, numerous French start-ups (40%) have positioned themselves in technologies where everything remains to be done.</p>
<p>For industrial systems, for example, French players such as Sentryo and Seclab are particularly well placed.</p>
<p>This is also the case for technologies used to analyze malware, with products and services such as those offered by Tetrane and Quarkslab. Their expertise is internationally acknowledged, including by major American groups.</p>
<p>In cryptography, the French school of mathematics enables start-ups to enjoy access to cutting-edge expertise, difficult to access in other countries. This helps them to develop innovative vulnerability analysis tools such as Cryptosense.</p>
<p>On the other hand, certain fields continue to be neglected in France despite strong growth potential, including deception techniques (that aim to provide false information to a hacker to slow them down), which are gaining popularity in Israel, and even at a European level.</p>
<h3>French start-ups experience difficulties with communication and appreciation of their expertise</h3>
<p>The national ecosystem of start-ups is very dynamic and even the highly specialized forms of expertise exist, helping to turn ideas into reality and launch the first products. A key point is nevertheless required for the cyber-security market: the ability to communicate effectively. Our contact with several foreign incubators shows a striking difference in terms of communication with Anglo-Saxon start-ups able to promote their products using hard-hitting pitches and effective marketing.</p>
<p>This lack of commercial know-how is particularly negative for French start-ups that wish to take their products to an international level.</p>
<figure id="post-10098 media-10098" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-10098" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-1.png" alt="" width="1058" height="647" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-1.png 1058w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-1-312x191.png 312w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-1-768x470.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-1-64x39.png 64w" sizes="auto, (max-width: 1058px) 100vw, 1058px" /></figure>
<h2>France &#8211; fertile ground for cyber start-ups</h2>
<p>For several years, many initiatives have been developing to support the cyber sector in France. We could mention the government&#8217;s Digital Security strategy driven by the French IT security agency (ANSSI) or the investments made by the Ministry of Defense. Different economic clusters are involved, which in practice translates into a geographic concentration of start-ups. Paris, as is often the case, is in the lead, but Lyon, Rennes and the south of France are also very much present.</p>
<h3>Methodology for the construction of the start-up radar</h3>
<p>Since 2015, Wavestone has been actively monitoring the start-up ecosystem as part of its <a href="http://www.wavestone.com/shakeup">ShakeUp</a> program. With its many contacts and activities within the ecosystem of cyber-security innovation in France, the start-up radar now lists almost 400 structures across Europe and the world, with a special focus on France. The criteria for joining the French radar: registered office in France, less than 35 employees, and a legal structure that is less than 7 years old (excluding for major hubs).</p>
<p>Following these monitoring activities by the cyber-security practice and digital trust teams, we meet up with the most innovative start-ups to evaluate their solution, and some are selected to join ShakeUp, the Wavestone accelerator program.</p>
<figure id="post-10101 media-10101" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-10101" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2.png" alt="" width="1034" height="731" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2.png 1034w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2-270x191.png 270w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2-768x543.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/10/Image-2-345x245.png 345w" sizes="auto, (max-width: 1034px) 100vw, 1034px" /></figure>
<p>&nbsp;</p>
<h3>Support structures are numerous and active, but not very specialized</h3>
<p>France is a global leader in innovation with no less than 228 incubators, and around fifty accelerators. But in comparison to Israel, Switzerland and the United Kingdom, we do not have incubation or acceleration structures dedicated specifically to cyber-security. Certain incubators have created clusters to concentrate the necessary skills, but they still do not provide specialized support. It is therefore rare to find coaches in these structures who have an in-depth knowledge of the cyber market, its players and its specificities, particularly the product purchasing and qualifying process. Axeleo and Wavestone are perhaps the most similar to the dedicated foreign structures. Looking forwards, a regional initiative called Ocssimore will be starting in Toulouse in September 2017. &#8220;FrenchTech&#8221;, which enjoys excellent international visibility, has recently begun to focus on the issue of cyber-security with the creation of the <em>Security &amp; Privacy</em> network.</p>
<h3>A favorable, but perfectible funding ecosystem</h3>
<p>France has real strengths when it comes to funding innovation, and many start-ups are evidence of its effectiveness. The &#8220;Programme Investissement Avenir&#8221; (invest in the future) invests 22 billion euros in research; the Research Tax Credit and the status of &#8220;Jeune Entreprise Innovante&#8221; (young innovative enterprise) help to reduce the costs of R&amp;D, social charges, and corporate taxation.</p>
<p>For its part, BPI France provides a wide range of funding opportunities for entrepreneurs and support activities thanks to its partners (banks, investors, local authorities, etc.) and, through accelerators, it offers participatory loans and can stand as guarantor for the banks.</p>
<p>Many forms of regional support  are also available. At the same time, we are seeing a distinct increase in corporate ventures, as well as Business Angels who are often even in competition with each other to invest in the best cyber start-ups.</p>
<p>Nevertheless, the complex ecosystem with its many different players often makes finding funding complicated. The formalities for raising funds often resemble a real marathon, with bureaucracy still very much present. It is necessary to have a detailed plan of attack, to apply for every scheme at the right time with the right application… but without sacrificing the time needed to grow the start-up! Finally, few major French groups tend to acquire start-ups, with the latter being tempted to accept offers from foreign companies.</p>
<p>France has a vibrant cybersecurity start-up ecosystem; the country ranks among global leaders in this field. Indeed, the creation of start-ups in France is supported by numerous structures. But these start-ups need to find many customers for their development so they seek them among corporate accounts.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/10/cyber-security-start-ups-france-12/">Cyber-security start-ups in France, a booming ecosystem (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Startup cybersécurité en France, un écosystème en pleine explosion (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-22/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Fri, 22 Sep 2017 15:48:05 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[développement]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[start-up]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10010/</guid>

					<description><![CDATA[<p>Après un premier article consacré au sujet du radar des start-ups cybersécurité en France, ce deuxième article porte sur les leviers qui s&#8217;offrent à elles pour assurer leur développement. Comment se rapprocher des grandes entreprises ? Comment s&#8217;exporter à l&#8217;international...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-22/">Startup cybersécurité en France, un écosystème en pleine explosion (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Après un <a href="https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-11/">premier article</a> consacré au sujet du radar des start-ups cybersécurité en France, ce deuxième article porte sur les leviers qui s&#8217;offrent à elles pour assurer leur développement. Comment se rapprocher des grandes entreprises ? Comment s&#8217;exporter à l&#8217;international ? Ce sont là parmi les nombreux défis à relever pour nos start-ups<br />
</em></p>
<h2>Les grands comptes : des cibles existentielles mais complexes</h2>
<p>Le tissu économique français repose beaucoup sur des grands groupes disposant de capacités d’investissement important. Pour les startups cherchant à commercialiser leur offre en cybersécurité, ce sont des clients de choix.  Cependant, les processus rigides et complexes de ces grandes entreprises constituent un obstacle majeur pour les startups.</p>
<p>Après les embûches liées à l’identification des multiples donneurs d’ordre dans la structure (RSSI, architecte, expert, DSI, achats…), il reste très difficile de signer son premier contrat. La durée du processus d’achat allant de 3 à 6 mois et sa complexité ne correspondent pas au fonctionnement des startups, qui se voient demander des preuves de rentabilité, un nombre important d’années d’existence ou des références d’autres clients, ce qui est impossible lors des premiers contrats.</p>
<p>Cette situation est exacerbée pour la cybersécurité car les startups ne peuvent pas souvent compter sur les pôles Innovation créés par les grands-comptes pour faciliter les échanges avec l’écosystème de l’innovation. D’une part car les startups ont du mal à convaincre les apports métiers des solutions proposées et d’autre part car les équipes Innovation ont du mal à comprendre les apports concrets vu les spécificités des sujets abordés. Les retours d’expérience réussis montrent que la filière cybersécurité des grands-comptes doit souvent donner l’impulsion, voir porter elle-même les relations avec les startups cyber.</p>
<h3>Des habitudes à faire évoluer dans les grandes entreprises</h3>
<p>Une fois la mise en relation réalisée, il reste une étape : la réalisation de tests en conditions réelles (<em>Proof of Concept</em>). C’est un exemple de la difficulté pour les startups de rivaliser avec les éditeurs cybersécurité classiques dans le monde des grands comptes. Ces tests sont demandés pour évaluer l’efficacité d’une nouvelle solution. Les grands éditeurs, aux moyens financiers importants, offrent ces « PoCs » à leurs clients, qui en retour se sont habitués à ces tests « gratuits » à leur profit.</p>
<p>Pour les startups cependant la situation est différente car leur besoin en fonds de roulement est très court et réaliser de tels tests gratuitement peut mettre en péril la structure toute entière !</p>
<p>Il est donc nécessaire que les grands groupes prévoient des budgets adaptés, souvent de l’ordre de quelques milliers d’euros seulement, pour tester les solutions innovantes proposées par les startups.</p>
<h3>En France, des retours positifs dans les interactions startup/grands comptes</h3>
<p>Cependant des collaborations réussies entre startup et grands comptes montrent que ces deux mondes peuvent travailler ensemble. Et l’effort consenti apporte ensuite énormément. Des startups comme Alsid ou Idecsi bénéficient ainsi de témoignages de clients d’ampleurs à même de rassurer d’autres sociétés et les investisseurs.</p>
<h3>Un écosystème cybersécurité français valorisant l&#8217;innovation</h3>
<p>En France, la présence d’un écosystème qui fait la promotion régulière de l’innovation en associant grands comptes et startups est notable : Assises de la Sécurité avec le Prix de l’Innovation, le FIC avec le prix de la PME Innovante ou encore le concours dédié à la cybersécurité dans le milieu bancaire coorganisé par la Société Générale et Wavestone. Ces initiatives permettent une mise en lumière de l’innovation en cybersécurité, ainsi que la mise en relation directe de différents acteurs. Elles participent ainsi à la création de la relation de confiance nécessaire pour que les grands comptes investissent dans les solutions proposées par des startups.</p>
<h3>L&#8217;importance de l&#8217;existence d&#8217;une offre française pour la souveraineté numérique</h3>
<p>La cybersécurité est une problématique mondiale mais relève aussi de la sécurité nationale. L’intérêt d’avoir des produits de confiance dans ce domaine est évident.</p>
<p>Même si beaucoup reste à faire pour garantir une souveraineté numérique, les initiatives de certaines startups françaises ont permis l’importation de concepts n’existant initialement qu’à l’étranger. C’est par exemple le cas des plateformes de <em>Bug Bounty </em>(en français, « chasse aux failles »). En France, trois startups, Bug Bounty Factory, Bug Bounty Zone et Yogosha proposent des services dans ce domaine. Ceci pourra permettre à terme de garder la connaissance de vulnérabilités sensibles sur le territoire Européen ou national.</p>
<p>Il est important de noter que le marché hexagonal de la cybersécurité est largement animé par des acteurs du secteur de la défense, publics ou privés, qui investissent et aident aux développements de startups. Mais ces opportunités de développement sont en même temps un frein à l’exportation et rendent plus difficile la communication de références.</p>
<h2>Demain, arriver à sortir des frontières</h2>
<h3>Le secteur de la recherche se structure</h3>
<p>La recherche en cybersécurité est aussi très active en France avec de nombreux laboratoires mobilisés et des initiatives de premier plan. Le collectif Allistene, regroupant l’INRIA, le CEA, le CNRS et plusieurs grandes écoles, en est un exemple. De premières chaires sont dédiées aux sujets de la cybersécurité et de ses applications concrètes, par exemple pour les véhicules autonomes. Conjointement avec les initiatives des grandes entreprises, tout concourt à créer un terreau positif pour l’éclosion et la croissance de nombreuses startups.</p>
<h3>Dépasser le cadre franco-français pour croître à l&#8217;international</h3>
<p>La France possède de nombreux talents en cybersécurité, un terreau facilitant l’émergence des startups et un marché permettant de faire vivre ces structures. Mais ce bilan très positif ne doit cependant pas masquer la principale difficulté actuelle de nos startups : connaître le succès et la croissance à l’international.</p>
<p>Hormis quelques <em>success story</em>, comme historiquement Qualys ou plus récemment Linkurious aux Etats-Unis, les startups françaises ont du mal à sortir des frontières hexagonales. Elle se heurtent à des barrières sur leur capacité à communiquer de manière percutante en anglais, sur la faiblesse de références clients françaises, sur des problèmes juridiques mais aussi psychologiques à s’expatrier. Alors que la qualité des profils français en cybersécurité est largement reconnue, la qualité des startups, est-elle encore inconnue.</p>
<p>Dépasser ce plafond de verre requiert des initiatives conjointes de l’Etat, des grandes entreprises et un esprit de conquête exacerbé chez les fondateurs de startups. Mobilisons-nous collectivement, chacun avec ses forces, pour que cela devienne une réalité dans les années à venir.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-22/">Startup cybersécurité en France, un écosystème en pleine explosion (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Startup cybersécurité en France, un écosystème en pleine explosion (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-11/</link>
		
		<dc:creator><![CDATA[Jules Haddad]]></dc:creator>
		<pubDate>Thu, 14 Sep 2017 10:14:12 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[développement]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[radar]]></category>
		<category><![CDATA[start-up]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9979/</guid>

					<description><![CDATA[<p>La cybersécurité est aujourd’hui au centre des attentions et la protection des données personnelles ou la défense contre les cyberattaques sont devenues des priorités pour les entreprises et les Etats. Dans un domaine où la menace évolue sans relâche, l’innovation...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-11/">Startup cybersécurité en France, un écosystème en pleine explosion (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>La cybersécurité est aujourd’hui au centre des attentions et la protection des données personnelles ou la défense contre les cyberattaques sont devenues des priorités pour les entreprises et les Etats. Dans un domaine où la menace évolue sans relâche, l’innovation est un prérequis. Si les Etats-Unis et Israël prédominent, désormais la France se détache par le dynamisme de ses startups cybersécurité et la diversité des dispositifs mis en place pour les épauler. Zoom sur les spécificités du panorama français.</em></p>
<h2>La cybersécurité en France</h2>
<h3>Un tissu dynamique de plus de 100 startups</h3>
<p>Aujourd’hui, la France compte plus de 100 startups ou PME innovantes en matière de cybersécurité. Ce nombre, en constante augmentation, reflète le dynamisme du secteur et les atouts de la France dans ce domaine. Le secteur représente plus de 1000 emplois directs. Même si cela peut paraître faible, ce nombre devrait augmenter fortement dans les prochaines années.</p>
<h3>Une majorité de startups choisissent de réinventer des solutions de sécurité déjà bien implementées<strong><br />
</strong></h3>
<p>60% des startups entrent sur le marché avec la volonté de faire évoluer des solutions de sécurité ayant déjà fait leurs preuves (sécurité des terminaux, du réseaux, de la messagerie, gestion des identités…).</p>
<p>De manière générale, attaquer un marché déjà consolidé est complexe. Mais il reste des fenêtres d’opportunités, en particulier dans la sécurité applicative. De nombreux acteurs importants sont présents sur ce domaine sans pour autant parvenir à proposer de solutions vraiment satisfaisantes. Les approches innovantes de jeunes pousses comme Sqreen, Ingen ou encore Yagaan peuvent apporter un renouveau.</p>
<h3>Sécurité industrielle, cryptographie, et <em>reverse engineering</em> : des domaines innovants sur lesquels la France est bien positionnée</h3>
<p>En regard, de nombreuses startups françaises (40%) ont su se positionner sur des technologies où tout reste à construire. Sur les systèmes  industriels, par exemple, les acteurs français comme Sentryo ou Seclab sont particulièrement bien positionnés. C’est aussi le cas pour les technologies d’analyse de logiciels malveillants avec des produits ou des services comme ceux de Tetrane et Quarkslab. Leurs expertises sont reconnues internationalement, y compris par des grands groupes américains.</p>
<p>Côté cryptographie, l’école française de mathématiques permet aux startups d’avoir accès à des expertises pointues difficiles d’accès dans d’autres pays. Cela permet le développement d’outils innovants d’analyse de vulnérabilités comme Cryptosense.</p>
<p>En revanche, certains domaines sont encore négligés en France alors qu’ils ont un fort potentiel de développement, comme les techniques de « tromperie » (« deception » en anglais, qui vise à fournir des fausses informations à un attaquant pour le ralentir) dont l’essor est déjà amorcé en Israël et même au niveau Européen.</p>
<h3>Des startups françaises avec des difficultés de communication et de valorisation de leur expertise</h3>
<p>L’écosystème national de startups est très dynamique et les expertises, même très spécifiques, ne manquent pas pour concrétiser des idées ou lancer des premiers produits. Un point-clef est cependant requis sur le marché de la cybersécurité : la capacité à communiquer efficacement. Les contacts entretenus avec plusieurs incubateurs étrangers nous montrent une différence frappante en termes de communication entre des startups anglos-axonnes qui savent valoriser leurs produits grâce à des pitchs percutants et un marketing efficace.</p>
<p>Ce manque d’expertise commerciale est particulièrement pénalisant pour les startups françaises qui souhaitent internationaliser leurs offres.</p>
<figure id="post-9983 media-9983" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-10007 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-1-2.png" alt="" width="1058" height="647" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-1-2.png 1058w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-1-2-312x191.png 312w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-1-2-768x470.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-1-2-64x39.png 64w" sizes="auto, (max-width: 1058px) 100vw, 1058px" /></figure>
<h2>La France, une terre propice pour les startups cyber</h2>
<p>Depuis plusieurs années, de nombreuses initiatives se développent en France pour soutenir le secteur cyber. On peut citer la stratégie de Sécurité Numérique du gouvernement portée par l’ANSSI ou encore les investissements du Ministère de la Défense. Différents pôles économiques sont mobilisés, ce qui se traduit concrètement par une concentration géographique des startups. Paris est, comme souvent, en tête mais Lyon, Rennes ou le sud de la France sont aussi très présents.</p>
<h3>Présentation du radar des startups</h3>
<p>Depuis 2015, Wavestone réalise une veille active sur le domaine des startups dans le cadre de son programme <a href="http://www.wavestone.com/shakeup">ShakeUp</a>. Fort de ses nombreux contacts et actions au sein de l’écosystème de l’innovation cybersécurité en France, le radar des startups compte aujourd’hui près de 400 structures répertoriées à l’échelle européenne et internationale avec un focus particulier sur la France. Les critères pour intégrer le radar français : siège social en France, moins de 35 salariés et moins de 7 ans d’existence de la structure juridique (hors pivot majeur).</p>
<p>Suite à ces actions de veille par les équipes de la practice cybersécurité et confiance numérique, les startups les plus innovantes sont rencontrées pour réaliser une évaluation de leur solution et certaines peuvent rejoindre <a href="http://www.wavestone.com/shakeup">ShakeUp</a>, le programme d’accélération de Wavestone.</p>
<p>&nbsp;</p>
<figure id="post-9992 media-9992" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-9992" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2.png" alt="" width="1034" height="731" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2.png 1034w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2-270x191.png 270w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2-768x543.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/09/Image-2-345x245.png 345w" sizes="auto, (max-width: 1034px) 100vw, 1034px" /></figure>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h3>Des structures d&#8217;accompagnement nombreuses et actives mais peu spécialisées</h3>
<p>La France est un des leaders mondiaux dans l’innovation avec pas moins de 228 incubateurs nationaux et une cinquantaine d’accélérateurs. Mais par rapport à Israël, à la Suisse ou au Royaume-Uni, nous ne disposons pas de structures d’incubation ou d’accélération spécifiquement dédiées à la cybersécurité. Certains incubateurs ont créé des clusters pour concentrer les savoir-faire mais sans pour autant spécialiser les accompagnements. Ainsi, il est rare de trouver dans ces structures des coachs ayant une forte connaissance du marché cyber, de ses acteurs et de ses spécificités notamment dans le processus d’achat et de qualification de produits. Axeleo ou Wavestone sont ce qui se rapprochent le plus des structures étrangères dédiées.</p>
<p>A suivre, une initiative régionale nommée Ocssimore va démarrer à la rentrée 2017 à Toulouse.  La FrenchTech, très présente et visible à l’international, se mobilise depuis peu sur le sujet de la cybersécurité avec la création du réseau thématique « <em>Security &amp; Privacy</em> ».</p>
<h3>Un écosystème de financement favorable mais perfectible</h3>
<p>La France a de véritables atouts pour le financement de l’innovation, dont de nombreuses startups témoignent de l’efficacité.  Le « Programme Investissement Avenir » investit 22 milliards d’euros dans la recherche ; le « Crédit Impôt Recherche » et le statut de « Jeune Entreprise Innovante » permettent de réduire les coûts de R&amp;D, les charges sociales et l’impôt sur les sociétés.</p>
<p>De son côté, BPI France multiplie les financements dédiés aux entrepreneurs et les actions d’accompagnement grâce à ses partenaires (banques, investisseurs, régions…) et, par le biais d’accélérateurs, elle propose des prêts participatifs et peut se porter caution auprès des banques.</p>
<p>De nombreuses aides régionales sont également disponibles. En parallèle, nous assistons à une nette augmentation du <em>corporate venture</em> ainsi que les Business Angels sont parfois même en concurrence pour investir dans les meilleures startups cyber.</p>
<p>Cependant, l’écosystème complexe, avec un grand nombre d’acteurs, rend souvent le parcours de financement compliqué. Les démarches pour lever des fonds s’apparentent à de véritables marathons où la bureaucratie est encore très présente. Il s’agit d’avoir un plan de bataille précis, pour solliciter chaque dispositif au bon moment avec le bon dossier… sans pour autant sacrifier le temps destiné au développement de la startup ! Enfin, peu de grands groupes français font l’acquisition des startups, qui peuvent alors être tentées d’accepter les offres d’entreprises étrangères.</p>
<p>La France possède donc un formidable écosystème de startup dans le domaine de la cybersécurité, plaçant le pays parmi les leaders mondiaux. En effet, la création de startup en France est soutenue par des structures d&#8217;accompagnement adaptées. Mais pour assurer leur pérennité, ces startups cherchent à attirer de nombreux clients, notamment parmi les grands groupes français.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/09/cybersecurite-startup-france-11/">Startup cybersécurité en France, un écosystème en pleine explosion (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
