Figen AICyber

Cybersecurity for finance and wealth management

Figen AI Cyber is a cybersecurity consultancy. We train your teams, assess your risks and test your defences, on a scope agreed in writing.

For IT and cyber leadership at wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and finance players (management companies, asset managers).

Illustration: what is inside the scope gets tested, the rest does not.

What we offer

Three fixed-fee offers

The engagement letter sets the scope, the deliverable and the delivery date.

  1. 01

    Training

    Your teams learn to spot fraud, use their tools without exposing client files, and respond to an incident.

    Content
    cyber risk, working with AI agents, new fraud techniques
    Format
    8 to 12 people, on site or remote
    Deliverable
    assessment and certificate
    Scope a training course
  2. 02

    Risk assessment

    We measure your gap against the rules that apply to you (DORA, NIS2, GDPR), requirement by requirement.

    Content
    assets, suppliers, access, gaps ranked by priority
    Deliverable
    posture report, 90-day plan, requirements matrix
    Timing
    15 working days, committee presentation
    Scope an assessment
  3. 03

    Penetration testing

    We attack your systems the way an adversary would, on the targets listed in the contract and nothing else.

    Targets
    web and API, Active Directory, email, cloud, phishing, AI agents
    Deliverable
    report and sealed test log
    Timing
    10 working days, retest at D+30 included
    Scope a penetration test

Why now

Flaws are exploited the day they go public

Since spring 2026, disclosed severe flaws have shot up

Lines traced from the a16z chart. From 2022 to early 2026, disclosed high-severity vulnerabilities move between roughly 100 and 500, and critical ones stay under 100. From spring 2026 both series climb steeply, to about 2,300 high and 630 critical at the last point, in summer 2026.

Critical and high-severity vulnerabilities (CVEs) disclosed by major vendors. Traced from the a16z chart, source Epoch.ai, 3 September 2026. Disclosure practices differ between vendors and the counting method may have changed, which could explain part of the rise.

Exploited on disclosure: 86.7% in 2026, ×4 since 2020

Bar chart, share of vulnerabilities exploited on or before the day they were disclosed: 18.7% in 2018, 22.4% in 2019, 22.8% in 2020, 31.1% in 2021, 33.8% in 2022, 42.2% in 2023, 47.9% in 2024, 53.6% in 2025, 86.7% in 2026 (part of the year).

Share of vulnerabilities exploited on or before the day they were disclosed. Source: Zerodayclock.com, via an a16z chart dated 1 September 2026. 2026 covers part of the year (*).

From months to minutes: 1.5 months in 2022, about a day in 2026

Logarithmic scale: a median of 1.5 months in 2022, about 1 day in 2026, and a projected 1 minute in 2027.

Median time between a flaw’s disclosure and its exploitation, on a logarithmic scale. 2027 is a projection, extrapolated from the 2018-2024 trend. Source: Zerodayclock.com, via an a16z chart dated 1 September 2026.

The team

Who runs your engagements

Raphaël and Théo took first place in the Paris ranking of EPITECH’s Hack & Juice, in offensive security.

  • Raphaël

    Cybersecurity Consultant

    Leads the training courses.

    • Web and API penetration testing
    • Security of AI agents
    • Prompt injection
    • Agent permissions
    • OWASP WSTG
    • OWASP ASVS
  • Théo

    Cybersecurity Consultant

    Builds our in-house testing tools.

    • Attack surface
    • External reconnaissance
    • Infrastructure
    • Active Directory
    • MITRE ATT&CK
    • HackTheBox CTF
  • Vincent Aurez

    President, Figen AI

    The contact for your leadership team.

    • Engagement lead
    • Coordination

Team skills

Offensive security
  • HackTheBox CTF, ~100 h
  • Bug bounty
  • Controlled phishing
Languages
  • C
  • C++
  • C#
  • Python
  • Go
  • Java
  • Assembly
Web and data
  • JavaScript
  • TypeScript
  • SQL
  • PostgreSQL
  • MongoDB
Cloud and DevOps
  • Docker
  • Kubernetes
  • AWS
  • GCP
  • CI/CD
Networks and systems
  • Linux
  • TCP/IP
  • Network architecture
  • Application security
Frameworks
  • OWASP
  • MITRE ATT&CK
  • CIS Benchmarks
  • ANSSI guides

Method

How we work

Always

  • A scope written into the engagement letter
  • Our own tooling, hosted in France
  • A sealed test log, handed over at closure
  • Evidence kept 12 months, then deleted under certificate
  • A written proposal within 3 working days

Never

  • Testing outside the written scope
  • Taking client data away
  • Third-party SaaS scanners
  • Subcontracting outside the European Union
  • Publishing your name without a mandate
Engagement logIllustrative excerpt, fictional hashes
TimestampStepHash
D1 · 09:12Opened4f9a1c02
D1 · 10:41Reconnaissanceb7e288d1
D2 · 14:03Authenticated test0c53af7e
D3 · 11:20Findinge91d4b60
D6 · 16:47Closurea2f70e15

Each line carries the sha256 hash of the one before.

Access and partnerships

  • Member of the Claude Partner Network

    Anthropic’s programme for organisations that help businesses adopt Claude.

  • OpenAI Daybreak access — Trusted Access for Cyber

    Used for our authorised penetration tests, on a written scope.

FAQ

Frequently asked questions

Does the risk assessment cover DORA and NIS2?

Yes, for the rules that apply to you. Gaps are measured requirement by requirement. Within 15 working days you receive the requirements matrix, a posture report and a dated remediation plan.

Do you test AI agents connected to our client files?

Yes, if they are listed in the scope: prompt injection, permissions, data access. Nothing outside the written scope is tested. The report follows within 10 working days, with a retest at D+30.

What happens to our data?

Our tools run on servers in France, with no transfer outside the European Union. Evidence is encrypted, kept for 12 months, then deleted under certificate. A non-disclosure agreement is signed before the first technical discussion.

How do we start?

With a 30-minute call to set the scope, requested by email. A written proposal follows within 3 working days.

Next step

Thirty minutes is enough to set the scope

Tell us what you want tested or taught. Written proposal within 3 working days.

Figen AICyberFigen AI group · Paris

Figen AI Cyber belongs to the Figen AI group, which also publishes the Figen OS software. The two are contracted separately.