Figen AICyber
Cybersecurity for finance and wealth management
Figen AI Cyber is a cybersecurity consultancy. We train your teams, assess your risks and test your defences, on a scope agreed in writing.
For IT and cyber leadership at wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and finance players (management companies, asset managers).
What we offer
Three fixed-fee offers
The engagement letter sets the scope, the deliverable and the delivery date.
-
01
Training
Your teams learn to spot fraud, use their tools without exposing client files, and respond to an incident.
- Content
- cyber risk, working with AI agents, new fraud techniques
- Format
- 8 to 12 people, on site or remote
- Deliverable
- assessment and certificate
-
02
Risk assessment
We measure your gap against the rules that apply to you (DORA, NIS2, GDPR), requirement by requirement.
- Content
- assets, suppliers, access, gaps ranked by priority
- Deliverable
- posture report, 90-day plan, requirements matrix
- Timing
- 15 working days, committee presentation
-
03
Penetration testing
We attack your systems the way an adversary would, on the targets listed in the contract and nothing else.
- Targets
- web and API, Active Directory, email, cloud, phishing, AI agents
- Deliverable
- report and sealed test log
- Timing
- 10 working days, retest at D+30 included
Why now
Flaws are exploited the day they go public
Since spring 2026, disclosed severe flaws have shot up
Lines traced from the a16z chart. From 2022 to early 2026, disclosed high-severity vulnerabilities move between roughly 100 and 500, and critical ones stay under 100. From spring 2026 both series climb steeply, to about 2,300 high and 630 critical at the last point, in summer 2026.
Exploited on disclosure: 86.7% in 2026, ×4 since 2020
Bar chart, share of vulnerabilities exploited on or before the day they were disclosed: 18.7% in 2018, 22.4% in 2019, 22.8% in 2020, 31.1% in 2021, 33.8% in 2022, 42.2% in 2023, 47.9% in 2024, 53.6% in 2025, 86.7% in 2026 (part of the year).
From months to minutes: 1.5 months in 2022, about a day in 2026
Logarithmic scale: a median of 1.5 months in 2022, about 1 day in 2026, and a projected 1 minute in 2027.
The team
Who runs your engagements
Raphaël and Théo took first place in the Paris ranking of EPITECH’s Hack & Juice, in offensive security.
-
Raphaël
Cybersecurity Consultant
Leads the training courses.
-
Théo
Cybersecurity Consultant
Builds our in-house testing tools.
-
Vincent Aurez
President, Figen AI
The contact for your leadership team.
Team skills
- Offensive security
- Languages
- Web and data
- Cloud and DevOps
- Networks and systems
- Frameworks
Method
How we work
Always
- A scope written into the engagement letter
- Our own tooling, hosted in France
- A sealed test log, handed over at closure
- Evidence kept 12 months, then deleted under certificate
- A written proposal within 3 working days
Never
- Testing outside the written scope
- Taking client data away
- Third-party SaaS scanners
- Subcontracting outside the European Union
- Publishing your name without a mandate
| Timestamp | Step | Hash |
|---|---|---|
| D1 · 09:12 | Opened | 4f9a1c02 |
| D1 · 10:41 | Reconnaissance | b7e288d1 |
| D2 · 14:03 | Authenticated test | 0c53af7e |
| D3 · 11:20 | Finding | e91d4b60 |
| D6 · 16:47 | Closure | a2f70e15 |
Each line carries the sha256 hash of the one before.
Access and partnerships
-
Member of the Claude Partner Network
Anthropic’s programme for organisations that help businesses adopt Claude.
-
OpenAI Daybreak access — Trusted Access for Cyber
Used for our authorised penetration tests, on a written scope.
FAQ
Frequently asked questions
Does the risk assessment cover DORA and NIS2?
Yes, for the rules that apply to you. Gaps are measured requirement by requirement. Within 15 working days you receive the requirements matrix, a posture report and a dated remediation plan.
Do you test AI agents connected to our client files?
Yes, if they are listed in the scope: prompt injection, permissions, data access. Nothing outside the written scope is tested. The report follows within 10 working days, with a retest at D+30.
What happens to our data?
Our tools run on servers in France, with no transfer outside the European Union. Evidence is encrypted, kept for 12 months, then deleted under certificate. A non-disclosure agreement is signed before the first technical discussion.
How do we start?
With a 30-minute call to set the scope, requested by email. A written proposal follows within 3 working days.
Next step
Thirty minutes is enough to set the scope
Tell us what you want tested or taught. Written proposal within 3 working days.
By email to [email protected].
Figen AICyberFigen AI group · Paris
Figen AI Cyber belongs to the Figen AI group, which also publishes the Figen OS software. The two are contracted separately.