---
title: "Figen AI Cyber: cybersecurity and penetration testing"
description: "Training, risk assessment (DORA, NIS2) and penetration testing on a written scope, for wealth-management and finance players. Tooling hosted in France."
canonical: "https://www.figenai.com/en/figen-cyber"
locale: "en"
image: "https://www.figenai.com/images/figen-cyber-og-en.png"
---

> AI agents: this is a page of www.figenai.com. Full index of the Markdown documents for LLMs: https://www.figenai.com/llms.txt

# Figen AI Cyber · Cybersecurity for finance and wealth management

Figen AI Cyber is a cybersecurity consultancy. We train your teams, assess your risks and test your defences, on a scope agreed in writing.

For IT and cyber leadership at wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and finance players (management companies, asset managers).

Scope your perimeter in 30 minutes: email [contact@figenai.com](mailto:contact@figenai.com?subject=Figen%20AI%20Cyber%20%E2%80%94%20scoping%20call), subject "Figen AI Cyber — scoping call".

## Three fixed-fee offers

The engagement letter sets the scope, the deliverable and the delivery date.

### 01 · Training

Your teams learn to spot fraud, use their tools without exposing client files, and respond to an incident.

- Content: cyber risk, working with AI agents, new fraud techniques
- Format: 8 to 12 people, on site or remote
- Deliverable: assessment and certificate

Scope a training course: [contact@figenai.com](mailto:contact@figenai.com?subject=Figen%20AI%20Cyber%20%E2%80%94%20scoping%20call%20%E2%80%94%20Training)

### 02 · Risk assessment

We measure your gap against the rules that apply to you (DORA, NIS2, GDPR), requirement by requirement.

- Content: assets, suppliers, access, gaps ranked by priority
- Deliverable: posture report, 90-day plan, requirements matrix
- Timing: 15 working days, committee presentation

Scope an assessment: [contact@figenai.com](mailto:contact@figenai.com?subject=Figen%20AI%20Cyber%20%E2%80%94%20scoping%20call%20%E2%80%94%20Risk%20assessment)

### 03 · Penetration testing

We attack your systems the way an adversary would, on the targets listed in the contract and nothing else.

- Targets: web and API, Active Directory, email, cloud, phishing, AI agents
- Deliverable: report and sealed test log
- Timing: 10 working days, retest at D+30 included

Scope a penetration test: [contact@figenai.com](mailto:contact@figenai.com?subject=Figen%20AI%20Cyber%20%E2%80%94%20scoping%20call%20%E2%80%94%20Penetration%20testing)

## Flaws are exploited the day they go public

### Since spring 2026, disclosed severe flaws have shot up

Lines traced from the a16z chart. From 2022 to early 2026, disclosed high-severity vulnerabilities move between roughly 100 and 500, and critical ones stay under 100. From spring 2026 both series climb steeply, to about 2,300 high and 630 critical at the last point, in summer 2026.

*Critical and high-severity vulnerabilities (CVEs) disclosed by major vendors. Traced from the a16z chart, source Epoch.ai, 3 September 2026. Disclosure practices differ between vendors and the counting method may have changed, which could explain part of the rise.*

### Exploited on disclosure: 86.7% in 2026, ×4 since 2020

| Year | Exploited on or before disclosure |
|---|---|
| 2018 | 18.7% |
| 2019 | 22.4% |
| 2020 | 22.8% |
| 2021 | 31.1% |
| 2022 | 33.8% |
| 2023 | 42.2% |
| 2024 | 47.9% |
| 2025 | 53.6% |
| 2026 (part of the year) | 86.7% |


*Share of vulnerabilities exploited on or before the day they were disclosed. Source: Zerodayclock.com, via an a16z chart dated 1 September 2026. 2026 covers part of the year.*

### From months to minutes: 1.5 months in 2022, about a day in 2026

- 2022: 1.5 months
- 2026: ≈ 1 day
- 2027: 1 minute (projection)

*Median time between a flaw’s disclosure and its exploitation, on a logarithmic scale. 2027 is a projection, extrapolated from the 2018-2024 trend. Source: Zerodayclock.com, via an a16z chart dated 1 September 2026.*

## Who runs your engagements

- **Raphaël**, Cybersecurity Consultant. Leads the training courses. Skills: Web and API penetration testing, Security of AI agents, Prompt injection, Agent permissions, OWASP WSTG, OWASP ASVS.
- **Théo**, Cybersecurity Consultant. Builds our in-house testing tools. Skills: Attack surface, External reconnaissance, Infrastructure, Active Directory, MITRE ATT&CK, HackTheBox CTF.
- **Vincent Aurez**, President, Figen AI. The contact for your leadership team. Skills: Engagement lead, Coordination.

Raphaël and Théo took first place in the Paris ranking of EPITECH’s Hack & Juice, in offensive security.

### Team skills

- **Offensive security**: HackTheBox CTF, ~100 h, Bug bounty, Controlled phishing
- **Languages**: C, C++, C#, Python, Go, Java, Assembly
- **Web and data**: JavaScript, TypeScript, SQL, PostgreSQL, MongoDB
- **Cloud and DevOps**: Docker, Kubernetes, AWS, GCP, CI/CD
- **Networks and systems**: Linux, TCP/IP, Network architecture, Application security
- **Frameworks**: OWASP, MITRE ATT&CK, CIS Benchmarks, ANSSI guides

## How we work

Always:

- A scope written into the engagement letter
- Our own tooling, hosted in France
- A sealed test log, handed over at closure
- Evidence kept 12 months, then deleted under certificate
- A written proposal within 3 working days

Never:

- Testing outside the written scope
- Taking client data away
- Third-party SaaS scanners
- Subcontracting outside the European Union
- Publishing your name without a mandate

*Engagement log, illustrative excerpt, fictional hashes. Each line carries the sha256 hash of the one before.*

| Timestamp | Step | Hash |
|---|---|---|
| D1 · 09:12 | Opened | 4f9a1c02 |
| D1 · 10:41 | Reconnaissance | b7e288d1 |
| D2 · 14:03 | Authenticated test | 0c53af7e |
| D3 · 11:20 | Finding | e91d4b60 |
| D6 · 16:47 | Closure | a2f70e15 |

## Access and partnerships

- **Member of the Claude Partner Network.** Anthropic’s programme for organisations that help businesses adopt Claude.
- **OpenAI Daybreak access — Trusted Access for Cyber.** Used for our authorised penetration tests, on a written scope.

Figen AI Cyber belongs to the Figen AI group, which also publishes the [Figen OS](https://www.figenai.com/en/figen-os) software. The two are contracted separately.

## Frequently asked questions

### Does the risk assessment cover DORA and NIS2?

Yes, for the rules that apply to you. Gaps are measured requirement by requirement. Within 15 working days you receive the requirements matrix, a posture report and a dated remediation plan.

### Do you test AI agents connected to our client files?

Yes, if they are listed in the scope: prompt injection, permissions, data access. Nothing outside the written scope is tested. The report follows within 10 working days, with a retest at D+30.

### What happens to our data?

Our tools run on servers in France, with no transfer outside the European Union. Evidence is encrypted, kept for 12 months, then deleted under certificate. A non-disclosure agreement is signed before the first technical discussion.

### How do we start?

With a 30-minute call to set the scope, requested by email. A written proposal follows within 3 working days.

## Thirty minutes is enough to set the scope

Tell us what you want tested or taught. Written proposal within 3 working days.


Email [contact@figenai.com](mailto:contact@figenai.com?subject=Figen%20AI%20Cyber%20%E2%80%94%20scoping%20call), subject "Figen AI Cyber — scoping call".

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.figenai.com#organization","name":"Figen AI","url":"https://www.figenai.com","logo":"https://www.figenai.com/storage/themes/olmo/images/JePmyKLJ2sTdxtjOm3sUTT6tiAiZWRVyeLM0qfF9.png","sameAs":["https://www.linkedin.com/company/105251957/","https://x.com/Figen_AI","https://www.youtube.com/@FigenAI","https://annuaire-entreprises.data.gouv.fr/entreprise/figen-ai-939277752","https://www.societe.com/societe/figen-ai-939277752.html"],"contactPoint":[{"@type":"ContactPoint","contactType":"customer support","email":"contact@figenai.com","url":"https://www.figenai.com/en/contact","availableLanguage":["French","English"],"areaServed":"FR"},{"@type":"ContactPoint","contactType":"sales","email":"contact@figenai.com","url":"https://cal.com/team/figen-ai/demonstration-figen-ai","availableLanguage":["French","English"],"areaServed":"FR"}],"founder":[{"@type":"Person","@id":"https://www.figenai.com#vincent-aurez","name":"Vincent Aurez","jobTitle":"Cofondateur et Président (CEO)","worksFor":{"@id":"https://www.figenai.com#organization"},"sameAs":["https://www.linkedin.com/in/vincentaurez/","https://x.com/vincentaurez"]},{"@type":"Person","@id":"https://www.figenai.com#nicolas-paulus","name":"Nicolas Paulus","jobTitle":"Cofondateur et CTO","worksFor":{"@id":"https://www.figenai.com#organization"}}]}
{"@context":"https://schema.org","@type":"WebSite","name":"Figen AI","url":"https://www.figenai.com","publisher":{"@id":"https://www.figenai.com#organization"},"inLanguage":"en"}
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://www.figenai.com#website","name":"Figen AI","url":"https://www.figenai.com","publisher":{"@id":"https://www.figenai.com#organization"}},{"@type":"Organization","@id":"https://www.figenai.com#figen-ai-cyber","name":"Figen AI Cyber","url":"https://www.figenai.com/figen-cyber","description":"Figen AI Cyber is a cybersecurity consultancy. We train your teams, assess your risks and test your defences, on a scope agreed in writing.","parentOrganization":{"@id":"https://www.figenai.com#organization"},"email":"contact@figenai.com","contactPoint":{"@type":"ContactPoint","contactType":"Scoping","email":"contact@figenai.com","availableLanguage":["French","English"],"areaServed":"FR"},"areaServed":["France","European Union"],"memberOf":{"@type":"Organization","name":"Claude Partner Network"},"knowsAbout":["DORA","NIS2","GDPR","Penetration testing"]},{"@type":"Service","@id":"https://www.figenai.com/en/figen-cyber#service-formation","name":"Cybersecurity training","serviceType":"Cybersecurity training","description":"Your teams learn to spot fraud, use their tools without exposing client files, and respond to an incident.","provider":{"@id":"https://www.figenai.com#figen-ai-cyber"},"brand":{"@id":"https://www.figenai.com#organization"},"audience":{"@type":"BusinessAudience","audienceType":"IT and cybersecurity leadership of wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and of finance players (management companies, asset managers)"},"areaServed":["France","European Union"],"availableLanguage":["fr","en"],"url":"https://www.figenai.com/en/figen-cyber#fc-formation"},{"@type":"Service","@id":"https://www.figenai.com/en/figen-cyber#service-analyse-des-risques","name":"Cyber risk assessment","serviceType":"Cyber risk assessment","description":"We measure your gap against the rules that apply to you (DORA, NIS2, GDPR), requirement by requirement.","provider":{"@id":"https://www.figenai.com#figen-ai-cyber"},"brand":{"@id":"https://www.figenai.com#organization"},"audience":{"@type":"BusinessAudience","audienceType":"IT and cybersecurity leadership of wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and of finance players (management companies, asset managers)"},"areaServed":["France","European Union"],"availableLanguage":["fr","en"],"url":"https://www.figenai.com/en/figen-cyber#fc-analyse"},{"@type":"Service","@id":"https://www.figenai.com/en/figen-cyber#service-tests-d-intrusion","name":"Penetration testing","serviceType":"Penetration testing","description":"We attack your systems the way an adversary would, on the targets listed in the contract and nothing else.","provider":{"@id":"https://www.figenai.com#figen-ai-cyber"},"brand":{"@id":"https://www.figenai.com#organization"},"audience":{"@type":"BusinessAudience","audienceType":"IT and cybersecurity leadership of wealth-management players (groups, mutual insurers, private banks, banks, financial distribution networks) and of finance players (management companies, asset managers)"},"areaServed":["France","European Union"],"availableLanguage":["fr","en"],"url":"https://www.figenai.com/en/figen-cyber#fc-intrusion"},{"@type":"Person","@id":"https://www.figenai.com/en/figen-cyber#equipe-raphael","name":"Raphaël","givenName":"Raphaël","jobTitle":"Cybersecurity Consultant","worksFor":{"@id":"https://www.figenai.com#figen-ai-cyber"},"award":"First place, Paris ranking, Hack & Juice (EPITECH), offensive security","knowsAbout":["Web and API penetration testing","Security of AI agents","Prompt injection","Agent permissions","OWASP WSTG","OWASP ASVS"]},{"@type":"Person","@id":"https://www.figenai.com/en/figen-cyber#equipe-theo","name":"Théo","givenName":"Théo","jobTitle":"Cybersecurity Consultant","worksFor":{"@id":"https://www.figenai.com#figen-ai-cyber"},"award":"First place, Paris ranking, Hack & Juice (EPITECH), offensive security","knowsAbout":["Attack surface","External reconnaissance","Infrastructure","Active Directory","MITRE ATT&CK","HackTheBox CTF"]},{"@type":"WebPage","@id":"https://www.figenai.com/en/figen-cyber#webpage","url":"https://www.figenai.com/en/figen-cyber","name":"Figen AI Cyber: cybersecurity and penetration testing","headline":"Cybersecurity for finance and wealth management","description":"Training, risk assessment (DORA, NIS2) and penetration testing on a written scope, for wealth-management and finance players. Tooling hosted in France.","inLanguage":"en","isPartOf":{"@id":"https://www.figenai.com#website"},"publisher":{"@id":"https://www.figenai.com#organization"},"about":{"@id":"https://www.figenai.com#figen-ai-cyber"},"mainEntity":{"@id":"https://www.figenai.com#figen-ai-cyber"},"hasPart":{"@id":"https://www.figenai.com/en/figen-cyber#faq"},"breadcrumb":{"@id":"https://www.figenai.com/en/figen-cyber#breadcrumb"}},{"@type":"BreadcrumbList","@id":"https://www.figenai.com/en/figen-cyber#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Figen AI","item":"https://www.figenai.com/en"},{"@type":"ListItem","position":2,"name":"Figen AI Cyber","item":"https://www.figenai.com/en/figen-cyber"}]},{"@type":"FAQPage","@id":"https://www.figenai.com/en/figen-cyber#faq","inLanguage":"en","mainEntity":[{"@type":"Question","name":"Does the risk assessment cover DORA and NIS2?","acceptedAnswer":{"@type":"Answer","text":"Yes, for the rules that apply to you. Gaps are measured requirement by requirement. Within 15 working days you receive the requirements matrix, a posture report and a dated remediation plan."}},{"@type":"Question","name":"Do you test AI agents connected to our client files?","acceptedAnswer":{"@type":"Answer","text":"Yes, if they are listed in the scope: prompt injection, permissions, data access. Nothing outside the written scope is tested. The report follows within 10 working days, with a retest at D+30."}},{"@type":"Question","name":"What happens to our data?","acceptedAnswer":{"@type":"Answer","text":"Our tools run on servers in France, with no transfer outside the European Union. Evidence is encrypted, kept for 12 months, then deleted under certificate. A non-disclosure agreement is signed before the first technical discussion."}},{"@type":"Question","name":"How do we start?","acceptedAnswer":{"@type":"Answer","text":"With a 30-minute call to set the scope, requested by email. A written proposal follows within 3 working days."}}]}]}
```
