🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in

Local authorities · Cybersecurity & NIS2 compliance

Cybersecurity for your local authority, without straining your budget

The NIS2 directive, online public services to accredit, ransomware paralysing town halls, tight budgets and a small IT team: we know your daily reality.

Cyber-SSI already supports around ten local authorities, from a small municipality to a county council, including an inter-municipal syndicate. Our approach comes down to three things: experts, fixed-price packages with no lock-in, and support that adapts to the way you work, on site or remotely, as you need.

~10
local authorities supported, from municipalities to county councils
90+
local authority IT directors met since the start of 2026
65–70%
potential saving compared with hiring an in-house CISO
Your challenges

We know your challenges, we deal with them every day

Since the start of 2026, we have spoken with more than 90 local authority IT directors.

Every conversation, even when it leads to neither a quote nor a signature, teaches us something: it lets us map the real issues by size, structure and location of each authority, and refine solutions that genuinely fit.

The result: we know your daily reality, because we discuss it every week.

01

Lack of time

Your IT department is already chasing day-to-day work: the information security policy is out of date, policies are unwritten, and governance always comes after tasks deemed more urgent.

02

Lack of budget

A cybersecurity budget is never a given: you have to convince senior management and elected officials, who are often not well aware of the risks.

03

Lack of resources

Recruiting relevant cyber profiles is hard; recruiting a CISO is even harder.

Three challenges come up almost every time. The best way forward: talk to us directly about them.

Our speciality

Outsourced CISO: a cybersecurity expert who specialises in local authorities

Hiring a CISO (chief information security officer) is expensive, and experienced profiles are scarce, all the more so for a local authority. A shared-time model changes that: you get an expert CISO, at the volume that matches your real need and your budget.

This is our speciality. We support local authorities as an outsourced CISO every day: it is our core business, not a side activity. And if your territory is organised as a shared structure (syndicate, inter-municipal body), we keep up the pace: we already do it daily for several entities across the same territory.

And because we are a mobile company, we travel to your site as needed: your CISO is not an email address, it is a person who adapts to the way you work. All of it with no lock-in: you adjust the volume to your needs and your annual budget.

Outsourced CISO

1 expert CISO
at the volume you actually need

We already support:

MunicipalitiesCounty councilInter-municipal syndicateInter-municipal bodies

Shared structures too: we keep up the pace for several entities across the same territory, day in day out.

In practice, as your outsourced CISO, we take charge of:

  • steering your security strategy (information security policy, roadmap, prioritisation);
  • tracking risks and the action plan, year after year;
  • staff awareness training (the first line of defence against phishing);
  • a regular cyber committee with your teams and elected officials, and clear reporting;
  • preparing and maintaining your NIS2 compliance;
  • a named point of contact in the event of an incident.
The comparison

In-house CISO or outsourced CISO? The numbers compared

Hiring an in-house CISO means a rare, expensive profile that takes a long time to find: on the French market in 2026, an experienced CISO represents a fully loaded employer cost of €130,000 to €156,000 per year, and 6 to 9 months pass between the decision to hire and a fully operational CISO (sourcing, notice period, ramp-up). Meanwhile, your compliance work waits.

CriterionIn-house CISO (permanent contract)Cyber-SSI outsourced CISO
Cost€130,000–156,000/year (loaded) + recruitmentUp to ~65–70% saving, calibrated on your real need
Start-up6 to 9 monthsOperational from day 1 (1 to 2 weeks)
ContinuityInterrupted by every absence or departureLead + backup pairing: no interruption
FlexibilityFixed full time, whatever the workloadVolume adjustable up or down
FitLikely under-use (small authority)You only pay for what you actually need

And if your territory operates as a shared structure, this already reduced cost is split further between entities.

Our CISOs already know your environment.

Each of our CISOs supports at least two local authorities. They therefore know your way of working, your constraints, and above all your business tools and software vendors (civil registry, finance, urban planning, citizen relationship management, etc.) inside out. The result: no ramp-up time, they are operational from day one, where a profile from the private sector would have everything to discover.

And in the interest of transparency:

if your workload were ever to exceed around fifteen days a month on a lasting basis, an in-house CISO would become the more rational choice: we would be the first to tell you, and we could even help you prepare that recruitment. We recommend the right solution, not the one that suits us.

NIS2 directive

NIS2: already an obligation, or a deadline to anticipate, depending on your size

The NIS2 directive significantly widens the scope of entities subject to cybersecurity obligations, and local authorities are on the front line. Depending on your size and your remit, there are two situations:

You are already in scope

Regions, departments, large inter-municipal bodies and authorities above certain thresholds may qualify as an essential or important entity, with obligations already in force. You may also be directly in scope because of the services you operate: a water utility, for example, or another essential service. The challenge is then to become compliant without delay, and to demonstrate it.

You are not (yet) directly in scope

Many municipalities fall below the thresholds but remain affected indirectly (suppliers, satellite bodies, expectations from the State) and have every interest in anticipating: NIS2 good practices are also the ones that genuinely protect you from an attack.

In both cases, we first help you find out where you stand, then move forward in useful steps: risk analysis, governance, technical measures, continuity planning, incident management. The simplest way to work out your situation: talk to us directly.

Our support

Our other services for local authorities

EBIOS RM risk analysis in under a week

The ANSSI reference method, delivered quickly by expert consultants: risk mapping, scenarios, prioritised treatment plan. Useful for NIS2, for an accreditation, or simply to know where to start.

Learn more about EBIOS RM

Online public service accreditation

Opening an online service to citizens? We support you through its security accreditation process, from analysis to decision.

Staff awareness training

A concrete, jargon-free programme designed for teams who are not IT specialists.

Audit & penetration testing

To measure your real level objectively and prioritise fixes.

See our penetration testing

Incident response and post-incident support

Someone who already knows your systems on the day it matters.

See our incident response

CISO coaching

We build up the skills of future local authority CISOs: hands-on support on your real subjects, supervised by a senior CISO who also has training experience.

Q&A workshop · 15 minutes

Put your questions to a local authority CISO

A specific question about cybersecurity, governance, NIS2 compliance, or how to secure more budget? Book a 15-minute Q&A workshop with a CISO who supports several local authorities. You come with your questions, you leave with concrete answers, no lock-in, and no sales pitch. It is the simplest way to benefit from our public sector experience, whether or not your project is mature.

Public procurement

Off-contract or public tender: we adapt to your purchasing model

We work equally well off-contract and through public tenders: you choose, according to your authority's purchasing policy.

Off-contract (direct award)

Below public procurement thresholds, a local authority can contract by direct award. In that case we provide a compliant quote within 48 hours, and we can start as soon as the quote is signed, with no heavy procedure.

Through public tender

If your policy requires a formal procedure (adapted procedure, call for tenders), we respond to your consultations. Our fixed-price services fit easily into a contract framework.

All our services are sized for simple, fast purchasing: diagnostic, EBIOS RM in a week, targeted NIS2 support, monthly outsourced CISO. And because our contracts have no lock-in, they align naturally with the annual nature of your budget: you never commit the authority beyond the voted financial year.

Why Cyber-SSI

Why local authorities choose us

  • Experts operational from day 1. No ramp-up time billed to your project.

  • Fixed-price packages, no overruns. You know what you are committing to; the invoice does not drift.

  • No lock-in. You stay in control, financial year after financial year.

  • On site or remotely, as you need. A French, mobile company that adapts to how each client works.

  • A team that knows the public sector: NIS2, ANSSI, accreditation, budget constraints and governance with elected officials.

References

They trust us

Around ten local authorities already trust us, across varied scopes. A few examples (anonymised):

A county council

Outsourced CISO, online public service accreditation, EBIOS RM risk analysis, drafting of security policies, penetration testing and configuration audit.

Outsourced CISO

An inter-municipal syndicate: 5 municipalities & 2 inter-municipal bodies

Outsourced CISO, online public service accreditation, EBIOS RM risk analysis, security policies, penetration testing, configuration audit, HDS health data hosting compliance, ExpertCyber label obtained, and ISO 27001 certification in progress.

Outsourced CISO

A local authority in the Île-de-France region

EBIOS RM risk analysis.

EBIOS RM

Let's talk about your authority

An in-depth conversation with an expert consultant, with no lock-in and no sales pitch.

Book a meeting: 30 min

We use audience measurement cookies (Google Analytics) to improve your experience. No cookie is set without your consent. Learn more