You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Noam HakouneNH

Noam Hakoune

Cybersecurity GRC CISO - CISSP - ISO27001 - NIS2

€600/day
1 project
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Noam

Cybersecurity Consultant | CISO | GRC | Audit & Risk Management | Trainer

Do you want to structure your cybersecurity, reduce your risks, or meet growing regulatory requirements?

I act as an external CISO / shared CISO, cybersecurity consultant, or GRC expert for SMEs, mid-sized companies, and sensitive organizations to transform their security constraints into concrete, managed, and operational programs.

CISO & Governance
  • Cyber strategy and roadmap
  • IS Security Governance, PSSI, policies, and procedures
  • Cyber project management: scoping, budget, vendors
  • CISO dashboards and KPIs
  • Employee awareness
  • Supervision of cyber projects
  • Executive Committee presentations

Governance, Risk, and Compliance (GRC)

  • Risk mapping, EBIOS RM, ISO 27005
  • Treatment and remediation plans
  • GDPR, NIS2, DORA compliance
  • Third-party risk management (TPRM)

Industrial Cybersecurity (OT)

  • Securing IT/OT environments (IEC 62443)
  • Risk analysis on industrial systems
  • IT/OT segmentation and convergence
  • Support for OIV (Operators of Critical Importance) and critical sectors
- OT CISO

ISO 27001 & ISO 22301 Support

  • Maturity assessment
  • Implementation of an ISMS (scope, gaps)
  • Documentation and preparation for certification audits
  • BUILD & RUN, continuous improvement

Cybersecurity Audits

  • IT audits (compliance and organizational)
  • Prioritization of corrective actions
  • Post-audit team support

Cyber Crisis Management & Resilience

  • Crisis exercises and incident response
  • IT, business, and management coordination
  • Business continuity and disaster recovery plans (BCP/DRP)

Training

  • AFNOR IEC 62443 Trainer
  • Cyber warfare and geopolitical issues
  • CISSP Training

My goal: to enable organizations to move from reactive cybersecurity to structured, managed cybersecurity aligned with their business objectives.

Available on a time and materials or fixed-price basis, on-site or remote.

Contact me.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • ChapsVision
    Cybersecurity Consultant / External CISO
    CONSULTING AND AUDITS
    October 2023 - June 2026 (2 years and 8 months)
    Paris, France

    Context

    Supporting critical organizations, industrials, and large accounts in structuring their cybersecurity in the face of evolving threats, regulatory requirements (NIS2), IT/OT convergence, and digital sovereignty.
    Sensitive clients: OIV, industrials, energy, and major technology groups.

    Missions

    External CISO & Cybersecurity Governance
    • Cybersecurity governance for organizations without a full-time internal CISO.
    • Strategic direction and support for IT/OT teams
    • Security roadmaps aligned with business objectives.
    Risk Analysis & Compliance
    • Risk analyses
    • Risk treatment plans.
    • Support for NIS2 compliance.
    Industrial Cybersecurity (OT)
    • Cybersecurity specifications for critical industrial environments.
    • Security measures adapted to OT/IT constraints.
    • Analysis of industrial architectures and security recommendations.
    • Implementation of best practices with the teams.
    AI Governance & Cybersecurity
    • Support for AI usage governance.
    • Review of AI cybersecurity best practices for vendor solutions and tools (Chaps).
    • Risks related to new uses (confidentiality, sensitive data, supplier dependency, sovereignty).
    Cyber Crisis Management (+15 exercises)
    • Scenario and timeline design
    • Scenario facilitation
    • Lessons learned
    Resilience
    • BCP/DRP design

    Methods & Frameworks

    • EBIOS RM, ISO 22301 / ISO 27005, NIS2, NIST AI RMF
    • IS Security Governance, IT/OT Risk Analysis
    • OT Security, AI Governance, Digital Sovereignty

    Results

    • Structuring of cybersecurity approaches in critical environments.
    • Improved visibility of cyber risks for management.
    • Action plans reducing threat exposure.
    • Preparation for new regulatory requirements.
    • Enhanced resilience level
    CISO Risk Analysis Industrial Cybersecurity NIS2 AI and Cybersecurity
  • Nexa digital group
    Cybersecurity Speaker & Consultant
    EDUCATION AND E-LEARNING
    September 2023 - Today (2 years and 11 months)
    Paris, France

    Context

    Supporting students, professionals, and organizations on current cybersecurity issues, with an approach combining technical expertise, strategy, and understanding of business impacts.

    Missions

    Cybersecurity Training & Awareness
    • Design and delivery of cybersecurity training.
    • Transfer of IT security fundamentals to technical and non-technical audiences.
    • Awareness of new cyber threats.
    Cybersecurity Consulting
    • Intervention on security governance issues.
    • Presentation of best practices for structuring a cyber strategy.
    • Support for organizational issues related to cybersecurity.
    Conferences & Specialized Content
    • Industrial cybersecurity.
    • Economic and strategic impact of cyberattacks.
    • Cyber geopolitics.
    • Cyber warfare and new digital power dynamics.

    Topics Covered

    • Cybersecurity strategy
    • IS Security Governance
    • Cyber risks
    • Industrial cybersecurity
    • Employee awareness

    Results

    • Training of technical profiles and decision-makers on cyber issues.
    • Acculturation of organizations to digital risks.
    • Development of a better understanding of the business impacts of cybersecurity.
    Industrial Cybersecurity Cybersecurity Strategy cybersecurity training Cybersecurity Awareness Cyber Consulting
  • Risk&Co
    GRC Cybersecurity and Industrial Security Consultant
    CONSULTING AND AUDITS
    September 2022 - October 2023 (1 year and 1 month)
    Levallois-Perret, France

    Context

    Consulting mission with industrial players wishing to strengthen their security level, structure their IS Security Governance, and improve their cyber risk management.

    Missions

    Cybersecurity Risk Management
    • Conducting risk analyses according to EBIOS RM and ISO 27005 methodologies.
    • Identification of threats, vulnerabilities, and business impacts.
    • Construction of risk maps.
    • Definition of treatment plans and security recommendations.
    IS Security Governance
    • Drafting and evolution of PSSI
    • Creation of security frameworks and procedures
    • Support for structuring cybersecurity initiatives
    Network and Architecture Security

    • Network architecture analysis
    • Identification of weaknesses
    • Security recommendations adapted to industrial constraints

    Methods and Frameworks

    • EBIOS RM
    • ISO 27001
    • ISO 27005
    • ISO 22301
    • Risk Analysis
    • IS Security Governance
    • Industrial Security

    Results

    • Strengthening the cyber maturity of supported organizations
    • Formalization of security governance processes
    • Improved management of industrial cyber risks
    Risk Analysis Cyber Threat Intelligence Network Security Security Policy

Reviews

5.0

Out of 1 rating

D

Déborah

Responsable opérationnelle - L.Estomate SAS

Reviewed on 7/13/2026

As the director of a communication agency, I was advised to conduct a cybersecurity risk analysis. I knew the subject was important, especially since we handle client data, access to various accounts, and numerous online tools daily, but I didn't fully grasp all the risks our company could be exposed to. Noam took the time to analyze our operations, identify vulnerabilities, and propose concrete security recommendations tailored to our business and knowledge level. His approach is very professional, educational, and above all, entirely personalized: he didn't just provide a list of generic recommendations but truly guided us in our thinking and implementation. The interactions were very smooth and pleasant. Noam is attentive, responsive, and knows how to make seemingly technical subjects accessible. Thanks to his support, we were able to ask the right questions, implement concrete measures, and further secure our company, our data, and that of our clients.

Recommendations

DL
TL
Diane Lipszyc and 1 other person have recommended Noam

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Risks, International Security, and Cybersecurity
    Ecole de Guerre Economique
    2020
    Cybersécurité - Mise en conformité - Sécurité réseau - Chefferie de projet cyber - Intelligence économique - gestion des risques - Veille

Certifications

Skill set

Categories