Skip to content
A generated model manifold: a graph of nodes and edges in three dimensions, the near layer sharp and the far layer dissolving.

About

One clean cut. Everything in proportion.

Sectius comes from sectio aurea, the golden section. The name is a method, not an ornament.

The story

01

The golden section

Sectius comes from sectio aurea, "the golden section" — the name Renaissance geometers such as Luca Pacioli and Kepler gave to the golden ratio. Euclid defined it 2,300 years ago as the division of a line "in extreme and mean ratio": there is exactly one way to cut a segment so that the whole is to the larger part as the larger part is to the smaller. One cut, and everything is in proportion.

That is what this firm does with security and compliance. Sectio, the cut: the work starts with a precise cut — defining the perimeter, separating what is critical from what is not, segmenting networks, classifying data, deciding which obligations truly apply. We cut cleanly.

Aurea, the right proportion: not the over-engineered security that paralyses a mid-size company, not the under-investment that exposes it; not cosmetic compliance, not bureaucracy. The right measure, calibrated to the organisation.

One cut that holds: the golden section is the only cut where every part stays in proportion to the whole. We aim for the same — one coherent programme across cyber, compliance, cloud and AI, where evidence is produced once and every control serves the whole.

The name is pronounced "sek-ti-us", three light syllables, the same in English, French, Spanish, German and Arabic.

02

The pressure

In 2026 the pressure arrives from four directions at once. NIS2 has pulled thousands of mid-size companies into scope and made their directors personally accountable. DORA asks financial entities and their ICT providers to evidence resilience contract by contract. The Cyber Resilience Act turns security into a condition of market access for anything with digital elements. The AI Act sets obligations for organisations that merely use an AI system, not only those that build one.

At the same time, the attack surface has moved. Cloud adoption put critical systems outside the perimeter. Generative AI put company data into tools nobody approved. Supply chains turned every supplier into a possible entry point.

The companies caught in the middle — fifty to two thousand people — rarely have a compliance team. They have an IT manager with a full plate, a CFO watching the budget, and a board that has just discovered it is accountable. The large consulting firms will quote them a programme they cannot afford, staffed by consultants who learned the framework last quarter.

03

The method

We built Sectius for exactly that gap. One senior partner who stays on the engagement from first call to final readout. Seven practices — AI and cybersecurity, managed security, offensive security, cloud and DevSecOps, governance and compliance, strategy, training — held by the same people, because the gaps between practices are where findings and incidents live.

Underneath, a unified control framework. NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act ask overlapping questions in different words. We map them once, so a control is implemented once, evidenced once, and reused in every audit that asks for it.

And security built into the delivery pipeline rather than reported on top of it. A finding in a pull request costs an hour. The same finding in an audit report costs a quarter.

04

The proof

Eighty per cent of our catalogue is sold at a fixed price, with the deliverables written down before you commit. Our packs carry names, timelines and price bands, published on this site rather than revealed after a discovery phase.

Our engagement model has six steps and a weekly thirty-minute checkpoint. You always know what has been done, what is next, and whether we are on schedule.

05

The relationship

Compliance is not a project that ends. A certificate has to be maintained, a register kept current, an AI system re-reviewed when it changes. So we are built around recurring services — vCISO, Compliance-as-a-Service, Managed DevSecOps — rather than around one-off missions that leave a report behind and nobody to maintain it.

A pack is usually the way in. What follows is a relationship.

The founder

Founder nameFounder and principal consultant

Sectius was founded by a cybersecurity and compliance specialist with senior experience across regulatory compliance, data security, artificial intelligence, software platforms and cloud infrastructure. Based in France, working across Europe, French-speaking Africa and South America.

The choice to stay small is deliberate. It means the person who scopes your engagement is the person who delivers it, and the person who presents it to your board. It also means we say no to work we cannot do well, and bring in a partner when a mission needs a qualification or a jurisdiction we do not hold ourselves.

Photograph to be supplied before launch.

The partner network

Multi-jurisdiction coverage through partners who practise locally and are vetted before they touch an engagement. We remain your single point of contact and stay accountable for the result.

A generated model manifold: a graph of nodes and edges in three dimensions, the near layer sharp and the far layer dissolving.
Europe
France, Belgium, Luxembourg, Switzerland, Spain, Germany, Portugal, Italy
Qualified testing and incident response teams, certification bodies, and counsel for national transpositions of NIS2.
French-speaking Africa
Tunisia, Morocco, Senegal, Ivory Coast, Cameroon
Local data protection law, national cybersecurity agencies, and support for subsidiaries of European groups.
South America
Brazil, Argentina, Colombia, Chile
LGPD and national privacy regimes, local hosting requirements, and audit support in Spanish and Portuguese.

Our commitments

Five things we put in the contract, not on a slide.

  1. Confidentiality

    A mutual non-disclosure agreement is signed before any technical detail is exchanged, and it survives the end of the engagement. Findings are never reused as case studies without written permission.

  2. Professional liability insurance

    We carry professional indemnity cover that explicitly includes cyber liability. Certificates are provided with the framework contract.

  3. Vendor independence

    We take no commission, rebate or referral fee from any vendor or partner. When we recommend a tool, it is because it fits your case. Our partner arrangements are disclosed in writing.

  4. Mission data hosted in the EU

    Documents, evidence and findings related to your engagement are stored on infrastructure located in the European Union, under our control, and returned or destroyed at the end of the engagement on your instruction.

  5. Retest included

    Every technical audit includes a retest after remediation, at no additional cost. A finding you have fixed should be closed with evidence, not left open until the next budget cycle.

Start with a conversation

Forty-five minutes, free, and specific to your situation.