Cheque Cyber / Cyber Vouchers
About this good practice
Two financial assistance vouchers to improve SMEs cybersecurity performance:
- The Cyber Investment Voucher designed to help SMEs implement priority actions with support of up to €10,000.
- The Cyber Diagnostic Check is designed to help SMEs identify priority actions to be with assistance up to €5,000.
SMEs benefit from an in-depth technical diagnosis and a detailed action plan based on 4 key analysis pillars by consultants (PASSI* certified). This diagnosis is run by the. Board of Cyber, a French start-up founded in 2022, specialised in cyber risk management.
The analysis is based on 4 pillars:
1. Map your public assets public assets on the Internet.
2. Assessment of your cyber performance based on your mapping.
3. Perform an audit of your organizational maturity.
4. Assessment of the risk of compromise of your internal information system.
The deliverables are: a summary analysis report including priority areas for improvement / a detailed report on the audit carried out by the consultant / an action plan with recommendations / a 3-year cyber roadmap.
Resources needed
The Region provided €3 million available to support companies in their Cyber approach: from diagnosis to investment.
Evidence of success
Since october 2023, hundred SMEs in the Paris Region have benefited from the region's Cyber Vouchers.
Cyber Diagnosis Voucher after 10 months of practices:
- Applications received 158
- Eligible applications (notified): 102
- Applications rejected: 32
Payment requests
- 17 claims in progress
- 18 claims paid for a total of €85,400
Payment requests and claims should be fast for SMEs.
This enable them to grow with peace of mind and better manage the risks associated with cyber security.
Potential for learning or transfer
The Security Rating data allowed to analyse the main trends and identify recommendations for simple corrective action.
It is recommended to focus on messaging and settings that are easy to configure.
Priority should be given to fixing web vulnerabilities, particularly those related to TLS/SSL, such as correcting certificate errors.
Additionally, it is worth considering upgrading the technologies used on hosting servers and assessing the feasibility of upgrades to programming languages in use.