Autonomous use
French cybersecurity startup radar 2026 — Wavestone & Bpifrance
Your Microsoft 365does not staysecure without monitoring.
An audit gives you a dated snapshot. We provide the continuity: audit, remediation and permanent monitoring of your Microsoft 365 configuration and email security, with the evidence your insurer, your customers and NIS2 require.
Reply within one business day · No commitment · Data hosted in France
Remediation pending
Trusted by
The problem
An audit is a dated snapshot.
Your configuration keeps moving.
Between two audits, the configuration changes: an administrator adds a rule, a project opens a share, a contractor is granted access. Six months on, the report you commissioned no longer describes your environment.
Today
without monitoring- One audit every 18 months, outdated after three.
- Configuration drift goes unnoticed.
- No evidence to hand your insurer or the customer auditing you.
- Remediation stays in the report, never reaches the tenant.
With SecOps Forces
continuous posture- A permanent picture, not a dated PDF.
- Every sensitive change is detected and qualified.
- Timestamped, exportable, defensible evidence.
- Remediation is applied from the platform, by your teams or by our experts.
Our offering
Two offerings, two engagement models.
The product is the platform. On Microsoft 365 your own teams run it, and involving our experts remains optional. Email security is the exception: we operate it ourselves, because moving to p=reject involves decisions taken with you, over time.
Managed service
Managed email security & DMARC
Additional support
optional, on Microsoft 365
In practice
What the platform covers.
How it works
From scan to continuous monitoring.
The platform already knows what to look at: no discovery phase to scope, the analysis scope is set from the start.
Scan
The platform maps the real configuration of your tenant and domains in 30 to 60 minutes, with no agent to deploy.
Prioritization
Every gap is ranked by level of risk and by remediation effort. You know what must be addressed first and what can wait.
Remediation
Fixes are applied from the platform, in batches, verifying at each step that no legitimate use is interrupted. Implementation rests with your teams or with our experts, depending on the option chosen.
Monitoring
The corrected configuration is watched continuously. Any drift is flagged, qualified and documented.
The platform
Your evidence fits
on one screen.
Posture score, history, compliance by framework, DMARC status for every domain. What you present to your board, your insurer or an auditing customer exports directly from the interface.
Overall security score
Score history
Domains monitored
62Under contract
DMARC status
| Domain | Score | DMARC | Type |
|---|---|---|---|
| secopsforces.com | 95 % | reject | SMTP |
| secopsforces.io | 35 % | monitoring | parked |
Tenant at initial audit — 355 controls run
Interface preview — illustrative data.
Customer story
Six weeks to protect my domain from impersonation.
"The SecOps Forces team secured us in record time. That is half a day a week given back to our business."
Customers
Environments under
significant constraint.
Manufacturing, logistics, textiles, consulting: Microsoft 365 environments of several thousand users, spread across many sites, whose business flows tolerate no interruption.
Customers


Partners & recognition


2026 recognition
Picked out by Wavestone and Bpifrance.
Every year, Wavestone and Bpifrance map the startups that matter in French cybersecurity. SecOps Forces joins the 2026 edition, in the Cloud Security category.
- All in oneEmail, Microsoft 365, phishing and vulnerabilities brought together in a single platform, under one contract.
- Managed + SaaSAutomation handles the volume, our experts make the call. You do not take on another console to administer.
- Built for mid-marketPrioritized recommendations that are then applied, rather than a vulnerability inventory to sort through.
New entrant, 2026 edition
Publications
The latest news.
Solina évolue dans un environnement complexe par nature.
Groupe multi-entités, en croissance externe continue, le périmètre email s'étend à chaque nouvelle acquisition : aujourd'hui, plus de 50 noms de domaines à sécuriser, et ce chiffre continue d'augmenter.
View the postLa sécurité email est, par nature, un sujet opaque.
Les équipes savent qu'il faut s'en préoccuper, mais rarement où elles en sont réellement. Chez Solina Group, ce défi est adressé avec une méthode claire et rigoureuse : organisation irréprochable, tableaux de bord de suivi, plateforme dédiée, reporting régulier.
View the post🚨 Le standard DMARC vient de changer. Après 11 ans.
En mai 2026, l'IETF a publié les RFC 9989, 9990 et 9991 — elles remplacent la RFC 7489 de 2015. Bonne nouvelle d'abord : rien ne casse. Vos enregistrements continuent de fonctionner. Mais si vous gérez un domaine, il y a un peu de ménage à prévoir.
View the post🛡️ On vous donne rendez-vous au SIT Africa !
SecOps Forces sera présent à la 13ᵉ édition du Security IT Day Africa, du 9 au 12 juin 2026 à Marrakech (Palmeraie Rotana Resort). Quatre jours pour échanger sur ce qui compte vraiment en cybersécurité.
View the post🔍 Explorer et analyser SPF, DKIM et DMARC avec KQL dans Microsoft 365
Quand on parle d'email security et de délivrabilité, on a souvent les questions suivantes : est-ce que SPF/DKIM/DMARC passent ? Que deviennent les messages en cas d'échec ? Quels domaines sont les plus concernés ?
View the post🔧 Gestion DNS : l'importance du monitoring des enregistrements SPF, DKIM et DMARC
La suppression ou modification non contrôlée des enregistrements DNS représente un enjeu opérationnel majeur souvent sous-estimé. Conséquences immédiates : délivrabilité email dégradée, vulnérabilité au spoofing, interruption des communications professionnelles.
View the post
Frequently asked
The questions that come up most often.
How long does a Microsoft 365 audit take?
Do we have to buy a support package?
Where is our data hosted?
How is this different from a SOC or an MSSP?
Do we need to be NIS2-compliant before starting?
What size of organization do you work with?
Thirty minutes is enough
to know where you stand.
We review your situation and tell you what is urgent and what can wait. If our offering does not match your need, we will say so.
Live availability · No commitment · Reply within one business day