Veyan
Veyan is a French cybersecurity consulting firm founded in 2017 that provides governance, risk management, crisis response, and compliance (RGPD, ISO27k, HDS, EBIOS RM) services to PME/ETI and public organisations in the Grand Ouest region of France.
- Company typePrivate
- Founded2017
- HeadquartersGuidel-plage, France
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Veyan does
Veyan SAS is a privately held French cybersecurity consulting firm founded in 2017 in Guidel, Morbihan (Brittany), by Pierre Bogenschütz and Hervé Degroot. The firm specialises in cybersecurity governance, risk management, crisis response, and regulatory compliance for organisations, operating through three offices in the Grand Ouest region (Guidel headquarters, Saint-Herblain/Nantes, and Vannes at the PIBS innovation park). Its service portfolio is organised around six pillars: Gouvernance SSI (on-demand CISO, policy and ISMS definition, ISO27k and HDS compliance), Gestion de crise (crisis exercises, BCP/DRP, incident response), Conformité RGPD (on-demand DPO, CNIL control preparation), Sensibilisation (awareness training, e-learning, phishing simulations, serious games), Analyse de risques (EBIOS RM methodology), and Evaluation de maturité (ISO27001/GSSI assessments, audits, penetration testing). Veyan is also a Bpifrance-accredited expert for the subsidised Diag Cybersécurité diagnostic for SMEs and ETIs, and is listed as a validated ANSSI field partner in the Vipe cyber directory under Crisis Management.
Veyan's core capability is methodological rather than technical: it does not develop proprietary software products but delivers advisory services through a structured continuous-improvement framework (Mesurer, Piloter, Prévenir) and certified frameworks (EBIOS RM, ISO27k, HDS, GSSI). The firm primarily serves private PME/ETI and public-sector organisations in Western France, with disclosed engagements including energy distributor Sorégies and international paper manufacturer SWM International (3,600 employees across 10 factories). Its go-to-market is sales-led and consultancy-driven, relying on direct client contact via website and email, regional event participation (Forum Économique Breton, CyberMois), content marketing via blog and LinkedIn, and a referral network anchored in the Brittany cybersecurity ecosystem (BDI, Vipe, France Cyber Maritime, EDIH, Club EBIOS, Cybermalveillance.gouv.fr).
The business model is professional services revenue from consulting engagements delivered on a project or retainer basis, with no publicly disclosed pricing. Revenue is unstated; registered capital is €50,000 and headcount is reported at 1–10 employees with no external funding rounds disclosed. Veyan bears the "Marque Bretagne" regional label and operates as an independent, founder-controlled SAS with no identified institutional investors.
Veyan firmographics
Firmographics- Name
- Veyan
- Legal name
- Veyan SAS
- Website
- https://veyan.fr
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Veyan is a French cybersecurity consulting firm founded in 2017 that provides governance, risk management, crisis response, and compliance (RGPD, ISO27k, HDS, EBIOS RM) services to PME/ETI and public organisations in the Grand Ouest region of France.
- Ownership category
- akta.pro rank
Veyan industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
- akta.pro secondary industry
- Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ)
Keywords
Where Veyan is headquartered
LocationHeadquarters
- HQ city
- Guidel-plage
- HQ country
- France
- HQ region
- Europe
Offices3 records
Markets served
Veyan business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Infrastructure
Revenue model
- Cybersecurity Consulting Services: Professional services revenue from cybersecurity governance consulting, including RSSI à la demande, governance policy definition, SMSI definition, ISO27k and HDS compliance, crisis management preparation and incident response, GDPR/DPO services, awareness training, EBIOS RM risk analysis, and ISO27001/GSSI maturity assessments. Services are delivered by consultants on a project or retainer basis.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Veyan product offering
Product offeringCore offering
Veyan is a cybersecurity consulting firm that advises organisations on the definition and implementation of tailored cybersecurity roadmaps. Its service portfolio spans cybersecurity governance (on-demand CISO, SMSI/ISMS, ISO27k and HDS compliance), crisis management (preparation, PCA/PRA, incident response), GDPR compliance (on-demand DPO), security awareness training, EBIOS RM risk analysis, and maturity assessments including penetration testing. Services are delivered by consultants on a project or retainer basis to private and public organisations in the Grand Ouest region of France.
Product overview
Veyan is a cybersecurity consulting company offering a portfolio of governance and advisory services. The core offering consists of six main service pillars: Gouvernance SSI (cybersecurity governance with on-demand CISO services, policy definition, and ISO27k/HDS compliance), Gestion de crise (crisis management including BCP/DRP and incident response), Conformité RGPD (GDPR compliance with on-demand DPO services), Sensibilisation (security awareness training including e-learning and serious games), Analyse de risques (risk analysis using EBIOS RM methodology), and Evaluation de maturité (maturity assessment including penetration testing). The company also offers the Bpifrance-subsidized Diag Cybersécurité diagnostic service. Services are delivered through a structured methodology focused on measurement, piloting, and prevention, with a continuous improvement approach.
Differentiator
Problem solved
Functional benefit
Products and services
- Gouvernance SSI Cybersecurity governance service encompassing on-demand CISO (RSSI à la demande), information security policy definition, SMSI (Security Management System) definition, and compliance with ISO27k and HDS standards for organisations that need formal security governance.
- Gestion de crise Crisis management service covering preparation and crisis exercises, business continuity and disaster recovery planning (PCA/PRA), and incident response support for organisations preparing for and recovering from cyberattacks.
- Conformité RGPD GDPR compliance service providing on-demand DPO, initial compliance implementation, ongoing compliance maintenance, and CNIL control exercises for organisations required to meet French and European data protection requirements.
- Sensibilisation Security awareness and training service including training programmes, e-learning modules, workshops, phishing awareness campaigns, and serious games designed to improve organisational cybersecurity culture.
- Analyse de risques Risk analysis service using the EBIOS RM methodology, including definition of the risk perimeter and addressing plan, and business impact assessment to help organisations prioritise and address cyber risk.
- Evaluation de maturité Maturity assessment service measuring ISO27001 or GSSI compliance levels, including best practices audits and penetration testing, to benchmark and progress an organisation's cybersecurity maturity.
- Diag Cybersécurité Bpifrance
Companies that use Veyan
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
Veyan technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
Veyan partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and minor.
- BDI (Bretagne Développement Innovation)coreBDI is the regional development agency for Brittany. Veyan participates in the Brittany cybersecurity ecosystem facilitated by BDI, which promotes the region as a hub for cybersecurity. The partnership supports Veyan's market positioning and ecosystem integration.
- Vipe (Technopole Vannes)coreVipe is one of seven technopoles in Brittany, focused on supporting technology businesses in the Vannes/Gulf of Morbihan area. Veyan is listed in Vipe's cyber directory as a validated ANSSI field partner for consulting and crisis management services. Vipe and Golfe du Morbihan-Vannes-Agglomération co-created the directory to help businesses find qualified cybersecurity contacts.
- EDIH (European Digital Innovation Hub)minorVeyan partners with an EDIH (European Digital Innovation Hub) to provide cybersecurity expertise within the European digital transformation support network for SMEs.
- Club EBIOSminorClub EBIOS is a community of practitioners around the EBIOS Risk Manager methodology (a French ANSSI-endorsed risk analysis method). Veyan uses EBIOS RM in its risk analysis service offerings.
- VenetisminorVenetis is a Brittany-based IT and digital network/organisation. Veyan participates in the Venetis ecosystem for knowledge sharing and collaboration on IT security topics in the region.
- France Cyber MaritimeminorFrance Cyber Maritime is a regional cluster or association focused on cybersecurity in the maritime sector in Brittany. Veyan's partnership extends its reach into maritime-sector cybersecurity consulting.
- BpifrancecoreVeyan is an authorised expert (expert habilité) for Bpifrance's Diag Cybersécurité programme, a subsidised cybersecurity diagnostic for SMEs and ETIs. Bpifrance subsidises 32% of the diagnostic cost. This partnership provides Veyan with a structured entry-level service offering and access to Bpifrance's SME client base.
- Cybermalveillance.gouv.frcoreVeyan participates in Cybermalveillance.gouv.fr initiatives, including the annual CyberMois (Cybersecurity Awareness Month) campaign, sharing educational content and promoting national cybersecurity awareness. The partnership enhances Veyan's credibility and reach in the cybersecurity awareness domain.
- NowBrainsminorVeyan co-exhibited with NowBrains at the 6th Forum Économique Breton in Saint-Malo in September 2025, sharing a booth on the Tech Avenue dedicated to digital acculturation and AI.
- FT Bretagne SudminorFT Bretagne Sud is a local business federation or association in Southern Brittany. The partnership likely supports Veyan's local business network and community engagement.
Scale indicators3 records
Recent moves9 records
Expansion highlights7 records
Veyan competitors and assessment
Company assessmentBroad incumbents
- Wavestone: Wavestone is a leading French-origin consulting firm with a dedicated cybersecurity, risk and compliance practice offering RSSI-as-a-service, GRC and cyber-resilience advisory. It is a comparable competitor for mid-market and large accounts in France, although it operates at significantly greater scale and breadth than Veyan.
- Devoteam: Devoteam is a European IT and digital transformation consultancy with a sizeable cybersecurity practice covering GRC, cloud security and identity. It competes with Veyan for governance and cyber-transformation engagements with French mid-market and enterprise clients, though its portfolio is much broader.
- Orange Cyberdefense: Orange Cyberdefense is the dedicated cybersecurity arm of Orange and one of the largest MSSPs in Europe, offering GRC advisory, threat intelligence, MDR and consulting. It overlaps with Veyan on governance/RSSI-as-a-service and compliance work, especially for French organizations with regional footprints.
- Capgemini Engineering (cybersecurity practice): Capgemini is a global IT services group with a substantial cybersecurity and risk consulting practice serving French and European enterprises. It is an incumbent competitor for large GRC and cyber-transformation mandates that Veyan could otherwise grow into.
- Sopra Steria: Sopra Steria is a major European IT services group with a cybersecurity and digital trust practice that competes for governance, RGPD and cyber-resilience mandates at French mid-market and large-enterprise clients.
Direct peers
- Synacktiv: Synacktiv is an independent French cybersecurity consulting firm specializing in offensive security, incident response and security advisory. It is comparable to Veyan as a French pure-play cyber advisory competing for similar mid-market and enterprise clients, with overlapping crisis-management and risk-assessment offerings.
- Advens: Advens is a French cybersecurity pure-play founded in northern France that delivers GRC, security advisory, SOC and managed security services. It is directly comparable to Veyan in offering governance/GRC and risk advisory work to French organizations, but at substantially larger scale and with technical/managed services layered on top.
- Harmonie Technologie: Harmonie Technologie is a French cybersecurity pure-play delivering GRC, audit, pentest, SOC and managed security services to mid-market and enterprise clients. It overlaps with Veyan on governance, risk analysis and compliance engagements in France.
- Almond (Sopra Steria Cybersecurity): Almond is a French cybersecurity and digital trust consultancy (now part of Sopra Steria) that offers GRC, identity, cloud security and managed security services. It is a directly comparable French cyber advisory peer, larger in scale and now backed by Sopra Steria.
Emerging players
- CEIS (Groupe CEIS): CEIS is a French risk-management and cybersecurity consulting firm active in GRC, EBIOS-style risk analysis and security advisory for public and private organizations. It is comparable to Veyan as a French specialist cyber/risk advisory, though with stronger public-sector exposure.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Veyan social profiles
Digital presenceVeyan compliance and trust
Trust signalCompliance5 records
Veyan financial estimates
Financial estimateRevenue estimate
Valuation estimate
Veyan leadership team
Management profileNumber of profiles
Profiles3 records
Veyan funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Veyan M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Veyan
What does Veyan do?
Veyan is a cybersecurity consulting firm that advises organisations on the definition and implementation of tailored cybersecurity roadmaps. Its service portfolio spans cybersecurity governance (on-demand CISO, SMSI/ISMS, ISO27k and HDS compliance), crisis management (preparation, PCA/PRA, incident response), GDPR compliance (on-demand DPO), security awareness training, EBIOS RM risk analysis, and maturity assessments including penetration testing. Services are delivered by consultants on a project or retainer basis to private and public organisations in the Grand Ouest region of France.
Is Veyan a public or private company?
Veyan is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Veyan founded?
Veyan was founded in 2017. It employs 1 to 10 people.
Where is Veyan based?
Veyan is headquartered in Guidel-plage, France, in the Europe region.
How does Veyan make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Veyan's main competitors?
Broad incumbents on record are Wavestone, Devoteam, Orange Cyberdefense, Capgemini Engineering (cybersecurity practice) and Sopra Steria. Direct peers are Synacktiv, Advens, Harmonie Technologie and Almond (Sopra Steria Cybersecurity). CEIS (Groupe CEIS) is listed as an emerging player.
Does Veyan have an API?
No public API is recorded for Veyan.
What industry is Veyan in?
Veyan's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC), with a secondary code of BPAEADAJ, Governance, Risk & Compliance (GRC) Managed Services. Its NAICS code is 54151 and its SIC code is 8742.