ESHAY ADVISORY
An Eshay Advisory team briefing an executive committee

Home  /  Firm

About us

Cybersecurity advisory built
for real-world complexity.

A senior team that has sat on both sides of the table — inside organisations under pressure, and across from them as advisors.

Our story

We started because the two halves of the job had stopped talking.

Our founders came from both sides. Some ran security inside organisations under real pressure — regulated data, legacy systems, business constraints and boards demanding answers. Others sat across the table as advisors, delivering recommendations that were technically correct but often impossible to implement.

Not because they were wrong, but because they didn't fit the organisation. The right tools weren't available. Existing systems couldn't support them. Budgets, priorities or regulatory requirements made them unrealistic.

We believed advice should work in the real world.

That's why we start by understanding the organisation, not just the problem. We find the right solution where it exists, adapt it where necessary, and build it when it doesn't.

Eshay Advisory exists to bridge strategy and execution — because recommendations only create value when they can be put into practice.

Two senior advisors working through a risk assessment with a client
Positioning

Between the boardroom and the build.

Consultancies produce strategy that engineering cannot implement. Technical firms produce findings that a board cannot act on. Eshay Advisory exists in the space between the two.

We are structured deliberately small and senior. The people who scope your engagement are the people who deliver it, and they have run security programs, shipped software and responded to incidents themselves. That is what allows us to move from a risk committee in the morning to a code or architecture review in the afternoon without changing our answer.

Where we are

Two offices, one practice.

Not a headquarters and a branch. The same team, working across both ecosystems, on the same engagements.

Paris puts us inside the regulatory perimeter our clients operate in. GDPR, NIS2 and DORA are not abstractions read from a summary — they are the frame our French and European engagements are scoped against, in the same timezone as the authorities that enforce them.

Jerusalem puts us inside one of the densest cybersecurity ecosystems in the world — where security research, detection engineering and product innovation move faster than the literature describing them.

The combination is the point. European governance discipline on one side, deep technical expertise and engineering on the other, with no handover between the two.

ISRAEL

Jerusalem

Gan HaTechnologia (Malha)
1 Agoudat Sport Hapoal
Jerusalem
+972 52 389 26 56

What guides us

Four commitments.

These are the commitments we would want from an advisor, so they are the ones we hold ourselves to.

CLARITY

Plain answers

We write so that a board and an engineer reach the same conclusion. No severity inflation, no marketing vocabulary, no finding dressed up to justify the invoice.

DEPTH

Real technical ground

Recommendations are tested against the systems that must implement them, in the environment you actually run — not against a reference architecture nobody has.

DISCRETION

Quiet by default

We work under NDA, we do not publish client names without written consent, and we never use an incident we handled as marketing material.

EXECUTION

Finished work

An engagement ends when the control is in place and verified. Not when the report is delivered, and not when the invoice is paid.

Where we say no

The work we decline.

A firm is defined at least as much by what it turns down. These are ours, stated before an engagement rather than discovered during one.

Assessments designed to pass

If the objective is a certificate rather than a safer organisation, we are the wrong firm. We will say so at the first meeting rather than the last.

Engagements we cannot staff senior

We would rather turn work down than sell a partner and deliver a junior. If the right person is not available, we say when they will be.

Selling a product into a gap we invented

Our products are declared, and we tell you plainly when a market alternative fits you better. An advisor who only ever recommends their own software is a vendor.

Scopes we consider theatre

A scope that cannot produce meaningful results serves no one. We'll challenge it, reshape it if needed, or politely decline the engagement.

Track record

Described within what our references allow.

Most of our work is covered by non-disclosure agreements. We are happy to arrange direct reference calls under NDA during a selection process — which is worth more than a logo wall anyway.

15+

Years of combined senior security leadership

200+

Assessments, audits and offensive engagements delivered

3

Proprietary products designed and maintained in-house

2

Countries, one practice — France and Israel

Our mission

Turn cyber risk into clear decisions and resilient systems.

Our commitment is to high-impact security work that protects organisations against real threats — and lets them get back to their actual business.

Reports don't reduce risk. Implemented controls do. That's the standard we hold ourselves to, and it is the reason clients keep us past the first engagement.

Careers

We hire for judgement.

Tooling can be taught. Knowing which finding matters to this business, this quarter, cannot.

We look for consultants and engineers who can hold a room of executives and read a pull request in the same week. Three roles are open now, and we read every unsolicited application that shows us real work.

See open positions
An Eshay Advisory analyst at work on a monitoring console

Clear decisions. Stronger controls. Practical execution.

Tell us what you are trying to protect and what is in your way. A senior advisor will answer — not a sales team.