Paris
8 rue de Berri
75008 Paris
+33 1 80 83 73 78
Home / Firm
About usA senior team that has sat on both sides of the table — inside organisations under pressure, and across from them as advisors.
Our founders came from both sides. Some ran security inside organisations under real pressure — regulated data, legacy systems, business constraints and boards demanding answers. Others sat across the table as advisors, delivering recommendations that were technically correct but often impossible to implement.
Not because they were wrong, but because they didn't fit the organisation. The right tools weren't available. Existing systems couldn't support them. Budgets, priorities or regulatory requirements made them unrealistic.
We believed advice should work in the real world.
That's why we start by understanding the organisation, not just the problem. We find the right solution where it exists, adapt it where necessary, and build it when it doesn't.
Eshay Advisory exists to bridge strategy and execution — because recommendations only create value when they can be put into practice.
Consultancies produce strategy that engineering cannot implement. Technical firms produce findings that a board cannot act on. Eshay Advisory exists in the space between the two.
We are structured deliberately small and senior. The people who scope your engagement are the people who deliver it, and they have run security programs, shipped software and responded to incidents themselves. That is what allows us to move from a risk committee in the morning to a code or architecture review in the afternoon without changing our answer.
Not a headquarters and a branch. The same team, working across both ecosystems, on the same engagements.
Paris puts us inside the regulatory perimeter our clients operate in. GDPR, NIS2 and DORA are not abstractions read from a summary — they are the frame our French and European engagements are scoped against, in the same timezone as the authorities that enforce them.
Jerusalem puts us inside one of the densest cybersecurity ecosystems in the world — where security research, detection engineering and product innovation move faster than the literature describing them.
The combination is the point. European governance discipline on one side, deep technical expertise and engineering on the other, with no handover between the two.
8 rue de Berri
75008 Paris
+33 1 80 83 73 78
Gan HaTechnologia (Malha)
1 Agoudat Sport Hapoal
Jerusalem
+972 52 389 26 56
These are the commitments we would want from an advisor, so they are the ones we hold ourselves to.
We write so that a board and an engineer reach the same conclusion. No severity inflation, no marketing vocabulary, no finding dressed up to justify the invoice.
Recommendations are tested against the systems that must implement them, in the environment you actually run — not against a reference architecture nobody has.
We work under NDA, we do not publish client names without written consent, and we never use an incident we handled as marketing material.
An engagement ends when the control is in place and verified. Not when the report is delivered, and not when the invoice is paid.
A firm is defined at least as much by what it turns down. These are ours, stated before an engagement rather than discovered during one.
If the objective is a certificate rather than a safer organisation, we are the wrong firm. We will say so at the first meeting rather than the last.
We would rather turn work down than sell a partner and deliver a junior. If the right person is not available, we say when they will be.
Our products are declared, and we tell you plainly when a market alternative fits you better. An advisor who only ever recommends their own software is a vendor.
A scope that cannot produce meaningful results serves no one. We'll challenge it, reshape it if needed, or politely decline the engagement.
Most of our work is covered by non-disclosure agreements. We are happy to arrange direct reference calls under NDA during a selection process — which is worth more than a logo wall anyway.
Years of combined senior security leadership
Assessments, audits and offensive engagements delivered
Proprietary products designed and maintained in-house
Countries, one practice — France and Israel
Our commitment is to high-impact security work that protects organisations against real threats — and lets them get back to their actual business.
Reports don't reduce risk. Implemented controls do. That's the standard we hold ourselves to, and it is the reason clients keep us past the first engagement.
Tooling can be taught. Knowing which finding matters to this business, this quarter, cannot.
We look for consultants and engineers who can hold a room of executives and read a pull request in the same week. Three roles are open now, and we read every unsolicited application that shows us real work.
See open positions
Tell us what you are trying to protect and what is in your way. A senior advisor will answer — not a sales team.