NIS2 Certified · GDPR Compliant · Hosted in France

Strengthen your teams' cyber resilience

CYMATRIX deploys realistic AI-orchestrated attack simulations to evaluate, train, and durably protect your organization against cyber threats.

MB LC AR

150+ companies trust us to protect their teams

CYMATRIX — Dashboard
Resilience score
84/100
↑ +18 pts this quarter
Phishing click rate
12%
↓ −31% vs baseline
Trained
847
of 912 active
Resilience score progression
84
Recent activityView all →
🎣
Phishing campaign — IT Dept.
247 recipients · Nov 14
Ongoing
📋
Adaptive training — Finance
38 modules · Nov 10
Done
📊
NIS2 Report Q3 2025
Audit-ready · Nov 1
Report
Trusted by
Why CYMATRIX

91% of cyberattacks start with a human error

Technical tools are no longer enough. Your real line of defence is your people — and CYMATRIX helps you strengthen it in a measurable way.

🎯

Ultra-realistic simulations

Scenarios tailored to your sector, processes and employee profiles — not generic templates.

🤖

100% automated orchestration

The AI agent plans, deploys and analyses each campaign without involving your security teams at every step.

📈

Measurable ROI & compliance

Clear CISO and C-suite reports, audit-ready for NIS2 and ISO 27001, with objective progress indicators.

How it works

A turnkey programme,
from setup to report

Operational in 48h, with no additional internal resource required.

1

Context analysis

CYMATRIX analyses your organisation: sector, headcount, tools and risk levels by department to calibrate relevant scenarios.

Detected profile
Sector: Financial services
1,200 employees — 6 sites
Stack: M365, SAP, Salesforce
High risk: Finance, HR, IT
2

Simulation deployment

The AI agent automatically launches campaigns on your schedule: targeted phishing, vishing, internal policy tests.

Active campaign — Week 3
HR Phishing — 340 targets
Executive impersonation — 45 targets
USB baiting test — 3 sites
3

Immediate targeted training

As soon as a risky behaviour is detected, the employee automatically receives a short, contextualised training module.

Module sent — Real time
"Spotting a suspicious email" — 4 min
Interactive quiz — Score 8/10
Certification recorded ✓
4

Reporting & continuous improvement

Real-time dashboards, monthly CISO & C-suite reports, and AI recommendations to optimise the programme over time.

Monthly report — November
Resilience score: 84/100 (+12)
Reporting rate: 67% (+22pts)
NIS2 compliance: 94% ✓
Testimonials

What our clients say

★★★★★

"CYMATRIX transformed our approach. In 6 months, our phishing click rate dropped from 34% to 9%. The results are undeniable."

MB
Marie Blanchard
CISO — Banking group, 8,000 employees
★★★★★

"Full automation let us run regular campaigns without mobilising our IT teams. NIS2 compliance is now documented and provable."

LC
Luc Cavalier
CIO — Industrial group, 3,500 employees
★★★★★

"What won us over was the scenario relevance. Our teams recognise the situations, making training far more impactful than e-learning."

AR
Amélie Renard
CHRO — Consulting firm, 650 employees

Ready to measure and strengthen your cyber resilience?

Join 150+ organisations using CYMATRIX. Personalised demo in 30 minutes.

Use Cases

Simulations tailored to every threat vector

CYMATRIX covers all attack vectors targeting the human factor — from fraudulent emails to physical intrusion — with scenarios calibrated for your sector.

Talk to an expert
Measured client results
Reduction in phishing click rate−74%
Increase in reporting rate+89%
Documented NIS2 compliance96%
🎣
Most common

Phishing simulation

Personalised fraudulent emails based on real organisational data to test employee vigilance against the number-one attack vector.

−74%
Click rate after 3 campaigns
48h
Setup time
  • Emails personalised to your domain and business context
  • Realistic landing pages — zero real data collected
  • Instant training triggered on click
  • Tracking by department, site and seniority level
📞
Growing risk

Vishing & social engineering

Simulation of fraudulent phone calls and manipulation attempts through executive or supplier impersonation.

63%
Average initial compliance
+41pts
After programme
  • Call scripts adapted to your internal processes
  • Identity verification procedure testing
  • Coverage: suppliers, management, IT support
  • Individual and collective reporting
🔒
NIS2 compliance

Incident response testing

Compromise simulation to assess your teams' ability to react, communicate and escalate according to your response procedures.

4 min
Observed avg. MTTD
0 risk
To production
  • SIEM alert and suspicious behaviour simulation
  • Escalation chain and crisis communication testing
  • Backup and recovery procedure evaluation
  • SOC maturity report included
📱
New

Smishing & QR code fraud

Fraudulent SMS campaigns and fake QR codes covering new attack vectors on mobile devices.

More effective than email
BYOD
Compatible
  • SMS mimicking your common suppliers
  • QR codes placed on physical materials in open spaces
  • Mobile vs desktop behaviour analysis
  • Mobile-adapted training modules
🏢
Physical red team

Physical access & baiting

Testing of physical access controls and employee behaviour facing infected media (USB drives, abandoned documents) in your premises.

71%
Plug in the USB drive
Vigilance improvement
  • Coordinated with your physical security team
  • Scenarios adapted to your premises and badge access
  • Zero real risk to systems
  • Individual debrief and recommendations
📅
Recommended

Continuous annual programme

A complete 12-month programme fully managed by AI: planning, progressive difficulty, individual tracking and monthly CISO reporting.

−68%
Phishing-related incidents
1 click
Initial setup
  • Automated 12-month campaign calendar
  • Adaptive difficulty based on each employee's progress
  • Monthly CISO reports + C-suite dashboard
  • Continuous NIS2 / ISO 27001 compliance documentation

Tailored to every sector

CYMATRIX adapts to the regulatory constraints and culture of each industry.

🏦Banking & Insurance
🏥Healthcare & Pharma
Energy & Industry
🏛️Public sector
✈️Transport & Logistics
🛒Retail & Distribution
💼Services & Consulting
🔬Research & Defence

Which use case fits your challenges?

Our experts will help you define the programme best suited to your organisation.

Technology

AI built for enterprise security

CYMATRIX is built on a modern multi-agent architecture, hosted on French sovereign infrastructure, with security by design at every layer.

Hosted in France
GDPR native
Zero production impact
🤖
AI orchestrator agent
Autonomous planning & decision
🔍
OSINT engine
Contextual personalisation
📊
Behavioural analytics
Real-time detection & scoring
🔐
SecNumCloud infrastructure
Sovereign, audited data
Architecture

A modular, secure architecture

Every component is isolated, auditable and designed to never expose your production systems.

Interface
🖥 Web dashboard
📱 Mobile app
🔌 REST API / Webhooks
🔑 SSO / SAML 2.0
AI Agent
🤖 LLM Orchestrator
📅 Campaign scheduler
🧠 Adaptive decision engine
📚 Training generator
Simulation
🎣 Phishing agent
📞 Vishing agent
🔍 OSINT agent
📱 Smishing agent
🏢 Physical red team
Analysis
📊 Behaviour analytics
⚖️ Risk scoring
📄 Report generator
🔗 SIEM connector
Infrastructure
🇫🇷 France hosting (HDS)
🔐 AES-256 encryption
🛡 Zero-Trust Network
📋 Immutable audit logs
Components

The technologies that make the difference

🤖

Multi-agent AI

Specialised agents coordinated by a central orchestrator. Each agent masters a specific attack vector and continuously improves.

Fine-tuned LLMReAct
🔍

OSINT personalisation

Automated collection of public data on your organisation to create realistic lures — without ever storing sensitive data.

Open sourcesGDPR
📈

Behavioural analysis

Predictive models identifying at-risk profiles, vulnerable departments and recurring behaviours to prioritise training actions.

Embedded MLReal-time
🔐

Security by design

All simulations run in isolated sandbox environments. Zero risk to your production systems. End-to-end encryption throughout.

SandboxE2E
📊

Intelligent reporting

Executive and technical dashboards, auto-generated NIS2/ISO 27001 compliance reports, and personalised AI recommendations.

NIS2ISO 27001
🔗

Native integrations

Ready-to-use connectors for the leading SIEMs, HRIS and collaboration tools. Deploy without overhauling your existing infrastructure.

REST APIWebhooks
Integrations

Compatible with your existing ecosystem

CYMATRIX integrates natively with your tools without requiring an infrastructure overhaul.

📧
Microsoft 365
Messaging & IAM
🔍
Google Workspace
Messaging & IAM
📡
Splunk
SIEM
🛡
Microsoft Sentinel
SIEM / XDR
👥
SAP SuccessFactors
HRIS
📚
Workday
HRIS
🎓
Moodle
LMS
📊
Cornerstone
LMS
About

We believe cybersecurity starts with people

Founded in 2022 by experts in offensive security and artificial intelligence, CYMATRIX was born from a simple observation: traditional training is no longer adequate against modern threats.

Our mission

Democratising enterprise-grade cyber simulation

We want every organisation, regardless of size, to access red-team quality attack simulations — automated, measurable and ethical — to durably strengthen its human resilience.

2022
Year founded
150+
Client companies
50K+
Employees trained
12
Experts on the team
The founding team

Experts who have been on both sides

👨‍💼
Truc. Pham
CEO & Co-Founder

15 years in offensive cybersecurity. Former senior pentester at a Tier-1 consultancy. Has guided 80+ CAC40 companies through security maturity programmes.

OSCPCEHCISSP
👨‍💼
Eric. Vu
CTO & Co-Founder

PhD in machine learning (École Polytechnique). Former AI researcher in applied cybersecurity. Architect of our multi-modal agent engine.

PhD MLLLMMulti-agent
👨‍💼
Seb. Carree
CISO & Head of Research

Former CISO of a CAC40 group. Expert in cyber risk management and NIS2 compliance. Guarantor of the platform's ethics and security.

NIS2ISO 27001CISM
Our values

What guides every decision we make

⚖️

Ethics by design

Our simulations are designed to train, never to punish. Every exposed employee receives a supportive, contextualised learning experience.

🛡️

Uncompromising security

No simulation creates real risk. Infrastructure audited annually, hosted in France. Your data never leaves the EU.

🔬

Continuous innovation

Our research team continuously monitors the evolution of attack techniques to keep our simulations aligned with real-world threats.

🤝

Measurable results

We commit to concrete indicators with progress objectives defined with you and transparent tracking of outcomes.

Contact

Let's talk about your awareness programme

Our team responds within 24h to arrange a personalised, free demonstration.

Request a demo

A demo in 30 minutes

We walk you through the platform, answer your questions and define a scenario tailored to your organisation.

📧
Email
ngoctruc.pham@cymatrix.net
📞
Phone
+33 7 77 75 56 33
📍
Address
8 Rue du Viaduc, 94100 Saint-Maur-Des-Fossés
What you get
Demo personalised to your sector
Assessment of your current maturity level
Tailored programme proposal
Response within 24 business hours