The expertise of a cyber consultancy in a single tool. AI-automated ISO 27005 risk management approach, 8 compliance frameworks, a sovereign platform hosted in France.
Galea integrates a cyber-specialist European sovereign AI engine that automates the ISO 27005 risk management approach, generates contextual risk scenarios and maintains ISO 27005 methodological rigour.
3 to 5 ISO 27005 scenarios per asset, with risk sources, attack paths and MITRE ATT&CK techniques
AI suggests an initial score on the 4x4 matrix, the expert revises it with justification. Full traceability
Action plans adapted to the sector and maturity level, classified according to the G·P·D·R model
Annual financial exposure, calculated on modelled attack paths
Audit multiple regulatory and normative frameworks simultaneously. Galea calculates your coverage rate in real time.
Information security management system. The 93 Annex A controls are pre-loaded, with per-domain scoring and Statement of Applicability (SoA) tracking.
European directive on the security of network and information systems. Classification by category (essential/important), 24h early warning, 72h notification obligations, and mandatory cybersecurity measures.
Digital Operational Resilience Act. European regulation on digital operational resilience for the financial sector. Penetration testing, third-party ICT risk management, and incident reporting.
Health Data Hosting and General Data Protection Regulation. Processing register, impact analysis (DPIA), data subject rights tracking, and mandatory HDS certification.
In an uncertain geopolitical context, the location of your risk and compliance data is a strategic issue. Galea guarantees that nothing leaves European territory — neither your data, nor the AI models that analyse it.
Certified European datacenter, ISO 27001 and HDS certified. No transfers to the United States.
Models trained and hosted in Europe. No dependency on OpenAI, Google or Amazon.
Designed for European compliance from day one. Not an adapted US product.
Galea absorbs your environment and challenges, then produces actionable risk scenarios and compliance deliverables — in a fraction of the time of a consulting firm.
Galea is more than software. With our Phishia support service, a team of cybersecurity engineers guides you through your GRC journey: initial audit, configuration, training and quarterly reviews.
A Phishia consultant runs your 5 workshops with you, leveraging Galea's AI
Training sessions: platform usage, cyber best practices, phishing simulation
Review of your posture every 3 months, preparation of reports for management
Initial audit, guided ISO 27005 risk assessment, team training, 4 quarterly reviews, certification preparation, priority support.
Estimate the current cost of your cybersecurity and discover how much you could save.
Start for free, scale as your needs grow.
Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.
Already a customer? Go to the platform