Home / Operational security

Anticipate threats, test your teams

CTI, OSINT, phishing simulation — integrated offensive and defensive tools for a proactive security posture.

Monitor threats in real time

Galea includes a CTI engine that automatically correlates emerging threats with your declared assets. You are alerted in real time when a vulnerability or attack campaign directly concerns you.

Contextualised CVE alerts

New CVEs are automatically correlated with the applications declared in your inventory. Alerted only if you are affected.

Dark web monitoring (CTI Pro module)

Detection of leaked credentials, mentions of your company on underground forums, alerts on paste sites.

Premium Threat Intel feeds

Integration of standardised Threat Intelligence feeds: CERT-FR, AlienVault OTX, MISP. Indicators of Compromise (IoCs) correlated with your assets.

Monthly threat reports

Monthly summary of threats relevant to your industry. Trends, active campaigns, tailored recommendations.

CTI — Recent alerts
!
CVE-2026-1234 — Apache Struts Critical — Affects your Finance ERP (Struts 2.5)
Critical
!
APT29 campaign — Microsoft 365 phishing Your Teams email is within the target scope
High
CVE-2026-5678 — OpenSSL Your version is not affected (3.2.1)
OK

Your digital footprint seen by an attacker

Galea's automated OSINT (Open Source Intelligence) continuously scans your Internet exposure. Forgotten subdomains, open services, credentials in data leaks — everything an attacker would find during reconnaissance.

Subdomain & service scan

Automatic discovery of all your subdomains, open ports and services exposed on the Internet.

Leaked credentials detection

Monitoring of breach databases. Alert if emails @yourdomain appear in a leak.

Forum mentions

Monitoring of underground forums, paste sites and Telegram channels to detect mentions of your organisation.

External exposure score

Overall rating of your digital exposure, with monthly trend and industry comparison.

OSINT — Exposure score
B+ Exposure
Subdomains
12
Leaked credentials
3
Open ports
7
Forum mentions
0
P. PHISHIA phishia.fr ↗

Phishing simulation & awareness training

Test your employees' vigilance with realistic phishing campaigns. The results are integrated directly into your Galea risk register.

50+ realistic templates

Microsoft 365, DHL, LinkedIn, HR notifications, password resets. Templates adapted to the European market.

Scoring by team

Open, click and submission rates. Individual and collective progress over 12 months with industry benchmarks.

Automatic awareness training

Employees who click immediately receive a micro-training module. Built-in gamification and progress tracking.

Native GRC integration

Phishia results feed the "awareness" risk in your Galea register. Risk score updated automatically.

PDF campaign report

Executive report with summary, detailed statistics, recommendations and cross-campaign evolution. Ready for your executive committee.

Active Directory import

Import your directory via CSV or connect Azure AD / Google Workspace. Pre-configured groups and teams.

Phishia is available as a Galea module (+€300/month) or standalone at phishia.fr

Assess the security of your suppliers

The supply chain is the weakest link in cybersecurity. NIS2 explicitly requires third-party risk management. Galea automates the assessment and monitoring of your critical subcontractors.

Automated questionnaires

Automatic dispatch of ISO 27001 / NIS2 questionnaires to your suppliers. Scheduled reminders, automatic scoring of responses.

Scoring & classification

Risk score per supplier (A to E). Classification by criticality: strategic, important, standard.

Continuous monitoring

Alerts when one of your suppliers is involved in a security incident. Correlation with CTI feeds.

NIS2 supply chain report

Documentation of your third-party risk management, ready for NIS2 audits and ISO 27001 certifications.

TPRM — Suppliers
A
Sovereign hosting (France) Host — Score 92/100 — Audited on 15/01/2026
Compliant
B
Vendor XYZ Development — Score 67/100 — Awaiting response
Partial
D
External SaaS Analytics — Score 34/100 — NIS2 non-compliant
Risk

Optimise your insurance coverage

Insurers increasingly require detailed information on your security posture. Galea automatically generates underwriting files with all the data your broker needs.

Automatic underwriting file

Cyber maturity report, security measures in place, remediation plan, incident history — all in one PDF.

Residual risk calculation

After risk treatment, Galea calculates your residual risk. A negotiation argument with your insurer.

ROI of security measures

Demonstrate to your management the return on investment of each measure: reduction in annual financial exposure vs. cost of the measure.

SecOps modules — à la carte

CTI
CTI Pro

Dark web, STIX, sector alerts

+€450/month
OSI
Full OSINT

Digital exposure, leaked credentials

+€300/month
PHI
Phishia

Phishing simulation, awareness

+€300/month
TPR
TPRM

Questionnaires, supplier scoring

+€390/month
INS
Cyber insurance

Underwriting files, maturity

+€150/month

All modules are included in the Advanced plan. View full pricing →

Protect your organisation proactively

30-minute demo, no commitment.

Request a demo
Free trial — No credit card

Ready to secure your organisation?

Join the companies that trust Galea to drive their cyber-résilience. 30-minute demo.

Already a customer? Go to the platform