Engagements and contexts

Engagements explained in context

These experiences describe the constraints encountered, the work carried out and the outcomes achieved without exposing sensitive architecture.

These markers come from Adrien’s professional experience. They are not presented as a Murillo Consulting client portfolio or as an endorsement by the organizations mentioned.

01

DevSecOps Cloud / defense

Industrialize and secure a private-cloud KaaS platform

Kubernetes-as-a-Service and IaaS/CaaS services in a defense environment.

Situation

Align deployment automation with technical, operational and security requirements without reducing operability.

Intervention

Secured Kubernetes foundations, automated delivery with IaC, CI/CD and GitOps, then integrated scanning, SBOM and CVE tracking.

Outcome

A more reliable delivery chain with traceable security gaps and corrective actions for MCO/MCS and accreditation.

02

Operational security / critical platform

Secure a critical platform with more than 100 VMs

Space and defense environment with availability, continuity, vulnerability and accreditation constraints.

Situation

Keep the platform operational while qualifying CVEs, security gaps and expected hardening actions.

Intervention

Prioritized vulnerabilities, managed MCO/MCS, performed impact analysis and consolidated monitoring and traceability.

Outcome

Qualified gaps, structured remediation plans and consolidated material for the accreditation review.

03

Applied research / CyberRange

Industrialize a KYPO CyberRange for 60 users

Open-source platform for cyber training, attack scenarios and applied research.

Situation

Provide isolated, reusable and measurable training environments across several learning paths.

Intervention

Deployed and automated the environments, then designed scenarios and operational monitoring.

Outcome

A CyberRange used by 60 people, with eight training scenarios and ten environments.

04

Governance / public sector

Turn unclear security framing into actionable priorities

Sensitive systems, risk analysis, security governance and continuity.

Situation

Multiple security topics had no clear treatment order or shared link between risk and action.

Intervention

Ran focused interviews, formalized risks, grouped controls and prepared a concise decision summary.

Outcome

Prioritized controls, clarified responsibilities and indicators ready for operational follow-up.

05

Multi-site organization / operations

Rebuild and secure an information system across six sites

Multi-site organization with more than 50 servers, an operations team and continuity constraints.

Situation

Modernize infrastructure and strengthen security without disrupting the information system.

Intervention

Rebuilt environments, improved access, backups and monitoring, and formalized operations and MCO/MCS procedures.

Outcome

Aligned infrastructure and security practices across six sites with stronger continuity and ownership.

Learn about Murillo Consulting

What these contexts have in common

Value comes from connecting the decision, implementation and the teams’ ability to sustain the trajectory.

01

Start with the decision

The need is framed around a trade-off, a risk or an expected outcome.

02

Work with the teams

CIO, CISO, GRC, business, platform and operations stakeholders remain involved at the right time.

03

Make the trajectory sustainable

Responsibilities, practices and deliverables are designed for ownership after the engagement.

A useful first step

Let’s clarify what needs to move first.

A short conversation is enough to review the context and identify the appropriate next step.

Discuss your needs