Cyclad × Hub Forge AI | Credit Agricole
Presentation · Credit Agricole

AI-driven cyber transformation: operational agents inside your IT system

Innovation, sovereignty, control. The complete pipeline from audit to action — deployed within your infrastructure.

DORANIS2GDPR ISO 27001PCI-DSS

// Confidential — Credit Agricole · March 2026

agent-monitor · human governance
SOC agent — SIEM triageRead-only · continuous monitoring ReadOnly
Proposes: isolate host 10.4.2.19DangerFullAccess action detected Intercepted
Validated by the administratorHuman decision · timestamped Approved
Notarized · immutable proofLedger independent of the vendor Sealed
Built for regulated banking environments Zero-Trust On-premise DORA · NIS2 ACPR · ECB
The 2026 context

Cyber transformation: the challenges of a banking group.

Generic AI does not meet the requirements of a banking group — neither in sovereignty, nor in integration, nor in control.

Alert volume

Thousands of daily SIEM alerts. Analysts spend 80% of their time on false positives. The average detection time remains too high.

Regulatory pressure

DORA requires resilience testing, NIS2 imposes notification deadlines. Each framework demands documented evidence — done manually, it is a bottomless pit.

AI = leak risk

Cloud AI tools send your data outside. It is impossible to validate the compliance of a chatbot that transits through a third-party server.

Siloed tools

SIEM, SOAR, ITSM, GRC — each in its own corner. No cross-functional intelligence. Correlations are done manually.

Our response

Agents under your control.

AI agents that understand your business, deployed within your infrastructure, connected to your tools — under human supervision.

1

Audit

Scoring of your processes

2

Correlation

Gaps × available expertise

3

Monitoring

CVE + tools, continuously

4

Agent

Business-specialized

5

MCP

Connected to your tools

6

Action

Under supervision

Every action is logged, auditable, and subject to human validation. Nothing executes without your consent.

Concrete cases

Use cases for your daily operations.

SIEM alert triage

The agent reads your alerts via MCP connector, correlates events, eliminates false positives, enriches IOCs. The analyst receives a dashboard sorted by criticality — not a raw queue.

SOCCyberForge

Regulatory compliance

The CompliForge agent produces DORA and NIS2 gap analyses, generates the missing policies, prepares documented evidence. With a GRC connector: automatic verification within your tools.

DORA / NIS2CompliForge

Incident response

The agent guides evidence collection, builds the timeline, generates the preliminary report. With a SOAR connector: execution of containment playbooks under human validation.

IncidentCyberForge

Entity audit

A standardized framework to assess the cyber maturity of each regional bank. Automatic scoring on 12 axes, detection of critical gaps, remediation plan.

AuditCompliForge

Active Directory hygiene

The agent detects inactive accounts, excessive permissions, dangerous configurations. With an AD connector: automatic scan and periodic report.

ADOpsForge

ACPR permanent controls

The agent generates control sheets, analyzes policy/field gaps, produces compliance dashboards for regulatory reporting.

ControlsCompliForge
COO Cybersecurity scope

Transformation, Innovation, Awareness.

Axes that map directly to your scope.

Industrialize cyber operations

The audit → agent → MCP pipeline turns manual processes into AI-assisted workflows. SOC triage, compliance, entity audits — each process is structured and accelerated without losing human control.

Transformation

Agentic AI — the next step

Beyond the chatbot: agents specialized by domain, enriched by 770+ open source skills, connected to your tools via MCP. This is AI that understands the business, not just the language. A market-leading position.

Innovation

Incident response agents

In a crisis situation, the agent guides the response team: evidence collection, timeline, internal communication, regulatory report. With a SOAR connector: execution of containment playbooks under validation. Reaction time is cut in half.

Crisis management

Shared expertise capital

Skills and playbooks are centralized in the Forges. Every team member accesses the same level of expertise. Juniors ramp up faster. Knowledge is no longer stuck in the head of a single expert.

Awareness

Your team's data/AI background is an asset: Hub Forge AI speaks both languages — data engineering and cybersecurity — within a single ecosystem.

MCP connectors

The agent acts, you stay in control.

Without a connector, the agent advises. With an MCP connector, it acts within your tools — always under supervision.

Advisory mode (default)

  • Guides your teams step by step
  • Proposes commands and configs
  • Generates reports and policies
  • Analyzes what you provide it

Action mode (MCP connector)

  • Reads your SIEM alerts in real time
  • Triages and qualifies automatically
  • Verifies compliance in your GRC
  • Acts under human validation
Read-only by default

Each connector starts in read-only mode. Write actions require explicit activation.

Human validation

Any critical action (closing an alert, changing a config, running a playbook) requires a confirmation.

Complete audit trail

Every call, every parameter, every result is logged. CSV export for your ACPR/ECB obligations.

Granular permissions

Each agent has rights defined per connector. No global access — the principle of least privilege.

Integrations

Connectors for your environment.

ToolConnectorAgentMode
SIEMAlert reading, correlation, enrichmentSOC agent — automated triageRead
SOARPlaybook triggering, trackingIncident response agentRead+Write
ITSM (ServiceNow)Tickets, assignment, trackingSupport agent — diagnosticsRead
GRC (RSA Archer, OneTrust)Registers, controls, evidenceDORA/NIS2 compliance agentRead
Active DirectoryAccounts, groups, permissionsAD audit agentRead
MonitoringMetrics, thresholds, anomaliesSupervision agentRead

Custom engagementEach connector is developed and configured by Cyclad for your specific environment.

Sovereignty

Zero externalized data.

The platform runs within your infrastructure. You can prove it.

VM in your infra

Pre-configured Docker image. Compatible with VMware, Proxmox, Hyper-V. All services isolated in containers.

100% local AI

The AI model runs inside the VM (DeepSeek, Qwen, Llama, Mistral). No prompt ever leaves your network.

Verifiable traffic

The VM is a single point. Your security team can sniff every packet and confirm: nothing leaves.

0
data sent outside
100%
local & auditable
DORA
compliant by design
ACPR
exportable audit trail
Agent Monitor

Total visibility.

Every action of every agent, in real time. Export for your ACPR audits and permanent controls.

Real-time dashboard

Active agents and their status
Actions of the day (read / write)
Success rate per agent
Latest activity + trends
Alerts on anomaly

Audit trail

Every call: date, agent, tool, parameters, result
Filterable by date, agent, action type
Native CSV export (UTF-8 / Excel)
Configurable retention
Compatible with ACPR / ECB obligations

Your security team sees exactly what each agent does, when, on which tool, with which parameters. Nothing is opaque.

Proposed approach

Progressive, controlled, measurable.

We start small and expand based on results.

1

Scoping

Identify your tools and priorities

2

POC

1 agent + 1 connector on a target scope

3

Pilot

Limited team, real-world conditions

4

Measurement

KPIs: time, quality, coverage

5

Rollout

New connectors + teams

Suggested POC: SOC triage

An agent connected read-only to your SIEM. It triages the night's alerts and presents an ordered dashboard to the SOC team in the morning. Zero risk, immediate value, measurable in 2 weeks.

Recommended2 weeks

Alternative POC: DORA compliance

A CompliForge agent loaded with the DORA framework. It produces the gap analysis of your current setup and generates the action plan. No connection to the IT system required — purely document generation.

No IT system accessCompliForge
Cyclad brings

Cyber expertise, MCP connector development, guidance, training, ongoing support.

Hub Forge AI brings

Platform, agent engine, 770+ cyber skills, connector SDK, continuous monitoring, Agent Monitor.

Next step

A 30-minute technical conversation.

To identify the scope of the POC and show you an agent in action.

Week 1

Technical scoping

Weeks 2-4

POC on your SIEM or DORA

Month 2

SOC team pilot

Book the conversation →
Cyclad × Hub Forge AI | Credit Agricole

// Confidential — Credit Agricole · March 2026