(DT15) (INCYBER) [RETEX SDIS 77] Comment sécuriser ses accès à privilèges sans complexité ?

(DT15) (INCYBER) [RETEX SDIS 77] Comment sécuriser ses accès à privilèges sans complexité ?

🎙 INCYBER 👥 7K 📅 April 12, 2026 ⏱ 27 min 👁 47 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

PAMbastionaccess controlMFAaudit

Summary

The video features a discussion between an INCYBER host and Stéphane, the RSI (Responsable de la Sécurité des Systèmes d’Information) of SDIS 77, a French fire and rescue service. They discuss the challenges of managing privileged access for external contractors and the implementation of a bastion solution called Provit, developed by Rubica. Stéphane describes the context: a large organization with 76 buildings, 4800 agents, and a complex IT infrastructure. The need for a bastion arose from the lack of visibility and control over external contractors’ actions. The bastion provides a single entry point for privileged access, with features like protocol break, access control, time-based filters, MFA, a credential vault, and session recording. They highlight criteria for selecting a solution: interoperability, ergonomics, vulnerability management, and support. The vendor, Rubica, emphasizes its French sovereignty, CSPN certification, and all-in-one VM deployment. A live demo shows how an external user authenticates with a passkey and accesses resources via RDP, with session recording and real-time monitoring. Stéphane shares his experience with a POC and the rollout, including plans to extend usage to internal administrators. Key benefits mentioned are simplicity, passkey-based MFA, responsive support, and regular product updates. The video concludes with a mention of the Data Breach Investigations Report highlighting internal human errors as a significant risk.

212 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable practical insights into the implementation of a PAM solution in a real-world public sector organization. The argumentation is based on the customer’s direct experience, which adds credibility. The vendor’s presentation is clear and structured, covering technical features and business benefits. However, the content is promotional, and the argumentation is one-sided, lacking independent evaluation or comparison with alternative solutions. The claims about the product’s effectiveness are supported by the customer’s testimony and certifications, but not by independent benchmarks.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The video is a vendor presentation, so sources are limited to the vendor’s claims and the customer’s testimonial. The title accurately reflects the content. The description includes links to the INCYBER forum website and LinkedIn, but no specific references to studies or reports. The mention of the Data Breach Investigations Report is anecdotal and not detailed. The video does not provide citations for the statistics mentioned (e.g., 80% of cyberattacks exploiting privileged accounts). The adequacy between title and content is good.

182 words

Title / Content Match

The title accurately reflects the content: a feedback session on securing privileged access without complexity, featuring a real-world case study.

Quality & Reliability

7/10

The video is a vendor presentation combined with a customer testimonial. It provides practical insights into privileged access management implementation, but is promotional in nature. Claims are supported by the customer's experience and product certifications, but independent verification is lacking.

Key Moments

Cited Sources

Concurring Sources

  • ANSSI recommendations on privileged access — The video mentions ANSSI guidelines for secure administration, which align with the need for a bastion.

Contribution & Novelties

The video provides a practical case study of implementing a PAM solution in a public sector organization, highlighting the importance of user acceptance and the use of passkeys for MFA. It also emphasizes the need to extend privileged access management to internal users, not just external contractors.

Pour aller plus loin :

  • Privileged Access Management (PAM) — Overview of PAM concepts and best practices.
  • FIDO2 and WebAuthn — Explanation of the passkey technology used in the demo.
  • ANSSI recommendations on privileged access — French cybersecurity agency’s guidelines on securing privileged accounts.

91 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and technical level, reflecting the video's practical focus. The lower score in information quality and reliability is due to the promotional nature of the content.

Reliability 6/10