Gartner — Post-quantum readiness

Access the report

Help center

Frequently asked questions

Everything you need to know about NEVERHACK, PROMETHEUS AI, our CERT crisis response service, and our approach to data sovereignty.

Getting started

4 questions
What is NEVERHACK?

NEVERHACK is a global cybersecurity group delivering a 360° approach to cyber risk management. Built on 40+ years of expertise — since Silicom was founded in 1983 — the group covers the full security lifecycle: strategic advisory, training, managed security operations, technology integration, AI, and emergency response. With 980+ experts across 13 countries, NEVERHACK is a Cyber Defence Partner for Digital Sovereignty.

What can I do on this website?

The NEVERHACK website lets you: explore our 9 cybersecurity delivery lines and services, interact with PROMETHEUS — our sovereign AI advisor — to get tailored security guidance, trigger an emergency CERT intervention in case of a cyberattack, browse our vendor ecosystem of 50+ certified technology partners, and access our knowledge base, legal documentation, and compliance resources.

Do I need an account to use the site?

Most content is accessible without an account. However, to use PROMETHEUS AI you need to register — a free account gives you 2 PROMETHEUS requests per month. Creating an account is free and takes less than a minute.

Does NEVERHACK operate in my country?

NEVERHACK has physical operations in France (HQ), Italy, Spain, Belgium, Estonia, Portugal, Canada, Mexico, the United States, Morocco, Oman, UAE, and Singapore. We can engage internationally beyond these locations — contact us to discuss your specific geography.

PROMETHEUS AI

7 questions
What is PROMETHEUS?

PROMETHEUS is NEVERHACK's sovereign AI advisory engine, purpose-built for cybersecurity. It analyzes your security challenges and returns a structured response covering: context understanding, risk analysis, recommended architecture, NEVERHACK capability mapping, and an implementation roadmap. It runs entirely on sovereign French infrastructure — no data is sent to third-party AI providers.

How do I use PROMETHEUS?

Once logged in, navigate to the Cyber AI page and type your cybersecurity question or challenge in the PROMETHEUS input (minimum 10 characters). Be as specific as possible — describe your environment, your concern, or the incident you're facing. PROMETHEUS will generate a structured advisory response within seconds.

What kind of questions can I ask PROMETHEUS?

PROMETHEUS is designed for cybersecurity topics. Good examples include: 'What are the key risks of deploying AI in a healthcare environment?', 'How do I build a Zero Trust architecture for a hybrid cloud?', 'We've detected lateral movement on our network — what should we do?', 'What framework should we follow for ISO 27001 certification?'. The more context you provide, the more precise the response.

How many requests can I make for free?

Every registered account includes 2 free PROMETHEUS requests per month. Additional requests can be purchased as token packs — visit the Tokens page once logged in to see available plans.

Is my data safe? Can PROMETHEUS access my confidential information?

Your data is never retained. All PROMETHEUS requests are processed in memory and discarded after the response is generated — nothing is logged, stored, or used to train AI models. The infrastructure is 100% sovereign, hosted in France, and aligned with ANSSI and SecNumCloud requirements. PROMETHEUS is designed to be compatible with sensitive and government-grade environments.

Can I use PROMETHEUS for classified or restricted environments?

PROMETHEUS runs on fully isolated French sovereign GPU infrastructure with no dependency on external AI platforms (OpenAI, Azure, Google, etc.). This makes it compatible with environments requiring strict data sovereignty. If your organisation has specific classification requirements, contact us to discuss a dedicated deployment.

What is the difference between PROMETHEUS and other AI tools like ChatGPT?

Three key differences: (1) Sovereignty — your data never leaves French infrastructure and is never used for training, unlike commercial AI tools. (2) Specialisation — PROMETHEUS is trained and tuned for cybersecurity, not general-purpose tasks. (3) Governance — every query is logged in your account's audit trail, with RBAC controls and human oversight, making it suitable for professional and regulated use.

CERT — Crisis Response

8 questions
What is the NEVERHACK CERT?

The NEVERHACK CERT (Computer Emergency Response Team) is a certified CSIRT available 24/7/365. It handles all types of cyber incidents — from ransomware and data breaches to network intrusions, DDoS attacks, and insider threats. Our team is deployed with a guaranteed SLA of under 2 hours from incident activation.

What types of incidents does the CERT handle?

The CERT covers: Ransomware & extortion (isolation, decryption analysis, negotiation support), Data breaches (containment, forensic analysis, regulatory notification), Network intrusions (lateral movement detection, APT eradication), DDoS & sabotage (traffic mitigation, ISP coordination), Phishing & social engineering, Insider threats, and any other cyber incident.

How do I activate a CERT intervention?

Go to the CERT page on this website and fill in the incident form: your company name, contact details, incident type, urgency level, and a brief description. Once you confirm the intervention via secure payment, our team is alerted immediately and will contact you within minutes. You'll also receive a confirmation email.

How quickly will the CERT team respond?

Our deployment SLA is under 2 hours from activation. In practice, you'll be contacted by a senior CERT analyst within minutes of payment confirmation. The team is operational 24 hours a day, 365 days a year — including weekends and public holidays.

What does the intervention fee cover?

The initial fee (€500) covers the first 2-hour emergency response — incident triage, immediate containment guidance, and team mobilisation. Additional hours beyond the initial response are billed separately based on the complexity and duration of the incident. All costs are agreed with you transparently before any extended work begins.

What urgency level should I select?

Choose your urgency based on impact: Critical — systems are down or actively encrypted (ransomware, total outage). High — an active attack is in progress but systems are still partially operational. Medium — you've detected suspicious activity or indicators of compromise but there is no confirmed active attack. When in doubt, select Critical — we'll triage accordingly.

What standards does the CERT operate under?

The NEVERHACK CERT operates under ISO 27035 (incident management), NIST 800-61 (incident response), ISO 22301 (business continuity), and ISO 27037/41/42 (digital evidence preservation and forensics). Our team is composed of certified forensic analysts and incident responders.

Can I get a post-incident report?

Yes. Following every intervention, the CERT produces a structured incident report covering the timeline of events, root cause analysis, evidence collected, remediation actions taken, and recommendations to prevent recurrence. This report can be used for regulatory notification (GDPR, NIS2) and cyber insurance claims.

Services & offers

6 questions
What are NEVERHACK's main service areas?

NEVERHACK operates across 9 cybersecurity delivery lines: (1) Cyber Advisory & GRC, (2) Cyber Training & Awareness, (3) Identity & Data Security, (4) Electronic Warfare & Secure Systems, (5) SOC / MSSP — 24/7 monitoring, (6) CERT — Emergency Response, (7) Sovereign Cyber AI, (8) Cyber OT Security, (9) Offensive Security. These are delivered through Professional Services, Managed Security (MSSP), and Technology Resale (VAR).

Do you offer 24/7 managed security services?

Yes. Our SOC / MSSP service provides 24/7/365 monitoring, threat detection, and incident response across IT, OT, and cloud environments. With a Mean Time to Detect (MTTD) under 15 minutes and a dedicated team of 200+ security analysts, we operate as a seamless extension of your internal security team.

What is the VAR service and how does it work?

VAR (Value Added Reseller) means we source, integrate, and operate best-in-class cybersecurity technologies from 50+ certified vendors — covering Endpoint/XDR, Network Security, Identity & Access, SIEM/SOAR, Cloud Security, and AI. Unlike a simple reseller, we provide certified integration by our architects and can operate the full stack as a managed service.

Which industries do you serve?

NEVERHACK specialises in sectors with high security requirements: Government & Defence, Critical Infrastructure, Energy & Utilities, Aerospace, Finance & Banking, Healthcare, Industrial & OT, and Transportation. Our experience in sensitive and regulated environments means we understand the specific constraints of each sector.

Do you handle industrial and OT security?

Yes. Our Cyber OT team of 80+ specialists focuses on industrial cybersecurity — OT assessments, segmentation, ICS/SCADA protection, and OT/SOC monitoring. We follow IEC 62443, NIST 800-82, and ISO 27001 and operate without disrupting production environments.

Can NEVERHACK help with regulatory compliance (NIS2, DORA, ISO 27001)?

Yes. Our Cyber Advisory & GRC team covers 12+ regulatory frameworks including ISO 27001/27002, ISO 27005, ISO 31000, ISO 22301, NIST CSF, NIST 800-53, and emerging frameworks like AI governance under ISO 42001. We run maturity assessments, design security architectures, and accompany you through certification processes.

Cyber insurance

8 questions
What is cyber insurance?

Cyber insurance is a financial protection mechanism that covers your organisation against the economic consequences of a cyberattack or data breach. It can cover: costs of incident response and forensic investigation, business interruption losses, regulatory fines (GDPR, NIS2), ransom payments, reputational crisis management, and third-party liability. It complements — but does not replace — your technical security controls.

What does NEVERHACK's cyber insurance offering cover?

NEVERHACK partners with leading cyber insurance underwriters to offer tailored coverage packages. Depending on your profile, coverage typically includes: 24/7 CERT incident response activation (integrated with our CERT service), forensic investigation costs, data recovery expenses, business interruption for the duration of the incident, extortion and ransomware payments (where legally permitted), and regulatory notification support. Coverage limits and terms are customised based on your sector, size, and risk profile.

How is NEVERHACK's cyber insurance different from a standard policy?

Unlike a standalone insurance product, NEVERHACK's offering is fully integrated with our operational security services. When you hold a NEVERHACK cyber insurance policy, a cyber incident automatically triggers our CERT team — no need to call multiple parties. The same team that investigates the incident also handles documentation for the claim, reducing settlement time and ensuring technical accuracy of the loss assessment.

How do I get a quote?

To receive a cyber insurance proposal, contact us via the Contact form on this site or reach out to your NEVERHACK account manager. We will schedule a brief risk qualification session (30–45 minutes) covering your sector, infrastructure, current security posture, regulatory obligations, and desired coverage limits. A tailored proposal is typically delivered within 5 business days.

What is the relationship between cyber insurance and the CERT?

Our CERT and cyber insurance are designed to work together. If you hold a NEVERHACK cyber insurance policy and experience a covered incident, the CERT intervention fee may be covered by your policy from the first hour. The CERT team also produces the incident documentation (timeline, root cause analysis, loss evidence) required to substantiate an insurance claim — eliminating the friction between technical responders and your insurer.

What conditions or exclusions should I be aware of?

Cyber insurance policies typically exclude incidents caused by: known vulnerabilities that were unpatched beyond a reasonable period, intentional acts or gross negligence by the insured, war or state-sponsored cyberattacks (nation-state exclusions vary by policy), and prior incidents not disclosed at underwriting. NEVERHACK helps clients understand their coverage boundaries and recommends security controls that both reduce risk and maintain insurability.

Does a NEVERHACK security engagement improve my insurability?

Yes. Insurers increasingly factor in your demonstrated security posture when calculating premiums and coverage limits. Clients who hold a NEVERHACK SOC / MSSP contract, have completed a CERT retainer, or have performed a formal risk assessment typically qualify for more favourable terms. We can provide insurers with security attestation documentation on your behalf.

Does NEVERHACK help with the claims process?

Yes. NEVERHACK acts as a technical expert throughout the claims process — not just during the incident. We provide: incident timeline and forensic report, evidence of losses (downtime logs, recovery costs), a post-incident remediation plan, and expert testimony if required by the insurer. Our goal is to ensure technically accurate claims, faster settlement, and fair compensation.

Data & sovereignty

4 questions
Where is my data hosted?

All NEVERHACK services — including PROMETHEUS AI inference — run on French sovereign infrastructure. No data transits through or is stored by third-party cloud providers (AWS, Azure, Google Cloud, OpenAI). This ensures full compliance with French and European data sovereignty requirements.

Does NEVERHACK comply with GDPR?

Yes. NEVERHACK is GDPR-compliant. Data collected through the website (account registration, CERT forms, PROMETHEUS queries) is processed according to our Privacy Policy, with no third-party sharing for commercial purposes. All data processing is documented and subject to your rights of access, correction, and deletion.

Is NEVERHACK suitable for government or sensitive sector clients?

Yes. NEVERHACK has decades of experience with government institutions, defence contractors, and critical infrastructure operators across Europe. Our infrastructure is aligned with ANSSI (French national cybersecurity agency) requirements, and our AI platform is designed to be compatible with SecNumCloud-grade environments.

What certifications does NEVERHACK hold?

NEVERHACK and its entities hold a range of certifications depending on the service and country. This includes ISO 27001 certification, qualified CSIRT status, and sector-specific accreditations. Visit our Certifications page for a full and up-to-date list.

Ask the AI

Open PROMETHEUS
in seconds

Get an instant AI-powered analysis of your cybersecurity challenge — sovereign, French-hosted, defence-grade.

Open PROMETHEUS
CERT — 24/7

Activate the CERT
in under 2 hours

Under attack? Our certified CSIRT deploys 24/7/365. Ransomware, breaches, DDoS — incident response in minutes.

Activate CERT
Catalogue

Explore the
full offers map

Nine delivery lines across MSSP, advisory, training, AI, and emergency response. Find the right engagement model.

View all offers