Marc-Frédéric Gomez, thirty years in information technology, more than ten of them spent entirely on cyber defence, incident response and threat intelligence.
I head the CERT of a major financial institution, a round-the-clock team operating internationally. As a SIM3 Auditor certified by the Open CSIRT Foundation, I work with CERT, CSIRT and SOC teams on their maturity. I hold an Executive MBA from the École de Guerre Économique and the PCI Professional certification.
This site is the English counterpart of my French blog. Technical analyses, readings of public advisories and reports, and field notes. Everything published here is my own view and commits no one but me.
Areas of practice
- Threat intelligence. CTI and OSINT as they are actually used inside a CERT: source qualification, bulletin production, indicator sharing, taxonomies and disclosure protocols.
- Incident response. Cyber crisis management, post-compromise investigation, threat hunting, coordination across analysis tiers and with business units.
- Vulnerability management. Vendor advisory analysis, risk-based prioritisation, KEV catalogue tracking, disclosure doctrine.
- Maturity and compliance. SIM3, ISO/IEC 27001, PCI DSS. Running audits and building improvement plans.
- Governance and tooling. Security programme management, selection and integration of open source solutions, MISP, OpenCTI, SIEM and SOAR.
RadioCSIRT
A daily podcast for SOC, CERT and CSIRT teams and for CISOs. Each day, the essentials of the threat landscape filtered through an incident response practitioner’s judgement: what is confirmed, what is not, and what should be handled first. Under ten minutes, seven days a week, on the major audio platforms.
Background
Before moving to the financial sector, I founded and ran several companies, among them Linux Motor, CTN1 and MG Consultants, working on open source support, European hosting, and PCI DSS compliance programmes for large organisations.
Publications and involvement
Co-author of TPE/PME : les oubliés de la cybersécurité, presented at FIC 2024 and an award winner in its category.
President of OpenDFIR, an association I co-founded to support the French-speaking incident response community with tooling, open models, SIM3 audits and field experience.
Co-translator into French of FIRST’s Traffic Light Protocol 2.0.
Member of CESIN, the French club of information and digital security experts.
Regular speaker at conferences, and publishing on LinkedIn, where my full background is listed.
Contact
- LinkedIn: linkedin.com/in/marcfredericgomez
- Podcast: www.radiocsirt.org
- French blog: blog.marcfredericgomez.fr



