Skip to content
Back to about
Author

Thomas Ferreira

Security Engineer

CISSP GCFA GCIH GCFE

CISSP-certified and holding multiple GIAC certifications (GCFA, GCIH, GCFE), Thomas specializes in security incident management and digital forensic analysis. He designs the phishing simulation scenarios and AI analysis engines at nophi.sh, drawing on over a decade of hands-on experience in cyber incident response.

Areas of expertise

Phishing simulation Incident response Digital forensics NIS2 compliance ISO 27001 Social engineering

Professional certifications

CISSP ISC²

Certified Information Systems Security Professional - issued by ISC², the global benchmark in information security.

GCFA GIAC / SANS Institute

GIAC Certified Forensic Analyst - specialization in advanced forensic analysis and incident response.

GCIH GIAC / SANS Institute

GIAC Certified Incident Handler - expertise in security incident management and threat detection.

GCFE GIAC / SANS Institute

GIAC Certified Forensic Examiner - skills in digital investigation and evidence collection.

Published articles

10 French SMEs That Got Hacked: Real Stories That Should Keep You Up at Night

Read article →

Free, SFR, Orange, Bouygues: French Telecom Operators Under Siege from Cyberattacks

Read article →

CEO Fraud and Targeted Phishing: The Most Costly BEC Cases in France

Read article →

The Real Cost of Ransomware in France: Hard Numbers, Case Studies, and Ground-Level Reality

Read article →

Health Data: Why It Is the Number One Hacker Target in France

Read article →

CNIL: The 20 Biggest GDPR Fines in France (and What They Teach Us)

Read article →

Cyberattacks on French Hospitals: An Alarming Track Record (2019-2026)

Read article →

Viamedis and Almerys: 33 Million French Citizens Exposed by a Flaw at Two Health Insurance Processors

Read article →

The 50 Largest Data Breaches in France (2020-2026)

Read article →

France Travail: 43 Million Records Stolen - A Complete Analysis

Read article →

Email security for SMBs: why testing SPF, DKIM and DMARC is urgent

Read article →

How to Trace the Origin of a Suspicious Email Using Headers

Read article →

Why a Simple E-Learning Module Is No Longer Enough to Train Your Teams on Cybersecurity

Read article →

Cybersecurity training vs phishing simulation: what's the difference, and what actually works?

Read article →

Phishing simulation for businesses: a practical 2026 guide

Read article →

Phishing Psychology: Why the Smartest People Still Click

Read article →

Malicious QR Codes, Voice Deepfakes, Trap SMS: New Forms of Phishing in 2026

Read article →

KnowBe4 vs French Solutions: What SMBs Need to Compare

Read article →

How to Choose a Phishing Awareness Solution in 2026

Read article →

Does Your Cyber Insurer Require Proof of Employee Training?

Read article →

Phishing Click Rate: Industry Benchmarks and How to Reduce It

Read article →

What a Cyberattack Really Costs an SMB with 50 Employees

Read article →

Cybersecurity Awareness ROI: How to Convince Your Management

Read article →

Business Phishing: 2026 Statistics, Real-World Examples, and Solutions

Read article →

How to Train Your Employees on Cybersecurity: A Complete Guide for SMBs

Read article →