Replay
Webinar · 22 Sep
Skip to content
Back to resources
Case studySeptember 22, 2026

Oney: from the monthly snapshot to daily tracking

Case study: banking group Oney consolidates its IT and cyber tools in OverView to track its posture daily, quantify its blind spots and prove its controls.

Recorded in French, with French captions. Playing loads the YouTube player, which sets its own cookies. Also available on YouTube.

Challenges

  • A manual consolidation once a month: half a day of work for a snapshot obsolete by the next day
  • Data sources that were hard to integrate, and therefore a consolidation covering only part of the infrastructure
  • Blind spots the team knew about but could not quantify, and therefore could not turn into an action plan

Solutions

  • Daily consolidation and history of the IT and cyber data coming out of the existing tools
  • Start on a bounded scope: three sources connected, then widen
  • Missing connectors built by OverSOC for the tools outside the catalog

Results

  • Daily tracking rather than a snapshot that ages
  • Blind spots quantified and ranked, turned into an action plan
  • Reliable metrics, with history from the day they are created

Oney, a European banking group present in around ten countries, tracked its security posture by hand: half a day a month to piece five sources together, and a snapshot already out of date the day it was published. Two months after connecting three of those sources in OverView, the cyber team sees its gaps the day they appear, and can quantify its blind spots instead of guessing at them.

This case study comes from the webinar held on 22 September 2026 with Julien Pflieger, Cyber Tech Lead at Oney. The full recording is at the top of the page — it is in French, with French auto-generated captions. The summary is below, in English.

Context

Payments, financing, split payments: Oney is a European banking group, present in around ten countries, serving several million customers. Behind every transaction sit services that cannot be interrupted, cannot escape control, and cannot lose track of what they did.

Julien Pflieger is Cyber Tech Lead for the French scope. He owns the strategy and the technical side of the cyber squads: vulnerability management, access management, protection and detection, cyber IT governance. The infrastructure, a little under 3,000 assets, mixes cloud, legacy and several generations of kit.

The setting
≈ 3,000 assetsCloud and on-premise, several generations of infrastructure
5 data sourcesCloud and on-premise scanners, monitoring, hypervisor, security. Each with its own blind spot
½ day per monthOf manual consolidation, for a snapshot archived once a month

"My day job is answering a question that looks simple: are we protected? Except that Oney is 43 years old, with infrastructure that never stops changing."

Challenges

The team's job is to give a view of cyber risk. The reports Julien Pflieger produces always answer the same two questions: what is our level of protection, and what are the priority actions? To answer them, market-leading tools, both for event detection and for vulnerabilities.

Except that even the best tools leave a blind spot. Cloud scanner, on-premise scanner, monitoring, hypervisor, security tools: the sources were not in disagreement, they were simply looking at different parts of the infrastructure. It had to be pieced together by hand to identify the points of non-compliance.

That piecing together cost half a day a month, for a global consolidation of the posture that Julien Pflieger archived as a snapshot. Two limits followed from it:

A monthly snapshot. Between two consolidations, the team was flying blind. A gap that appeared on the 3rd of the month only became visible three weeks later.

A partial consolidation. Julien Pflieger pieced together what he could piece together. Sources that did not fit the format stayed out.

"The hard question is not 'what do I see'. It is 'what am I not seeing'."

Why OverView

Julien Pflieger came across OverView through a conversation with a CISO he knows at a large French GSS company. The platform answered the need: consolidate the IT and cyber data from the existing tools to produce a unified inventory and security metrics. The pricing made it easy to decide to start on a first scope.

No big bang: Oney preferred to test the approach on a bounded scope, connect the priority sources, check that the data consolidated correctly, then widen. Three expectations tipped the balance:

  1. Keep a daily history. Move from a monthly snapshot to daily tracking, to see gaps when they appear, not three weeks later.
  2. Quantify the blind spots. A global view of the infrastructure, and an action plan drawn from it with the right priorities.
  3. Strengthen the audit trail. In a bank, being compliant is not enough: you have to be able to prove it, with dated data.

Implementation

OverView arrived at the same time as a deep transformation of Oney's cyber setup, which made it useful straight away. Two months after signing, with three sources connected, the first dashboards were validated and were tracking that transformation day after day.

Two teams on deck, cyber and infrastructure, to wire the sources up. The split: Oney's cyber team steers, frames the metrics and builds the reports; the infrastructure team wires the sources into the platform; OverSOC runs the workshops, handles the integrations and builds the missing connectors.

One thing did snag: some tools were not in OverSOC's connector catalog. The vendor built what was needed, and the data flows today.

Before OverViewNowWhat it allows
A monthly snapshot, archivedDaily history of the postureSeeing gaps when they appear
Data sources that were not integratedEvery source consolidated in one placeA base that covers the real infrastructure, not the convenient one
We presented last month's snapshotWe follow the change over timeTracking a deep transformation day after day

Results

What did cross-referencing the sources reveal? Honestly, no surprise, says Julien Pflieger. And that is already a result: the team knew its blind spots. What it did not have was the number. Cross-referencing took it from "we know there are blind spots" to "here they are, here is how many, here is the order we deal with them in". The audit trails came out considerably stronger.

"A blind spot you can name and quantify becomes a line in an action plan. Until it is quantified, it stays a worry."

Creating a new metric shows the change well. Before, you had to contact the team holding the data, agree an export format or API access, and start an integration job — arriving at a fixed, barely modular representation that starts at zero on the day it is created. Now Julien Pflieger builds the metric himself on the consolidated base, without going through anyone else. And because of the history, it also computes over past data: "a new metric no longer starts at zero the day you create it, it already has a curve behind it."

If he had to keep one, it would be the rate of non-compliance with no action plan. Infrastructure is a living thing: Julien Pflieger is wary of anyone showing 100% compliance.

"A non-compliance that is tracked, with a deadline and an owner, is risk you are steering. A non-compliance with no action plan is risk you are taking. The two have nothing in common, and it is the second that has to stay close to zero."

Useful AI starts with something other than AI

AI is the topic of the moment. Julien Pflieger deliberately sets AI governance aside, as a cyber workstream in its own right, and sticks to usage. His conviction fits in one sentence: effective use of AI starts with a reliable data source, clear processes, and defined deliverables and evidence.

What he expects of it: that it works from a consolidated, contextualized, historized base, to produce deliverables framed in advance. Querying the infrastructure in natural language, yes, provided the answer can be verified.

What he does not expect of it: that it will rescue poor-quality data. "It does not correct it: it amplifies it, and gives it a confident tone."

Three conditions for trusting an answer: a reliable, identified source (knowing where each number comes from), the full context (the company's specifics, its processes), and deliverables framed up front (templates, what has to be communicated, the evidence expected).

"OverView is, to me, a very good candidate for the role of reliable data source. That is the point from which AI becomes interesting."

If he were starting over

A data consolidation project is not judged only on the day the connectors land. It is decided in how you start, how you qualify what you collect, and how you work with your vendor. Julien Pflieger draws four lessons from it.

Start with the tag catalog. Write down quickly which tags you want and what they mean, then qualify the sources as you go rather than waiting to have everything. At the time of signing, the exercise was not straightforward. The product has moved on and the OverSOC team has put a lot of work into this.

Start small to decide fast. Oney did not wait until everything was mapped. Three sources, two months, a first validated dashboard: the platform was judged on real data rather than on a demo, and the scope widened afterwards.

Build on what exists rather than replacing it. The tool replaces none of the scanners. It does what none of them does alone: it makes them agree, and it shows the areas nobody was covering.

Support is part of the project. Building connectors for tools outside the catalog does not happen on its own. The two teams moved forward together until the data flowed.

To place your own infrastructure: the metrics simulator lists, from the tools you already run, what OverView could compute by cross-referencing them.


Sources: Oney x OverSOC interview with Julien Pflieger, Cyber Tech Lead at Oney, 31 August 2026, completed by a written questionnaire in September 2026 and by the webinar of 22 September 2026. For sector context, Verizon, Data Breach Investigations Report 2026 reports that 31% of the data breaches analyzed start with the exploitation of software vulnerabilities — a general statistic, across all sectors, which does not concern Oney and does not measure OverView's effectiveness.

Ready to take back control?

Plug in your sources, see for yourself in 14 days. Free access, no commitment, 45-minute setup.

Start for free