Client story

How Sanofi and Wavestone used Claude Code to build a Cyber by Design AI assistant

At a glance  

Combining cybersecurity expertise with Anthropic’s Claude Code to identify and mitigate project cybersecurity risks earlier, faster and more consistently

Client: Sanofi

Challenge: Embedding security into projects relied on numerous internal standards and templates, applied across every phase of the lifecycle. Cybersecurity experts spent significant time explaining the process to project teams and running repetitive reviews rather than focusing on analysis, decision-making and mitigating actual risks.

Solution: Wavestone supported Sanofi in designing and integrating an AI-powered Cyber by Design assistant, leveraging Claude Code, Anthropic’s agentic coding solution, to accelerate development and translate Sanofi’s cybersecurity requirements into an operational solution. The agent analyzes project documentation against Sanofi’s internal standards, to guide teams through the project lifecycle, highlight key security gaps, and automatically generate a structured cybersecurity assessment and action plan.

  •  Up to 70 percent estimated time savings on architecture reviews and feedback preparation
  •  More than 20 internal standards incorporated into the agent
  •  One solution made available to all internal cybersecurity teams

The challenge

Identifying and addressing project cyber risks faster and more consistently

Integrating security into projects requires cybersecurity teams to review a wide variety of documents throughout the project lifecycle. At Sanofi, these assessments draw on numerous internal standards and templates to determine whether project deliverables meet the organization’s security requirements and adequately address the cybersecurity risks introduced by the project.

While essential, this process involved a significant amount of repetitive and time-consuming work. Cybersecurity experts had to navigate several reference materials, identify security gaps, assess their associated risks, and determine the mitigation actions required before project milestones.

Sanofi therefore sought a way to streamline these activities without compromising the quality or consistency of its assessments. The objective was to accelerate document reviews, embed security requirements earlier in the project lifecycle, and enable cybersecurity experts to spend more time identifying and mitigating the risks that matter most.

The approach

Turning internal cybersecurity knowledge into an actionable AI agent

Wavestone supported Sanofi in the design and integration of an AI-powered Cyber by Design assistant. Claude Code, Anthropic’s agentic coding solution, was used as a key development accelerator, helping the team translate functional and cybersecurity requirements into a robust, operational agent while maintaining close control over the solution’s design. A first proof of concept was developed locally before being integrated into an internal Sanofi application, in close collaboration with the teams responsible for the tool. The assistant serves two audiences: project teams, who are guided on what is expected at each phase, supported in assessing project risks and able to consolidate their deliverables before review, and cybersecurity experts, who receive structured, pre-analyzed material.

The agent was built around three core sources of internal knowledge:

  • Cybersecurity standards, used as the cybersecurity control framework
  • Document templates, defining the expected structure and content for each type of deliverable
  • A cyber risk scoring model, providing a consistent basis for rating security posture and prioritizing risks

The assistant supports project teams at every stage of the project lifecycle, from intake through design, build and go-live, to run, by identifying the security requirements applicable to each phase, explaining what is expected, and indicating when cybersecurity involvement is genuinely required.

Rather than replacing cybersecurity expertise, the agent was designed to support it. For every document submitted for review, the solution compares its content with the relevant reference materials, identifies expected information and control points, and automatically prepares the review deliverable.

The resulting output includes:

  • A security posture rating, supported by clear justifications
  • A risk assessment identifying key cybersecurity risks, evaluating their potential business impact and proposing mitigation measures
  • A structured action plan identifying the steps required to mitigate risks and meet security requirements

This approach helps standardize reviews across projects while preserving the role of cybersecurity specialists in interpreting results, challenging findings and making decisions.

The results

Targeting up to 70% faster reviews while addressing cyber risks earlier

While the assistant supports the entire lifecycle, its most significant expected impact is on architecture reviews, where initial estimates point to a reduction of up to 70% in review and feedback preparation time. By automating the initial analysis and completion of the review deliverable, the solution is expected to reduce the burden of repetitive tasks and allow cybersecurity experts to focus more of their time on higher-value risk analysis and decision-making.

The agent incorporates more than 20 internal standards, giving teams a centralized and consistent way to apply Sanofi’s cybersecurity requirements. By systematically mapping project documentation against these standards, it helps identify security gaps earlier, assess their associated risks and define mitigation actions before issues materialize. The agent was made available across Sanofi’s internal cybersecurity teams, providing a consistent approach to architecture reviews and cybersecurity assessments throughout the organization.

Beyond productivity gains, the initiative strengthened Sanofi’s ability to manage cybersecurity risks consistently across projects. By applying the same standards, templates and risk-scoring principles, the agent supports clearer and more reliable assessments while helping project teams understand, prioritize and mitigate cybersecurity risks earlier in the project lifecycle, ultimately reducing risk exposure and accelerating remediation efforts.

Looking ahead

From repetitive review work to augmented cybersecurity expertise

By embedding internal cybersecurity knowledge into an AI-powered review agent, Sanofi transformed a labor-intensive process into a faster and more structured workflow.

The initiative illustrates how AI can create value when applied to a clearly defined operational need. The agent does not replace cybersecurity judgment: it handles repetitive document analysis, structures the findings and highlights the most critical risks, enabling experts to focus where their expertise adds the most value.

The next step is to shift cybersecurity left by putting the assistant directly in the hands of project teams, enabling them to identify and remediate security risks before formal reviews take place. Projects gain autonomy and avoid late-stage rework, while cybersecurity specialists spend less time on preparatory reviews and more on the most critical risks, making security a faster and earlier enabler rather than a late-stage checkpoint.

The objective was not to replace cybersecurity expertise, but to augment it by automating repetitive review tasks and reinvesting that time in identifying, prioritizing and mitigating the cyber risks that really matter.

Stanislas Fontaine

Explore our expertise

Learn more about our cybersecurity expertise or get in touch with our team.

Capabilities

Artificial Intelligence
ai consulting services Read more

Capabilities

Cybersecurity
Read more