How Sanofi and Wavestone used Claude Code to build a Cyber by Design AI assistant
The challenge
Identifying and addressing project cyber risks faster and more consistently
Integrating security into projects requires cybersecurity teams to review a wide variety of documents throughout the project lifecycle. At Sanofi, these assessments draw on numerous internal standards and templates to determine whether project deliverables meet the organization’s security requirements and adequately address the cybersecurity risks introduced by the project.
While essential, this process involved a significant amount of repetitive and time-consuming work. Cybersecurity experts had to navigate several reference materials, identify security gaps, assess their associated risks, and determine the mitigation actions required before project milestones.
Sanofi therefore sought a way to streamline these activities without compromising the quality or consistency of its assessments. The objective was to accelerate document reviews, embed security requirements earlier in the project lifecycle, and enable cybersecurity experts to spend more time identifying and mitigating the risks that matter most.
The approach
Turning internal cybersecurity knowledge into an actionable AI agent
Wavestone supported Sanofi in the design and integration of an AI-powered Cyber by Design assistant. Claude Code, Anthropic’s agentic coding solution, was used as a key development accelerator, helping the team translate functional and cybersecurity requirements into a robust, operational agent while maintaining close control over the solution’s design. A first proof of concept was developed locally before being integrated into an internal Sanofi application, in close collaboration with the teams responsible for the tool. The assistant serves two audiences: project teams, who are guided on what is expected at each phase, supported in assessing project risks and able to consolidate their deliverables before review, and cybersecurity experts, who receive structured, pre-analyzed material.
The agent was built around three core sources of internal knowledge:
- Cybersecurity standards, used as the cybersecurity control framework
- Document templates, defining the expected structure and content for each type of deliverable
- A cyber risk scoring model, providing a consistent basis for rating security posture and prioritizing risks
The assistant supports project teams at every stage of the project lifecycle, from intake through design, build and go-live, to run, by identifying the security requirements applicable to each phase, explaining what is expected, and indicating when cybersecurity involvement is genuinely required.
Rather than replacing cybersecurity expertise, the agent was designed to support it. For every document submitted for review, the solution compares its content with the relevant reference materials, identifies expected information and control points, and automatically prepares the review deliverable.
The resulting output includes:
- A security posture rating, supported by clear justifications
- A risk assessment identifying key cybersecurity risks, evaluating their potential business impact and proposing mitigation measures
- A structured action plan identifying the steps required to mitigate risks and meet security requirements
This approach helps standardize reviews across projects while preserving the role of cybersecurity specialists in interpreting results, challenging findings and making decisions.
The results
Targeting up to 70% faster reviews while addressing cyber risks earlier
While the assistant supports the entire lifecycle, its most significant expected impact is on architecture reviews, where initial estimates point to a reduction of up to 70% in review and feedback preparation time. By automating the initial analysis and completion of the review deliverable, the solution is expected to reduce the burden of repetitive tasks and allow cybersecurity experts to focus more of their time on higher-value risk analysis and decision-making.
The agent incorporates more than 20 internal standards, giving teams a centralized and consistent way to apply Sanofi’s cybersecurity requirements. By systematically mapping project documentation against these standards, it helps identify security gaps earlier, assess their associated risks and define mitigation actions before issues materialize. The agent was made available across Sanofi’s internal cybersecurity teams, providing a consistent approach to architecture reviews and cybersecurity assessments throughout the organization.
Beyond productivity gains, the initiative strengthened Sanofi’s ability to manage cybersecurity risks consistently across projects. By applying the same standards, templates and risk-scoring principles, the agent supports clearer and more reliable assessments while helping project teams understand, prioritize and mitigate cybersecurity risks earlier in the project lifecycle, ultimately reducing risk exposure and accelerating remediation efforts.
Looking ahead
From repetitive review work to augmented cybersecurity expertise
By embedding internal cybersecurity knowledge into an AI-powered review agent, Sanofi transformed a labor-intensive process into a faster and more structured workflow.
The initiative illustrates how AI can create value when applied to a clearly defined operational need. The agent does not replace cybersecurity judgment: it handles repetitive document analysis, structures the findings and highlights the most critical risks, enabling experts to focus where their expertise adds the most value.
The next step is to shift cybersecurity left by putting the assistant directly in the hands of project teams, enabling them to identify and remediate security risks before formal reviews take place. Projects gain autonomy and avoid late-stage rework, while cybersecurity specialists spend less time on preparatory reviews and more on the most critical risks, making security a faster and earlier enabler rather than a late-stage checkpoint.
The objective was not to replace cybersecurity expertise, but to augment it by automating repetitive review tasks and reinvesting that time in identifying, prioritizing and mitigating the cyber risks that really matter.
Explore our expertise