Installing Cyberwatch: prerequisites and deployment

Choosing your deployment mode

Cyberwatch can be deployed in several ways, from sovereign SaaS hosted in France to a full on-premise installation. Your choice depends on the sensitivity of your environment and your regulatory requirements: regulated sectors (defense, energy, healthcare, finance) and critical infrastructure often prefer on-premise or air-gapped deployments.

Standard deployment

Standard deployment relies on a central console that orchestrates asset discovery, vulnerability collection, and results reporting. Scans can be performed with or without agents depending on the use case: a lightweight agent is installed on each server, application, or workstation, including in disconnected mode, while agentless scanning queries machines remotely without any installation.

Air-gapped deployment

For the most sensitive systems that cannot be connected directly to the Internet, a full Cyberwatch console can be installed in air-gapped mode, completely isolated, with manual updates for the vulnerability database. For particularly critical OT environments, non-intrusive monitoring via remote scripts is also available: inventory data is then transferred via removable media without a network connection.

Next steps

Once installation is complete, configuring connectors (Active Directory, cloud APIs, CMDB, OT probes) allows you to launch automatic asset discovery. Consult the "Configuring your first vulnerability scan" guide for the next steps in setup.