
Cybersecurity refers to the set of technical and organizational means deployed to protect information systems against unauthorized access, illicit modifications, and service interruptions. It is based on three pillars: confidentiality, integrity, and availability of data. Following online cybersecurity news allows one to anticipate threats that evolve at a rapid pace, between new European regulations and increasingly targeted attack techniques.
Incident Notification under NIS2: The Timeline Companies Must Know
The European NIS2 directive imposes a three-step incident notification process on the concerned entities. An early alert must be sent to the competent authority within 24 hours of detection. A detailed notification follows within 72 hours, and a final report is expected within a month.
See also : Everything You Need to Know About the Legality of 1fichier in France: What the Law Says in 2026
This sequencing transforms incident management. It is no longer about reacting and then documenting afterward: each phase requires qualifying the nature and scope of the attack in real-time. For a company that has never formalized an escalation procedure, the transition from theory to compliance represents a significant undertaking.
Professionals who wish to delve deeper into the subject can find information on the Viruslab website, which lists resources related to current threats and best protection practices.
Related reading : How to Effectively Protect Your Personal Data Online in 2024
France has still not finalized the transposition of NIS2 into national law, and the European Commission has referred the country to the EU Court of Justice for this delay. This situation creates a zone of legal uncertainty for French organizations subject to the directive.

Cyber France Reference Framework (ReCyF): Operational Measures Published by ANSSI
Without waiting for the transposition law, ANSSI published the Cyber France Reference Framework (ReCyF) on March 17, 2026. This working document translates the objectives of NIS2 into concrete operational measures aimed at information system security managers.
The ReCyF covers a broader scope compared to previous recommendations. It incorporates obligations related to the digital supply chain and strengthens oversight requirements for third-party providers. For an SME’s CISO, this framework serves as a roadmap even before the formal entry into force of the law.
ANSSI’s approach is pragmatic: rather than a fixed normative text, the ReCyF offers progressive maturity levels. An organization can identify its starting point and plan its cybersecurity investments over several months, without needing to reach the maximum level immediately.
Ransomware and Phishing in Europe: Recent Trends
Ransomware cyberattacks have increased by 29% in Europe according to a recent study by TicTac Research. This increase does not only affect large companies: local authorities and healthcare establishments are among the preferred targets, as their information systems are often less segmented.
Phishing remains the most widespread intrusion vector. Current campaigns combine social engineering and exploitation of technical vulnerabilities, making detection more complex for automatic filters. ENISA reports highlight a convergence between phishing and distributed denial-of-service (DDoS) attacks, used in combination to overwhelm security teams while fraudulent access is established.
Mechanisms of a Combined Phishing-DDoS Attack
The typical scenario follows a precise sequence:
- A phishing email targets an employee with high access rights, using a credible pretext related to the company’s current affairs.
- Simultaneously, a DDoS attack saturates the organization’s servers, mobilizing the IT team on service availability.
- The attacker exploits the stolen credentials while attention is diverted, to exfiltrate data or deploy ransomware.
This diversion strategy explains why detection relies as much on user training as on technical tools. An effective firewall does not block a click on a fraudulent link.

Cybersecurity in France: The Role of Authorities and Frameworks
Several institutions structure the French cyber ecosystem. ANSSI leads the national strategy for information system security and operates CERT-FR, which publishes security alerts and vulnerability notices. CNIL oversees the protection of personal data and sanctions breaches of GDPR.
The Cybermalveillance.gouv.fr system plays a complementary role focused on assistance. It connects victims of cyber malice (individuals, businesses, local authorities) with certified ExpertCyber providers. This label guarantees a verified level of competence in securing and remediating.
The Pillars of an Operational Cybersecurity Policy
Implementing effective protection requires acting on several levers simultaneously:
- Access and Identity Management: each user only has the rights strictly necessary for their function, with enhanced authentication.
- Continuous system supervision: centralized event logs, detection of abnormal behaviors, regular penetration testing.
- Employee awareness: phishing simulation exercises, documented escalation procedures, a culture of reporting without blame.
- Backup and business continuity plan: periodically tested offline copies, known and validated restoration times.
These measures are not reserved for large companies. ANSSI’s ReCyF indeed offers levels suitable for organizations with limited resources.
Cybersecurity is no longer a domain reserved for network specialists. Between the notification obligations imposed by NIS2, operational frameworks like the ReCyF, and the rise of combined attacks, every organization must treat cybersecurity as a continuous process, not as a one-off project. The coming months, with the expected finalization of the French transposition of NIS2, should clarify the legal framework applicable to companies on national territory.