Many small and medium-sized business leaders initially believed that cybersecurity was something only large corporations needed to worry about. However, several managers have since changed their practices without hiring experts or making major financial investments. Others have discovered that improving cybersecurity has opened up new markets for their businesses. According to the ImpactCyber barometer, published in 2026 by Cybermalveillance.gouv.fr, one in six companies has been attacked in the past year, and eight out of ten leaders admit they are unprepared. The survey also collected stories from business leaders who improved their security without increasing expenses. France Num, a public platform for businesses, has highlighted cases where cybersecurity helped SMEs secure or maintain markets, challenging the idea that it is only a defensive expense.
François, manager of a ten-employee roofing company in Tours, revamped his company's security without hiring new staff. Previously, his team used a fixed IP address for remote access and a simple password based on the company's name. After realizing the risks, he switched IT providers, upgraded the server, and installed a firewall to filter connections. He also introduced individual, structured passwords for all team members. "Sensitizing the teams seems to be a priority," François says. His company handles sensitive banking data, which could have been exploited to impersonate the business in front of clients.
Guillaume, founder of a fintech company with sixty employees, focused on employee training rather than just technical tools. He believes that human error, such as accidentally downloading malicious software, is the biggest risk. He implemented training sessions and created scenarios to test the company's response to cyberattacks. "The installation of malicious software or the taking over of a computer is entirely possible," Guillaume explains.
Some businesses found that cybersecurity improvements led to new opportunities. Laurent Elles, founder of Acrotir, a rope access company based in Lunéville, realized in 2024 that his company couldn't compete for a government contract due to insufficient data security. After upgrading his cybersecurity, he received recognition at the Cybersecurity Award of the CPME Digital Trophies. Similarly, Edwige Le Douarin, founder of Aquatiris, an ecological sanitation company, faced a fake RIB fraud in 2022. She since implemented a comprehensive cybersecurity strategy, which also improved her company’s overall efficiency. Carole Alves Saldanha, director of Fondouest, a geotechnical engineering firm, credits a recent cybersecurity audit with helping her company respond effectively to a ransomware attack.
Despite these improvements, challenges remain. The ImpactCyber barometer, conducted in 2025, shows a slow but positive trend: the average number of security tools used by SMEs increased from 3.62 to 4.06 over a year. About 58% of companies now feel they have a good or very good level of protection, up from 39% the previous year. However, nearly 30% of SMEs still consider cybersecurity a low priority, and 63% cite a lack of knowledge or expertise as a barrier. Budget constraints and time limitations also remain significant issues. To help businesses, Cybermalveillance.gouv.fr offers a free service called Mon ExpertCyber, connecting users with certified IT providers to improve security without large investments.
SME Cybersecurity Efforts Show Progress Amid Persistent Challenges
AI-rewritten from original reportingHow it works
cybersecuritysmefraud-preventiondigital-transformationimpactcybercyber-risks
Original sources:
- 🇫🇷Clubic



