Following widespread criticism from both the left and right wings of the parliamentary chamber after the hacking of the tax authority's website, the French government unveiled its institutional response to cybersecurity issues within the ministries on Monday, September 7. The initiative, known as "REACTIV," aims to improve how the state protects the personal data of its citizens. Led by the National Agency for Information System Security (ANSSI), this new working group will have expanded powers to secure computer systems, focusing on better containing cyberattacks and responding more actively to data leaks.
REACTIV, whose full name is "REponse & ACTion Interministérielle face aux Violations de données," was established at the request of the prime minister's office, known as Matignon. This initiative marks a significant shift in how the government handles IT governance. For the first time, ANSSI will not only provide advice but also have the authority to issue instructions. According to ANSSI, this means the agency can now require ministries to take immediate action to protect citizens' data, within strict deadlines.
Under REACTIV, ANSSI’s mandate has been significantly expanded. The agency can now compel ministries to implement technical measures to prevent data leaks within set timeframes. Additionally, REACTIV centralizes all technical crisis communication, making ANSSI the de facto spokesperson for affected ministries and state agencies during security incidents. This move comes after several high-profile breaches, including the exposure of 678,000 users’ data by the Direction générale des Finances publiques (DGFiP) and the hacking of the ANTS (National Agency for the Security of Transport). These incidents highlighted weaknesses in access management and digital security practices.
To support REACTIV, the government plans a restructuring of its IT architecture, backed by a 200 million euro budget and the planned merger of two key departments, DINUM and DITP. However, the funding for USB tokens—hardware security keys intended for all government employees—has not yet been included in the budget announced earlier this year. As part of the new directives, multi-factor authentication (MFA) for all system administrators must be deployed by the end of the year. Employees will also be equipped with hardware security keys to protect against social engineering attacks, which often involve tricking individuals into revealing sensitive information.
The REACTIV operation involves a rapid shift in ANSSI’s operational focus, emphasizing stronger support for ministries dealing with account compromises and data breaches. However, the statement from the agency did not clarify whether additional resources would be allocated to ANSSI or the ministries to ensure the successful implementation of this new working group.
France Launches New Cybersecurity Initiative in Response to Recent Data Breaches
AI-rewritten from original reportingHow it works
cybersecurityreactivanssidata-breachgovernmentfrance



