Every October, Cybermois returns, raising awareness about the increasing danger of cyber threats and how well organizations are prepared to face them. For the third year in a row, the initiative is supported by Cybermalveillance.gouv.fr, a French government agency focused on cybersecurity. The effort highlights a worrying trend: while cyberattacks are becoming more frequent and severe, most French businesses, especially small and medium-sized enterprises (SMEs), are not adequately protected. In 2025, the National Agency for Information Systems Security (ANSSI) recorded 1,366 security incidents and 128 ransomware attacks, with nearly half targeting SMEs and mid-sized companies. Phishing attacks were responsible for 43% of incidents reported by small businesses, up from 24% the previous year. Meanwhile, distributed denial-of-service (DDoS) attacks against French organizations doubled in 2024 compared to 2023. Despite this, 80% of SMEs say they are not prepared to handle an attack, and more than half have no clear response plan or even an understanding of the potential damage.
A common issue among SME managers is a significant gap between their perception of security and the reality. In 2025, 58% of SME leaders believed their cybersecurity was strong, a 19-point increase from 2024. However, 70% of these companies have no formal cybersecurity reference point, and three-quarters spend less than 2,000 euros annually on cyber defenses. This mismatch between belief and actual preparedness is a major risk. Simply installing antivirus software or firewalls is not enough to protect against modern cyber threats. As the World Economic Forum notes, almost 95% of cybersecurity incidents involve human error, making awareness and training just as important as technology.
The Cybermois initiative aims to address these issues by promoting education and awareness. In France, the main barrier to cybersecurity is not money or time, but a lack of knowledge. Nearly two-thirds of SMEs cite this as their biggest obstacle, ahead of budget constraints and time limitations. Cybermois, managed by Cybermalveillance.gouv.fr and supported by over 1,300 public, private, and nonprofit partners, plays a key role in breaking this cycle. However, cybersecurity awareness should not be limited to an annual event in October. It must be a continuous effort, embedded in the culture of every organization.
The implementation of the NIS 2 directive, which was passed by the French Senate in March 2025 and will soon be debated in the National Assembly, is reshaping the cybersecurity landscape. More than 15,000 French organizations will be required to comply with this new regulation, facing potential fines of up to 10 million euros or 2% of their annual revenue for noncompliance. This is no longer optional—it is a legal requirement. Added to this are the rules under the General Data Protection Regulation (GDPR), which saw a 20% increase in reported data breaches in 2024. Meanwhile, the Digital Operational Resilience Act (DORA) strengthens cybersecurity requirements for the financial sector. These changes signal that cybersecurity is no longer just a technical concern for IT departments. It is now a key part of governance, compliance, and business continuity, with serious economic consequences. In 2023, cyberattacks were estimated to have cost the French economy nearly 90 billion euros.
To better protect themselves, companies are encouraged to focus on four key areas: first, assess vulnerabilities before investing in tools. Too many organizations spend on technology without understanding their true risks. Conducting a cyber maturity audit, a risk analysis, or an intrusion test can help prioritize actions that have the greatest impact. Second, place people at the center of the strategy. Since most incidents involve human error, training and awareness programs are essential, not optional. Regular phishing simulations and ongoing education are necessary to build a strong cybersecurity culture. Third, prepare for the worst by creating a business continuity plan, an incident response plan, and crisis management protocols. These are no longer just for large corporations—they are vital for any company that cannot afford long interruptions. Finally, anticipate regulatory compliance by using standards like ISO 27001 to build a sustainable and compliant information security management system. This proactive approach will help companies stay ahead of evolving cyber threats.
Cyber Threats Intensify as French Organizations Remain Vulnerable, Reports Show
AI-rewritten from original reportingHow it works
cybersecuritysmefrancenis2awarenessregulation



