French small and medium-sized enterprises (SMEs) are becoming prime targets for cybercriminals, largely due to the high level of access that their leaders have to company systems, server administrator rights, and the ability to authorize bank transfers. According to ENISA, the European Union Agency for Cybersecurity, nearly 57% of European SMEs believe that a major cyber incident could force them to shut down or stop operating. The 2025 Cyber Threat Landscape report by ANSSI highlights that cybercriminals are now using generative AI tools to create highly targeted and error-free phishing messages tailored to specific industries, increasing the chances of successful attacks. In 2025, Cybermalveillance.gouv.fr, a French cybersecurity initiative, reported a 70% rise in phishing attacks against professionals and a staggering 93% increase in requests for help related to transfer fraud. These incidents have led to losses of up to 80,000 euros per case.
SME leaders are also vulnerable due to poor digital habits, such as reusing the same passwords for both personal and professional accounts. In 2025, account hacking rose 45% and became the second most common threat for professionals, according to Cybermalveillance.gouv.fr. Cybercriminals are increasingly using smishing (phishing via SMS) and vishing (fraudulent phone calls) to exploit the limited security available on mobile devices. Furthermore, ransomware groups like SafePay specifically target SMEs with fewer than fifty employees, with over 90% of their victims falling into this category.
The legal obligations for SME leaders have grown more complex with the introduction of the NIS2 directive and the General Data Protection Regulation (GDPR). Under NIS2, which the French Parliament is expected to approve this summer, judges can now question the personal responsibility of SME leaders in cases of serious non-compliance. The GDPR requires all SMEs, regardless of size, to report data breaches to the CNIL (French data protection authority) within 72 hours. In 2025, data breaches increased by 10%, with over 6,000 incidents reported. Fines under simplified procedures can reach up to 20,000 euros per violation, although these decisions are not made public.
To better protect their businesses, SME leaders are advised to use two separate accounts—one for technical tasks requiring administrator access and another for daily operations. Enabling two-factor authentication on all professional accounts is also strongly recommended. Leaders should always verify unusual transfer requests by contacting the supposed sender through a known phone number before proceeding. Conducting annual audits of third-party access and revoking outdated rights is crucial, as former service providers may still hold administrator access. The public initiative Cybermalveillance.gouv.fr provides free cybersecurity diagnostics and connects SMEs with certified service providers across France.
French SME Leaders Face Rising Cybersecurity Risks and Legal Responsibilities
AI-rewritten from original reportingHow it works
cybersecuritysmesphishingransomwaregdprnis2
Original sources:
- 🇫🇷Clubic



