Skip to content

La Perouse

Info

How to Strengthen Cybersecurity Against New Online Threats

Cybersecurity refers to the set of technical and organizational measures aimed at protecting systems, networks, and data against unauthorized access...

Analyste en cybersécurité surveillant des menaces informatiques sur plusieurs écrans dans un bureau moderne

Cybersecurity refers to the set of technical and organizational measures aimed at protecting systems, networks, and data against unauthorized access, modifications, or destruction. In the face of online threats that evolve every quarter, protective reflexes must keep pace. The stakes are no longer limited to passwords or antivirus software: they now encompass the entire chain of an organization’s digital dependencies.

Digital Supply Chain: The Attack Surface That Companies Underestimate

Most cybersecurity guides focus on the internal perimeter: firewalls, updates, employee awareness. However, the risk is shifting towards suppliers, cloud service providers, and third-party software components. ENISA documents this trend in its ENISA Threat Landscape 2026 report, published on September 15, 2026: attacks targeting digital dependencies produce large-scale incidents, well beyond the perimeter of the initially targeted company.

A compromised payroll provider can expose the personal data of dozens of clients. A vulnerable open-source component, integrated without an audit, can open a door in a certified management system. Detecting these vulnerabilities requires a rigorous inventory of each software component and every outgoing data flow to a third party.

To map these risks, the technical resources available on Viruslab’s security page detail the protective mechanisms applicable to environments exposed to multiple external dependencies.

Specifically, strengthening this layer involves three distinct actions:

  • Creating a registry of providers with access, even indirect, to the company’s systems or data, and then assessing their level of protection according to documented criteria.
  • Contractually requiring a notification period in the event of a security incident at the supplier, aligned with current regulatory obligations.
  • Implementing monitoring for published vulnerabilities for each third-party software component integrated into production systems.

IT engineer inspecting servers in a datacenter room to enhance network security

Ransomware in 2026: Why SMEs and Microenterprises Remain the Primary Targets

Ransomware remains the most impactful short-term threat. The Cyber Threat Panorama 2025, published by ANSSI on March 11, 2026, indicates that ransomware compromises reported to the Agency have slightly decreased compared to 2024. This statistical decline does not reflect a retreat of the threat: SMEs, microenterprises, and mid-sized companies remain the most affected entities.

The proportion of incidents concerning healthcare establishments is again on the rise according to the same report. The attackers’ business model has evolved: the threat has become more fragmented among several groups, complicating detection and attribution.

Propagation Mechanisms to Watch

A ransomware attack rarely penetrates through a spectacular flaw. Initial access often comes through a phishing email, poorly secured remote access (RDP exposed without strong authentication), or outdated software with publicly known vulnerabilities.

Network segmentation limits lateral propagation once initial access is obtained. If the compromised workstation cannot directly reach the file server or domain controller, massive data encryption becomes more difficult for the attacker.

Offline backups, regularly tested, remain the last line of defense. A backup that is continuously connected to the network can be encrypted at the same time as production data, nullifying its usefulness.

Artificial Intelligence and Cybersecurity: A Double Exposure

AI is changing the threat landscape in two opposing directions. On one hand, machine learning-based detection tools enhance the ability to spot abnormal behaviors on a network. On the other hand, cybercriminal groups are using AI to improve their operations, according to the ENISA Threat Landscape 2026.

Phishing emails generated by language models are more convincing, better written, and personalized using public data. Audio deepfakes can impersonate a leader’s voice to validate a fraudulent transfer.

AI Systems as Direct Targets

The AI systems deployed by organizations themselves become potential targets. A model trained on confidential data can be manipulated to reveal it. A poorly segmented chatbot interface can serve as an access vector to the underlying information system.

Auditing the inputs and outputs of each AI system connected to the network becomes a full-fledged risk management step. This includes third-party APIs used to enhance a product’s functionalities.

Professional working remotely securing their IT access with two-factor authentication from their home office

NIS 2 Directive: Cybersecurity Obligations for Companies in France

The European NIS 2 directive expands the scope of organizations subject to cybersecurity obligations. In France, the transposition now concerns a much larger number of companies, including mid-sized structures that were not covered by the first version of the text.

The obligations focus on risk management, incident notification to the competent authorities, and the implementation of proportionate technical and organizational measures. Non-compliance with NIS 2 exposes organizations to administrative sanctions.

For microenterprises and SMEs discovering these requirements, the process begins with an assessment of their situation: does the company operate in a sector covered by the directive? Do its systems handle data whose unavailability would impact a service deemed critical?

  • Identifying whether the company’s activity falls within the sectors listed by NIS 2 (energy, transport, health, digital infrastructure, among others).
  • Designating a responsible person for information systems security, even on a part-time basis, tasked with overseeing compliance.
  • Documenting existing protective measures and comparing them to the requirements of the text to prioritize corrective actions.

The threat is no longer limited to an isolated virus on a workstation. Between the fragmentation of ransomware groups, the exploitation of AI by attackers, and the expansion of regulatory obligations, each organization must treat cybersecurity as an ongoing process, not as a one-time project. Companies that map their digital dependencies and genuinely test their backups have a head start over those that merely check boxes.

How to Strengthen Cybersecurity Against New Online Threats