French NATIONAL DIGITAL SECURITY STRATEGY — INTRODUCTION
INTRODUCTION
France is going through its digital transition.
Networks are omnipresent in the functioning of
the State, economic activity and the daily lives of
citizens.
Digital technology engenders new uses, new
products and new services and is therefore a factor
of innovation. It leads to transformation in most
trades. It transforms sectors of activity and businesses giving them more flexibility and competitiveness. Boosted by digital support, these sectors
are simultaneously more exposed to digital threats.
Doing without digital technology or the lack of
access to it results in a form of economic and social
exclusion. Similarly, the sovereignty of a State that
does not have the autonomy required in the digital
sector would be threatened.
For digital technology to remain an area of
freedom, exchanges and growth, trust and security
must be established and defended. Only through a
collaborative and coordinated effort can this objective be attained.
*
*
*
An initial cybersecurity strategy was developed in
France in early 2010 and was published in early 2011
shortly after the discovery of a cyberattack, the intention of which was to spy on the economic and finance
ministries. The attackers, who had been acting for several months, had taken control of the core of one of
the ministerial networks and were regularly collecting
political, economic and financial information.
This type of cyberattack targets many French businesses of all sizes in all sectors of activity. Businesses
are also the target of all types of fraud such as malware
infection that makes the business’ files unusable until a
ransom is paid by means that are difficult to trace.
In parallel, computer system intrusions aimed at
stealing personal information (identity, identification
data on commercial websites and bank details) are on
the rise. Most of the times, it concerns criminals committing crimes that are identical to those known in
the material world such as theft, fraud and blackmail,
but in an industrialised manner, with less risk of being
identified and prosecuted. Organised crime has seized
the opportunity provided by electronic communication
networks. Their technical capabilities are increasing to
the point where they are now capable of carrying out
acts of sabotage or taking production tools hostage, for
themselves or through subcontracting by hybridisation.
Harassment campaigns are developing on social
networks, such as cases of fraud victimisation whereby gullible subjects are persuaded to transfer money
abroad.
The defacement of many websites, notably those belonging to territorial authorities, following the attacks
of January 2015 and the cyberattack a few weeks later
on a French international media have demonstrated the
intention and ability of organised groups to cripple information system resources that support our daily lives.
What was recognised as «the state of threat» established in 2010, therefore turned out to be accurate. At
present, the threat is intensified by the increase in the
capabilities of attackers, the proliferation of techniques
7