
The week of August 22, 2026, is marked by several tremors in the cyber business world in France. Between the rise of the upcoming Resilience Law, AI-powered phishing campaigns, and the reclassification of digital service providers, companies are facing a tight schedule. Here are the key points to remember.
Resilience Law and NIS2: What the new school year changes for digital service providers
Have you noticed that your cloud host or IT provider is asking you for new contractual guarantees? It’s not a coincidence. The upcoming Resilience Law, which simultaneously transposes the NIS2, REC, and DORA directives for the financial sector, structures a framework that affects approximately 15,000 entities classified in France.
The text distinguishes two levels. “Important entities” include energy, transport, health, drinking water, digital infrastructure, and public administration. “Important entities” cover chemicals, agri-food, manufacturing, and postal services.
What concretely changes for the cyber business: each affected entity will need to verify the security of its digital supply chain. Data hosting locations, retention periods, multi-factor authentication—everything is included. The penalties can reach up to 10 million euros or 2% of global turnover for important entities.
Cloud providers, software publishers, and managed service providers need to anticipate now. A compliance audit launched in September will be more comfortable than a rushed compliance effort after the law is enacted. Following the news on Cyber Business ensures you won’t miss any updates on the parliamentary progress of this text.

AI-generated phishing: French SMEs on the front line
The majority of recent phishing campaigns now use AI-generated content. The phenomenon has scaled up within months. Audio deepfakes and ultra-personalized emails make detection much more difficult for an untrained employee.
Why are SMEs particularly exposed? Three concrete reasons:
- They rarely have a dedicated cybersecurity team and rely on an external provider who intervenes after the incident, not before.
- Their employees receive little regular awareness training, making them vulnerable to sophisticated social engineering techniques.
- The budget allocated to digital security often remains marginal compared to turnover, while the cost of a cyberattack can jeopardize operations for several weeks.
French micro-enterprises are progressing in digital equipment but remain cautious about AI and cybersecurity. The gap between tool adoption and effective protection creates a vulnerability zone that attackers methodically exploit.
Incident notification: the timeline imposed by NIS2
The Resilience Law provides for a strict notification protocol in the event of a security incident. The affected entity must report the event within 24 hours, provide an interim report within 72 hours, and then a final report within the following month.
For an SME that discovers on a Monday morning that its customer data has been exfiltrated, this timeline imposes an internal organization prepared in advance. Identifying the right contact person, documenting the incident, contacting the relevant authority: each step must be planned in a response plan drafted before the crisis.
Data sovereignty and cloud: the market is restructuring
The issue of digital sovereignty is no longer a theoretical debate. The obligations of the upcoming Resilience Law regarding hosting locations are pushing French companies to review their cloud contracts. European providers that guarantee hosting within the territory of the Union are gaining ground against American players.
This movement is accelerating in sectors subject to strong regulatory constraints: health, finance, public administration. A hospital or a local authority classified as an “important entity” can no longer settle for a standard contract without verifying the physical location of its data.

What companies need to check in their cloud contracts
- The exact location of the data centers used, including those for backup and recovery.
- Clauses related to the transfer of data outside the European Union, even temporarily, for maintenance or technical support.
- The provider’s ability to provide audit evidence on its own security measures (encryption, access management, logging).
- Reversibility conditions: retrieving data in a usable format if the provider changes its pricing policy or ceases operations.
Cyberattacks targeting tax data: the State reacts
Several data breaches have affected tax services in recent months. In response to these repeated incidents, the State has created an emergency unit dedicated to cyberattacks targeting taxpayers’ tax data. This institutional response reflects an awareness: public IT systems are priority targets for attackers.
For companies, these breaches serve as a reminder that data transmitted to administrations are not safe. A SIRET number, a balance sheet, bank details posted on a public platform can end up in the wrong hands. Vigilance does not stop at the borders of the internal information system.
French companies are rethinking their cybersecurity strategies in light of the risks associated with AI and the proliferation of attack vectors. The week ahead confirms an underlying trend: cybersecurity is becoming a structural budget item, on par with accounting or legal compliance. Leaders who still treat the subject as a minor technical expense are taking a measurable risk regarding the continuity of their operations.