1. Two different cases, one structural warning

Within a few days, two cases of very different kinds brought the protection of public-sector data back to the forefront. They should not be confused, but considering them together is useful because they reveal two complementary blind spots: on the one hand, the misuse of legitimate accounts inside an information system; on the other, the possible exposure of institutional information through a third-party digital service outside the perimeter directly controlled by the administration.

Regarding the DGFiP, the Ministry of the Economy and Finance confirmed on August 14, 2026 that unauthorized access in June and July relied on the theft or misuse of credentials belonging to a DGFiP employee and an authorized third party. The accounts concerned were disabled after detection, but the checks carried out at that time had not revealed that the intrusions had already led to data theft. More in-depth investigations later established that data relating to 678,000 individuals and professionals had been viewed or extracted, including tax information and, for businesses, items such as the company name or SIREN identifier.

This point is essential: an attacker does not necessarily need to force the door if they manage to obtain a valid key. Modern security must therefore continue to operate after authentication and be able to detect when an authorized account suddenly behaves in a way that is incompatible with its normal use.

The DJI SkyPixel alert reveals another type of vulnerability

On August 16, 2026, FrenchBreaches relayed the work of a security researcher concerning DJI SkyPixel. According to that work, an insufficiently protected feature may have made it possible to identify at least 42,029 accounts and link certain email addresses to public profiles. Among the government addresses identified was one using @gendarmerie.interieur.gouv.fr, which the researcher associated with the environment of the French Gendarmerie’s Criminal Research Institute.

It is important to be completely precise: this does not mean that the French Gendarmerie’s information system was compromised. The documented vulnerability concerns the DJI SkyPixel ecosystem. That is precisely what makes the case instructive. An administration can strengthen its own servers and still remain exposed through the platforms, software, mobile applications, cloud services, suppliers or external accounts used around them.

2. The real boundary: after authentication and beyond the State’s network

For years, a considerable part of cybersecurity was designed around the system’s point of entry: passwords, strong authentication, firewalls, filtering and access-rights control. These protections remain essential, but they are no longer sufficient. When an attacker uses the perfectly valid identity of an employee or contractor, the system must still be able to detect when apparently authorized activity becomes abnormal.

An employee who normally consults a few dozen files and whose account suddenly begins querying or extracting several thousand should not automatically be treated as a normal user simply because the password is correct. Volume, time of day, device, request rate, data sensitivity, file destination and the account’s usual behavior can be correlated in order to trigger enhanced verification when the context warrants it.

The objective is not to mechanically block every large-scale operation. Some administrations legitimately process data at scale. The point is to make a fundamental distinction: having an access right is not proof that every action performed with that right is legitimate.

3. Who must act, who must oversee, and why are these officials named?

Demanding accountability does not mean arbitrarily naming a culprit before all the facts are known. It means identifying each level of responsibility, understanding the levers available to it, and asking questions that genuinely correspond to its role. The chain is national, interministerial, ministerial, operational, regulatory and parliamentary at the same time. The purpose is therefore not to pile up names, but to show who coordinates, who protects, who responds to incidents, who administers, who oversees, and who can turn lessons learned into obligations.

At national level: the Prime Minister and SGDSN coordinate national security

At the top of the interministerial chain, Prime Minister Sébastien Lecornu; @ SebLecornu, relies on the Secretariat-General for National Defence and Security, the SGDSN. Secretary-General Nicolas Roche obviously does not administer every ministry’s systems; the SGDSN does, however, organize the overall coordination of national defence and security and oversaw the development of the 2026–2030 National Cybersecurity Strategy. The 2026–2027 roadmap for the State’s digital security also provides for monthly operational monitoring by the Interministerial Committee for Monitoring Digital Security, CINUS, bringing together ministerial security chains under ANSSI’s authority. The question at this level is therefore one of overall consistency: how do lessons from an incident affecting one ministry rapidly become decisions and common requirements across the State?

ANSSI: the national authority for cybersecurity and cyber defence

The French National Cybersecurity Agency, ANSSI; @ ANSSI_FR, is the national authority for cybersecurity and cyber defence. It is currently headed by Vincent Strubel. Its role cuts across the State: defend, understand the threat, share information, support stakeholders and regulate. It does not replace each ministry’s security officials, but it sits precisely at the level where common doctrines, detection capabilities, support for administrations and responses to major digital crises must be developed and coordinated.

The DGFiP and SkyPixel cases therefore raise several questions that are directly relevant to ANSSI: how does the State detect that an authenticated account has suddenly begun behaving like an attacker; how are risks linked to third-party services and contractors mapped; how are lessons from a compromise circulated to other administrations; and how is it verified that security recommendations do not simply remain written in a report?

CERT-FR and ministerial CSIRTs: detect, coordinate and respond to incidents

Within the national system, CERT-FR is the government and national computer incident response centre. It intervenes primarily in incidents affecting ministries and State services, as well as other critical actors, and supports ministerial CSIRTs. These ministerial teams analyse threats affecting their own perimeter and strengthen each ministry’s ability to understand, detect and handle incidents. CERT-FR is therefore not the IT department for every ministry; it is one of the operational links that makes it possible to share threat information, coordinate the response and prevent the same modus operandi from being repeated elsewhere without other administrations being alerted.

This architecture also recalls an essential principle: each ministry remains responsible for the security of its own perimeter. Implementation relies on internal security chains, including steering functions, qualified authorities, information-systems security officers and ministerial response capabilities. These internal officials are not all publicly identifiable, but they are an integral part of the chain through which alerts must travel upward and corrective measures downward.

At Bercy: political oversight and DGFiP management must also answer questions

The DGFiP case makes it necessary to identify the chain directly concerned at Bercy. David Amiel; @ Amiel_David_, is Minister for Public Action and Accounts; Amélie Verdier is Director-General of Public Finances, whose institutional account is @ dgfip_officiel. Their presence in this chain obviously does not mean that they personally caused a technical flaw. The minister bears political responsibility for oversight and resources; the Director-General bears strategic and administrative responsibility for the DGFiP.

The questions put to them are therefore concrete: why did the initial checks fail to detect immediately that data theft had already occurred; what measures have since been taken to monitor abnormal behaviour and extraction; what recommendations have been rolled out across the tax information system; and who will verify over time that these corrections are genuinely operational? The August 14, 2026 statement itself acknowledges that the fraudulent access relied on stolen credentials and that the initial checks had failed to identify the data theft; that is precisely why this chain must be included in the debate.

The Minister of the Interior: political responsibility and allocation of resources

Laurent Nuñez; @ NunezLaurent, is Minister of the Interior. His responsibility is obviously not to configure computer systems himself; it is to set political priorities, allocate resources, organize the chain of responsibility and ensure that identified structural vulnerabilities actually lead to corrections. It is therefore legitimate to ask what doctrine the ministry applies to controlling digital dependencies, third-party services, privileged access and contractors.

The Director-General of the Gendarmerie: strategic responsibility for the institution

Army General Hubert Bonneau heads the French Gendarmerie. Leading the institution does not mean being personally answerable for every technical error; it does, however, mean having to maintain a doctrine, an organization and control mechanisms capable of reducing the risks affecting the Gendarmerie, including when those risks originate with contractors or external platforms. The relevant question is therefore how the institution maps its dependencies, governs external uses and turns incidents into rules applicable across all of its services.

COMCYBER-MI: doctrine, resilience and continuity of State action

Major General Patrick Touak; @ TouakPatrick, heads the Ministry of the Interior’s Command in Cyberspace, COMCYBER-MI. The Gendarmerie reports that he has notably presented digital independence, continuity of State action, data theft, detection tools and the digital hygiene of employees and contractors as central issues. The question that can be put to him is therefore less “why does this flaw exist?” than “what doctrine does the ministry apply to identify third-party services used by its personnel, control institutional accounts opened outside the ministry, detect abnormal behaviour and prevent a local or external compromise from producing disproportionate effects?”

UNCyber: operational experience of the adversary

General Hervé Pétry commands the Gendarmerie’s National Cyber Unit. It would be incorrect to present him as responsible for securing all of the Gendarmerie’s information systems. UNCyber is currently structured around intelligence, investigation and technical support, with a mission focused on fighting high-level cybercrime. But that is precisely why its operational feedback is valuable: those who see every day how attackers compromise accounts, exploit stolen data, use platforms and bypass protections must be able to feed back the scenarios against which defensive systems need to prepare.

CNIL: overseeing personal-data protection and the handling of breaches

The French Data Protection Authority, CNIL; @ CNIL, must be distinguished from ANSSI. It is not responsible for defending State networks against cyberattacks; it is the independent authority responsible for protecting personal data. Its president is Marie-Laure Denis. When a personal-data breach poses a risk to people’s rights and freedoms, the data controller must in principle notify the CNIL as soon as possible and, where feasible, within 72 hours of discovering it.

In a case affecting hundreds of thousands of individuals and professionals, its oversight role is therefore fully relevant: how was the incident documented; what risk assessment was carried out; what information was provided to the people concerned; what corrective measures were taken; and were security and data-protection obligations met? CNIL replaces neither ANSSI nor the ministries; it provides another level of oversight, focused on people’s rights and the obligations of the data controller.

Parliament: scrutinize, hold hearings and turn findings into obligations

In Parliament, Philippe Latombe; @ platombe, chairs the special committee examining the bill on the resilience of critical infrastructure and the strengthening of cybersecurity; Éric Bothorel; @ ebothorel, is its general rapporteur. Their role is not to answer personally for past incidents, but their position enables them to hold hearings, exercise oversight, amend the law and request guarantees. At this level, a technical lesson can become a legal obligation or an oversight mechanism.

The chain thus becomes much clearer: the Prime Minister and the SGDSN provide overall coordination; ANSSI carries national authority and cybersecurity doctrine; CERT-FR and ministerial CSIRTs organize part of the operational incident response; each ministry remains responsible for its own perimeter; at Bercy, the Minister for Public Action and Accounts and the DGFiP’s senior management are directly answerable for the organization of the tax system; at the Ministry of the Interior, the minister, the Gendarmerie’s senior leadership and COMCYBER-MI bear their respective responsibilities; UNCyber contributes operational experience of the criminal threat; CNIL oversees personal-data protection; and Parliament holds hearings, exercises oversight and can turn technical lessons into legal obligations.

4. Four questions that should remain open until there is a verifiable answer

Once this chain has been identified, the issue is not to demand miracles or pretend that an administration can be invulnerable. It is, however, legitimate to demand traceability for decisions and corrective action.

5. Demanding accountability is not enough: corrections must be measurable

The word “audit” should no longer be synonymous with yet another report. A useful audit must make it possible to identify critical systems, their owners, privileged accounts, contractors with access, external services in use, sensitive data flows, backups, software dependencies and reconstruction capabilities. Each major vulnerability should be prioritized, assigned to an operational owner, given a timetable and tracked until it is effectively closed.

Privileged-access management provides a simple example. When a contractor needs to work on sensitive infrastructure, permanent access should not be treated as a normal convenience. Where the architecture allows it, access can be individual, limited to the resources actually required, strongly authenticated, logged, opened for a defined period and then automatically revoked. This is not suspicion of contractors; it is the application of a basic principle: no one should retain more privileges for longer than they genuinely need.

The same logic applies to backups and continuity. A backup whose existence appears in a spreadsheet is not yet a guarantee of resilience. It must be restored during exercises, measuring both the time required to rebuild a service and the ability to continue operating when the primary provider becomes unavailable.

6. Electronic invoicing changes the scale of economic risk

From September 1, 2026, all businesses concerned will have to be able to receive electronic invoices; large companies and mid-sized companies will also have to issue invoices in this form and transmit the data required by the scheme. The Ministry of the Economy states that more than ten million economic actors are concerned by the reform and that invoices pass through approved platforms.

It would be simplistic to present this system as one gigantic database containing every French invoice. The issue is subtler and, in some respects, more important: a vast ecosystem will circulate structured information at scale about transactions, suppliers, customers, amounts and commercial relationships. Some data are also transmitted to the administration. Protecting this whole environment must therefore be treated not only as a cybersecurity issue, but also as an economic-security issue.

The risk lies not only in the theft of an isolated document. It also lies in correlation. Millions of apparently ordinary data points can, when combined, make it possible to map industrial dependencies, supplier relationships, activity volumes or commercial trends. For a cybercriminal, a malicious competitor or a foreign intelligence service, that informational value can be considerable.

7. Artificial intelligence accelerates both attack and defence

Technological change makes this discussion even more urgent. Anthropic states that partners in its Project Glasswing, using Claude Mythos Preview, had already identified more than 10,000 high- or critical-severity vulnerabilities by early June 2026. In an earlier review, the company also stated that Mythos Preview estimated it had found 6,202 high or critical vulnerabilities across more than 1,000 open-source projects analysed. These are the figures published by Anthropic and should be presented as such, but they illustrate a major change in pace.

The question is therefore not whether artificial intelligence will replace experts. It is to understand that experts equipped with tools capable of analysing code, comparing configurations and searching for vulnerabilities at very high speed can gain a considerable advantage over those who keep exactly yesterday’s methods and pace. A serious national strategy must plan against tomorrow’s capabilities, not only yesterday’s.

8. Sovereignty is not limited to military secrets

Article 410-1 of the French Criminal Code recalls that the Nation’s fundamental interests include, among other things, its security, the protection of its population and the essential elements of its scientific and economic potential. This obviously does not mean that every data leak legally constitutes an attack on the Nation’s fundamental interests. That distinction is essential.

The provision nevertheless highlights a major political reality: protecting a country does not only mean protecting the specifications of a missile, submarine plans or an intelligence secret. A nation also protects its citizens, businesses, know-how, scientific capabilities, economic potential and the digital infrastructure on which their operation now depends.

9. Parliament has other oversight levers

The special committee devoted to cybersecurity is not Parliament’s only point of entry. Jean-Philippe Tanguy; @ JphTanguy, is a member of the Finance Committee and can therefore contribute to oversight of budgetary resources and Bercy’s actions. Jean-Michel Jacques; @ J_M_Jacques, chairs the National Defence and Armed Forces Committee; its remit becomes relevant when cybersecurity intersects with interference, sovereignty, hybrid warfare or the protection of strategic infrastructure. Vincent Caure; @ vincent_caure, chairs the Law Committee; that committee is involved when questions of security, law, State organization and parliamentary oversight intersect.

Here again, the point is not to ask them to configure a firewall. It is to ask them to use their institutional levers: what resources have been committed, what warnings were escalated, which recommendations went unimplemented, which contracts or dependencies pose a risk, what deadlines were set, and who is responsible for checking whether the announced corrections are real?

10. From criticism to proposals: 14 structural measures and 67 actions

Criticism is truly useful only when it also opens a debate on solutions. A citizen outside the State obviously does not know every internal constraint facing administrations and should not replace the officials who have the mandate, information and operational expertise. But a citizen can work, document, compare and publish proposals so that they can be discussed, corrected, improved or adopted.

That is the purpose of the work published on Delta-Sierra: 14 structural measures devoted to digital sovereignty and artificial intelligence, supplemented by a Digital Shield for France comprising 67 operational actions. The programme covers, among other things, protection, detection, privilege limitation, auditing, containment, resilience and reconstruction.

Full dossier:https://www.delta-sierra.com/france/audit-souverainete-numerique-ia-14-mesures.html

These proposals are not asking to be approved on principle; they are asking to be examined. If some are technically unsound, explain why. If some already exist, state where they are deployed, at what scale and with what results. If they are relevant but insufficiently implemented, identify the obstacles. If better solutions exist, put them on the table. And if some proposals can concretely strengthen the protection of citizens, businesses and the State, they are of course intended to be reused.

Conclusion: demanding accountability means demanding proof of correction

Digital resilience is not the unrealistic promise that no attacker will ever get in. It is an architecture in which a stolen credential does not allow someone to see everything; a compromised account does not allow an entire database to be silently siphoned off; a compromised workstation does not automatically open the whole network; a compromised contractor does not possess every key; an external service does not become a blind spot; and a successful attack is not enough to paralyse an essential service for an extended period.

Demanding accountability therefore does not mean arbitrarily searching for a culprit. It means asking each level of responsibility to demonstrate what it did, what it controls, what was corrected and how that correction was verified. After every crisis, the same questions should remain open until there is a verifiable answer: which vulnerabilities were known; which measures had already been decided; what was actually corrected; and who verifies, after the announcements, that the corrections are actually being applied?

A genuine national digital-resilience policy should be judged on those answers far more than on the statements published after each incident.