France is used here as a documented warning, not as a caricature. Other countries should ask whether their own critical-infrastructure governance can turn a technical alert into a funded, verified correction before an attacker exploits the gap.
Foreword: the problem is no longer merely knowing, but acting
On 21 August 2026, Le Figaro highlighted an FBI warning about attacks on water networks and the risk of industrial failures in France. Read in isolation, the headline can look like a new threat imported from the United States. Read chronologically, it is the latest episode in a much longer story: France has had a legal framework for vital operators since 2013, water-sector security rules since 2016, ANSSI evidence of incidents and exposed industrial equipment, European resilience obligations, and repeated warnings about uneven maturity. Meanwhile, US agencies reported attacks on water PLCs with loss of pressure and flooding in July 2026, followed in August by an inter-agency alert on active targeting of Siemens S7 systems, including AI-assisted exploitation scripts. [1][2][3][4][9][10][11]
The political dimension became harder to dismiss on 19 August 2026, when Prime Minister Sébastien Lecornu publicly stated that few ministries were at the required cybersecurity level and asked ANSSI to create a new operational cyber unit. The same day, US agencies issued their Siemens S7 warning. This coincidence does not prove that the French government had suffered an S7 campaign; it shows that industrial threats were accelerating at the very moment the head of government acknowledged insufficient cyber maturity inside the State. [11][13]
This dossier separates established facts, legitimate political questions and Delta-Sierraâs editorial judgment. When the word âincompetenceâ is used, it is a political assessment of governance, decision-making or implementation, not an allegation that every public employee has committed misconduct. The sources do not establish that the American Siemens S7 campaign has been observed in France; they establish an active US threat, comparable structural vulnerabilities in France and documented French compromises in water and energy. Those are three different propositions. [3][8][11][12]
A one-page chronology
| Date | Event |
|---|---|
| 2013 | Military Programming Law organises cyber protection of operators of vital importance. [1] |
| 2016 | Specific security rules are introduced for vital water-sector information systems. [2] |
| 2021â2024 | ANSSI handles events affecting 46 water-sector entities and documents recurring weaknesses. [3] |
| 17 Oct 2024 | EU deadline for NIS2 and Critical Entities Resilience transposition. [4][9] |
| 12 Mar 2025 | French Senate adopts the resilience/cyber bill at first reading. [5] |
| Jun 2025 | Cour des comptes calls for stronger inter-ministerial cyber steering. [6] |
| 22 Jan 2026 | CERT-FR reports French compromises in water and energy and publishes hardening advice. [8] |
| 29 Apr 2026 | European Commission refers France to the CJEU over critical-entity resilience. [9] |
| 8 Jul 2026 | Further CJEU referral over incomplete NIS2 transposition. [4] |
| 30 Jul 2026 | FBI reports attacks on US water PLCs with pressure losses and flooding. [10] |
| 19 Aug 2026 | French PM acknowledges insufficient ministry maturity; US agencies warn about Siemens S7. [11][13] |
| 20 Aug 2026 | Siemens says it sees no attack surge or unknown flaw; known configuration errors remain central. [12] |
| 21 Aug 2026 | Industrial-failure risk enters mainstream French debate. |
I. Thirteen years of alerts and rules: the scenario was not invisible
2013 and 2016: critical infrastructure and water were already treated as cyber-security issues
The 18 December 2013 Military Programming Law created specific obligations for protecting vital infrastructure from cyber threats and placed national coordination of information-system security under the Prime Minister. Three years later, a dedicated order established security and incident-reporting rules for information systems of vital importance in the water sector. These measures do not mean every future vulnerability was known; they mean that the risk of cyber compromise of essential services has been officially recognised for more than a decade. [1][2]
Water is especially difficult because responsibility is fragmented across municipalities, inter-municipal bodies, syndicates, public utilities, private operators, integrators and contractors. A national operator and a small local utility do not have the same engineers, budgets or capacity to replace industrial equipment that may be decades old.
2021â2024: French incidents were already real, not hypothetical
CERT-FR reported in November 2024 that 46 water-sector entities had been affected by IT events handled by ANSSI between January 2021 and August 2024. ANSSI described old installations, geographically dispersed sites, sometimes weak security budgets, highly uneven maturity and industrial interfaces reachable from the Internet. Remote management increases the attack surface; protocols designed historically for availability and simplicity may lack the authentication and encryption expected on todayâs hostile Internet. [3]
Industrial control is different from ordinary office IT. A compromised interface can operate a pump, valve, chemical dose, tank level, pressure setpoint or motor. At that point, a cyber incident can become a physical event.
2024â2026: European deadlines, French delays and repeated warnings
NIS2 and the Critical Entities Resilience Directive were designed to broaden and harmonise cyber-security and continuity obligations. The transposition deadline was 17 October 2024. France did not complete transposition on time; infringement procedures eventually led to referrals to the Court of Justice in 2026. France was not the only Member State involved, but the proceedings objectively document delay on legislation directly connected to cyber-security and resilience. [4][9]
The Senate adopted the French resilience and cyber-security bill at first reading on 12 March 2025. In June 2025, the Cour des comptes called for stronger inter-ministerial steering, better programming of resources and greater involvement of public-sector leadership. This matters because an institution can have excellent engineers and analysts while remaining weak at governance: who has the authority, budget and timetable to make a vulnerability disappear? [5][6]
Cybermalveillance.gouv.fr also documented highly uneven preparation in smaller local authorities. That study does not prove that their water systems are insecure; it does document a structural difficulty in territorial cyber maturity. [7]
January 2026: ANSSI was still seeing compromises in water and energy
CERT-FR reported multiple French compromises in water and energy and again described Internet-accessible equipment, weak authentication, default credentials and exposed industrial protocols. It went as far as recommending local operation and disconnection from the Internet when minimum security measures could not be implemented. It also reported a case that stopped a wind farm for several hours. [8]
July and August 2026: cyber attacks produced physical effects in US water systems
On 30 July, the FBI and EPA warned of attacks against Internet-facing Rockwell Automation / Allen-Bradley MicroLogix PLCs in water and wastewater facilities. Attackers changed addresses and passwords and caused loss of visibility or control. The FBI reported loss of pressure and flooding; depending on circumstances, pressure loss can also create water-quality risks. The point is decisive: cyber compromise can alter the physical conditions of an essential service. [10]
On 19 August, NSA, CISA, FBI, DOE and EPA issued a joint warning about active targeting of Siemens S7 PLCs. The advisory described actors using Internet-scanning services and AI-generated or AI-assisted exploitation scripts, sometimes disguised as legitimate monitoring tools. Water, energy, manufacturing, chemicals and food were among the affected sectors. Siemens then provided an essential counterpoint: it said it had not observed a surge in attacks or an unknown vulnerability, and stressed known configuration weaknesses. That nuance should not be lost; the issue is not a secret universal Siemens flaw, but the persistence of exposure, obsolete configurations and weak hardening. [11][12]
The debate is no longer âcould we have known?â but âwe already knew a great deal; between the technical alert, political arbitration, funding and field verification, where is time being lost?â
II. When a foreign service warns: four instructive precedents
Cyber-security is not the only field in which receiving information and acting on it are different operations. The Thalys case, the 2015 terrorist attacks, intelligence before Russiaâs 2022 invasion of Ukraine and the 2017 MacronLeaks episode illustrate four different failure or success modes: transmission, interpretation, prioritisation and prepared response.
Thalys and the 2015 terrorist attacks
Parliamentary work revisited the case of Ayoub El-Khazzani, who had been signalled by Spanish services before boarding the AmsterdamâParis Thalys in August 2015. The sources do not show that French services had a simple operational opportunity to arrest him beforehand; they do show the difficulty of moving, harmonising and exploiting signals between European countries. [15]
âThe 2015 attacks represent a global intelligence failure.â â Patrick Calvar, then head of the DGSI [14]
Calvarâs formulation matters because it came from the head of the service itself. It does not mean that individual analysts or police officers failed to work. It means that a complex system can fail despite surveillance, information and cooperation. Criticising the decision chain is not the same as attacking the professionals who produce the warnings.
Ukraine 2022: the information existed, but interpretation diverged
Before Russiaâs invasion, the United States and United Kingdom adopted a much more alarmist reading of Russian force concentrations. French services had allied information but assessed Moscowâs intentions differently. After the invasion, Chief of Defence Staff Thierry Burkhard acknowledged publicly that the Americans had correctly anticipated the attack. [24]
âThe Americans said the Russians were going to attack; they were right.â â General Thierry Burkhard, March 2022 [24]
This precedent is about interpretation rather than transmission. Intelligence is not merely data; it must become an assessment and then a decision. Accurate information can lose operational value if filtered through an overly reassuring or rigid analytical frame.
MacronLeaks 2017: a counter-example in which preparation worked
For intellectual balance, the cases in which the chain works matter too. Before the 2017 French presidential election, warnings about influence operations and intrusion attempts led to stronger preparation. When emails and documents were released shortly before the second round, measures taken by authorities, media and the campaign helped limit the operationâs effect. [17]
That counter-example shows that international cooperation and intelligence are not inherently ineffective. They produce value when an alert is understood, responsibility is clear and measures are prepared before the incident.
III. What is intelligence for if the final kilometre of decision-making fails?
The DGSI defines intelligence gathering, centralisation and exploitation in support of national security and fundamental national interests as core missions. The national intelligence coordination structure exists to ensure coherence and inform the President. In cyber-security, ANSSI, CERT-FR, intelligence services, ministries, judicial authorities, operators, sector CSIRTs, European partners and allies already form a substantial ecosystem. [18][19][25][26]
The final kilometre of national security
The weak point can lie between detection and correction. An expert identifies an exposed interface; a note is escalated; a recommendation is published. Then somebody must decide who pays, who orders the shutdown, who replaces a twenty-year-old PLC, who checks the contractor, who verifies implementation and who accepts a temporary service interruption to prevent something worse. That is the final kilometre.
In water, fragmentation makes the problem particularly visible. The State can warn, while the physical correction may depend on a municipality, public utility, private concession holder, industrial contractor or locally voted budget.
Why invest so much in warning systems if the decision cycle remains slower than the attacker?
France employs analysts, engineers, police officers, soldiers, diplomats, magistrates and operational centres to detect threats early. That investment has value only if the information advantage buys time. Attackers do not need a budget vote, an inter-ministerial circular or a validation meeting before testing an exposed configuration. AI further reduces the cost of reconnaissance, script generation and adaptation. The problem is not only that attackers become more capable; their decision cycle can become far shorter than the defenderâs. [11]
If information arrives quickly but action arrives slowly, a State can become paradoxically better informed than before while still unable to reduce risk fast enough. The problem is then not absence of intelligence but organisation of political will.
IV. Can one speak of âpolitical incompetenceâ?
The expression is severe. Used as a blanket personal accusation, it would be intellectually lazy. Used as a political judgment about measurable governance results, it can be debated. Four objective elements make that debate legitimate: the Prime Ministerâs own admission of insufficient ministry cyber maturity; the Cour des comptesâ criticism of steering and resources; European infringement proceedings for delayed transposition; and ANSSIâs continuing need to repeat elementary hardening rules in 2026. [6][8][13]
None of those facts alone proves that âthe State is incompetentâ. Together they support a narrower claim: persistent governance, homogenisation and implementation failures can reasonably be described as political incompetence when decision-makers have warning, authority and time but do not obtain verified correction.
Do not blame the wrong people
This criticism should not be aimed indiscriminately at ANSSI engineers, DGSI personnel, police or military staff. The cited documents show that many of them are precisely the people raising alarms. Political responsibility begins where expertise fails to become prioritisation, resources, binding action and verification. [3][6][8][14]
V. Water, energy and industry directly concern the fundamental interests of the Nation
Article 410-1 of the French Criminal Code defines the fundamental interests of the Nation broadly, including security, protection of the population and essential elements of scientific and economic potential. Water concerns population safety; energy conditions economic continuity; industrial processes contribute to national productive capacity. [20]
A legal distinction is essential: saying that poor policy may expose the fundamental interests of the Nation is not the same as alleging that a public official has committed the criminal offence of attacking those interests. The dossier concerns political and administrative responsibility, not an accusation of crime.
VI. Questions the State should answer publicly
- How many industrial controllers used in French water and wastewater networks are still directly or indirectly reachable from the Internet?
- How many are protected only by mechanisms now regarded as insufficient or by default credentials?
- What national inventory exists for critical industrial controllers and how current is it?
- After the 30 July US warning, what checks were requested from French water operators?
- After the 19 August Siemens S7 alert, what instructions were transmitted to French operators, and how quickly?
- Were non-public technical indicators exchanged between US and French services?
- Who verifies implementation of ANSSI recommendations in small organisations outside the historical OIV perimeter?
- Who finances replacement of obsolete industrial controllers when small local authorities cannot?
- How many operators can switch safely to manual or degraded mode if supervision is compromised?
- Who has final responsibility for proving that an alert became a correction and that the correction was tested?
A generic statement that âservices are mobilisedâ is not an answer. The result is measured in eliminated exposure, intrusion-detection capability, service continuity and time to return to a safe state.
VII. Is anyone at the controls?
It would be false to write that the French State does nothing. France has a national cyber-security agency, powerful intelligence services, European and international cooperation, legal obligations and professionals working every day to reduce risk. The troubling fact is that this impressive architecture coexists with weaknesses its own institutions have described for years.
What worries is not the absence of reports, but their accumulation; not the absence of warnings, but their repetition; not the absence of cooperation, but uncertainty over how quickly information becomes verified field action. In a modern State, intelligence is supposed to buy time. If a known vulnerability must be exploited before the previously obvious arbitration is finally made, much of that intelligence advantage has been wasted.
We knew. So between the moment information reaches decision-makers and the moment the vulnerability is actually corrected, who is in charge?
Sources and references
Primary, institutional and press sources used in the dossier. Official titles are kept in their published language where useful.
- [1] LĂ©gifrance â Loi n° 2013-1168 du 18 dĂ©cembre 2013, chapitre relatif Ă la protection des infrastructures vitales contre la cybermenace.
- [2] LĂ©gifrance â ArrĂȘtĂ© du 17 juin 2016 relatif aux systĂšmes dâinformation dâimportance vitale du secteur « Gestion de lâeau ».
- [3] ANSSI / CERT-FR â Secteur de lâeau : Ă©tat de la menace informatique, CERTFR-2024-CTI-011, 28 novembre 2024.
- [4] Commission europĂ©enne â Recours du 8 juillet 2026 concernant la transposition de NIS 2 par la France et trois autres Ătats.
- [5] SĂ©nat â Projet de loi relatif Ă la rĂ©silience des infrastructures critiques et au renforcement de la cybersĂ©curitĂ©, dossier lĂ©gislatif.
- [6] Cour des comptes â La rĂ©ponse de lâĂtat aux cybermenaces sur les systĂšmes dâinformation civils, juin 2025.
- [7] Cybermalveillance.gouv.fr â Ătude 2024 sur la cybersĂ©curitĂ© des collectivitĂ©s territoriales de moins de 25 000 habitants.
- [8] ANSSI / CERT-FR â Recommandations Ă destination des acteurs des secteurs de lâĂ©nergie et de lâeau, CERTFR-2025-DUR-003.
- [9] Commission europĂ©enne â Paquet dâinfractions du 29 avril 2026 : saisine de la CJUE concernant la directive sur la rĂ©silience des entitĂ©s critiques.
- [10] FBI â Malicious cyber actors targeting water and wastewater sector Internet-facing PLCs, 30 juillet 2026.
- [11] WaterISAC â Joint Cybersecurity Advisory â Active Targeting of Siemens S7 PLCs, synthĂšse de lâalerte interagences amĂ©ricaine.
- [12] Reuters / Boursorama â RĂ©action de Siemens Ă lâalerte amĂ©ricaine : pas de hausse dĂ©tectĂ©e des attaques ni de vulnĂ©rabilitĂ© inconnue, 20 aoĂ»t 2026.
- [13] TF1 Info / AFP â SĂ©bastien Lecornu : « Peu de ministĂšres sont au niveau requis » en cybersĂ©curitĂ©, 19 aoĂ»t 2026.
- [14] AssemblĂ©e nationale â Rapport dâenquĂȘte relatif aux moyens mis en Ćuvre par lâĂtat pour lutter contre le terrorisme depuis le 7 janvier 2015.
- [15] AssemblĂ©e nationale â Audition sur la coopĂ©ration et le renseignement : cas du Thalys et signalement espagnol dâAyoub El-Khazzani.
- [16] AssemblĂ©e nationale â Rapport de suivi des conclusions de la commission dâenquĂȘte sur les attentats de 2015.
- [17] U.S. Senate / Congress â Rapport sur lâingĂ©rence russe et lâexpĂ©rience française lors de lâĂ©lection prĂ©sidentielle de 2017.
- [18] DGSI â PrĂ©sentation officielle des missions de la Direction gĂ©nĂ©rale de la sĂ©curitĂ© intĂ©rieure.
- [19] ĂlysĂ©e â Coordination nationale du renseignement et de la lutte contre le terrorisme : missions de coordination et dâaide Ă la dĂ©cision.
- [20] LĂ©gifrance â Code pĂ©nal, article 410-1 : dĂ©finition des intĂ©rĂȘts fondamentaux de la Nation.
- [21] CISA â Siemens SIMATIC S7-1200 CPUs, avis industriel du 21 janvier 2025.
- [22] CISA â Siemens SIMATIC S7-1200 et S7-1500 CPU Families : avis de sĂ©curitĂ© et recommandations dâisolement rĂ©seau.
- [23] AssemblĂ©e nationale â SĂ©ance du 5 mai 2026 : dĂ©bat sur les fragilitĂ©s cyber de lâĂtat aprĂšs lâattaque de lâANTS.
- [24] Le Monde â Entretien du gĂ©nĂ©ral Thierry Burkhard sur les divergences dâanalyse avant lâinvasion russe de lâUkraine, mars 2022.
- [25] ANSSI â Rapport dâactivitĂ© 2025 et coopĂ©ration avec les CSIRT français et europĂ©ens.
- [26] ANSSI â PrĂ©sidence française du groupe de travail cybersĂ©curitĂ© du G7 en 2026.

