LESSON BEYOND FRANCE

France is used here as a documented warning, not as a caricature. Other countries should ask whether their own critical-infrastructure governance can turn a technical alert into a funded, verified correction before an attacker exploits the gap.

Foreword: the problem is no longer merely knowing, but acting

On 21 August 2026, Le Figaro highlighted an FBI warning about attacks on water networks and the risk of industrial failures in France. Read in isolation, the headline can look like a new threat imported from the United States. Read chronologically, it is the latest episode in a much longer story: France has had a legal framework for vital operators since 2013, water-sector security rules since 2016, ANSSI evidence of incidents and exposed industrial equipment, European resilience obligations, and repeated warnings about uneven maturity. Meanwhile, US agencies reported attacks on water PLCs with loss of pressure and flooding in July 2026, followed in August by an inter-agency alert on active targeting of Siemens S7 systems, including AI-assisted exploitation scripts. [1][2][3][4][9][10][11]

The political dimension became harder to dismiss on 19 August 2026, when Prime Minister Sébastien Lecornu publicly stated that few ministries were at the required cybersecurity level and asked ANSSI to create a new operational cyber unit. The same day, US agencies issued their Siemens S7 warning. This coincidence does not prove that the French government had suffered an S7 campaign; it shows that industrial threats were accelerating at the very moment the head of government acknowledged insufficient cyber maturity inside the State. [11][13]

METHOD AND LEGAL CAUTION

This dossier separates established facts, legitimate political questions and Delta-Sierra’s editorial judgment. When the word “incompetence” is used, it is a political assessment of governance, decision-making or implementation, not an allegation that every public employee has committed misconduct. The sources do not establish that the American Siemens S7 campaign has been observed in France; they establish an active US threat, comparable structural vulnerabilities in France and documented French compromises in water and energy. Those are three different propositions. [3][8][11][12]

A one-page chronology

DateEvent
2013Military Programming Law organises cyber protection of operators of vital importance. [1]
2016Specific security rules are introduced for vital water-sector information systems. [2]
2021–2024ANSSI handles events affecting 46 water-sector entities and documents recurring weaknesses. [3]
17 Oct 2024EU deadline for NIS2 and Critical Entities Resilience transposition. [4][9]
12 Mar 2025French Senate adopts the resilience/cyber bill at first reading. [5]
Jun 2025Cour des comptes calls for stronger inter-ministerial cyber steering. [6]
22 Jan 2026CERT-FR reports French compromises in water and energy and publishes hardening advice. [8]
29 Apr 2026European Commission refers France to the CJEU over critical-entity resilience. [9]
8 Jul 2026Further CJEU referral over incomplete NIS2 transposition. [4]
30 Jul 2026FBI reports attacks on US water PLCs with pressure losses and flooding. [10]
19 Aug 2026French PM acknowledges insufficient ministry maturity; US agencies warn about Siemens S7. [11][13]
20 Aug 2026Siemens says it sees no attack surge or unknown flaw; known configuration errors remain central. [12]
21 Aug 2026Industrial-failure risk enters mainstream French debate.

I. Thirteen years of alerts and rules: the scenario was not invisible

2013 and 2016: critical infrastructure and water were already treated as cyber-security issues

The 18 December 2013 Military Programming Law created specific obligations for protecting vital infrastructure from cyber threats and placed national coordination of information-system security under the Prime Minister. Three years later, a dedicated order established security and incident-reporting rules for information systems of vital importance in the water sector. These measures do not mean every future vulnerability was known; they mean that the risk of cyber compromise of essential services has been officially recognised for more than a decade. [1][2]

Water is especially difficult because responsibility is fragmented across municipalities, inter-municipal bodies, syndicates, public utilities, private operators, integrators and contractors. A national operator and a small local utility do not have the same engineers, budgets or capacity to replace industrial equipment that may be decades old.

2021–2024: French incidents were already real, not hypothetical

CERT-FR reported in November 2024 that 46 water-sector entities had been affected by IT events handled by ANSSI between January 2021 and August 2024. ANSSI described old installations, geographically dispersed sites, sometimes weak security budgets, highly uneven maturity and industrial interfaces reachable from the Internet. Remote management increases the attack surface; protocols designed historically for availability and simplicity may lack the authentication and encryption expected on today’s hostile Internet. [3]

Industrial control is different from ordinary office IT. A compromised interface can operate a pump, valve, chemical dose, tank level, pressure setpoint or motor. At that point, a cyber incident can become a physical event.

2024–2026: European deadlines, French delays and repeated warnings

NIS2 and the Critical Entities Resilience Directive were designed to broaden and harmonise cyber-security and continuity obligations. The transposition deadline was 17 October 2024. France did not complete transposition on time; infringement procedures eventually led to referrals to the Court of Justice in 2026. France was not the only Member State involved, but the proceedings objectively document delay on legislation directly connected to cyber-security and resilience. [4][9]

The Senate adopted the French resilience and cyber-security bill at first reading on 12 March 2025. In June 2025, the Cour des comptes called for stronger inter-ministerial steering, better programming of resources and greater involvement of public-sector leadership. This matters because an institution can have excellent engineers and analysts while remaining weak at governance: who has the authority, budget and timetable to make a vulnerability disappear? [5][6]

Cybermalveillance.gouv.fr also documented highly uneven preparation in smaller local authorities. That study does not prove that their water systems are insecure; it does document a structural difficulty in territorial cyber maturity. [7]

January 2026: ANSSI was still seeing compromises in water and energy

CERT-FR reported multiple French compromises in water and energy and again described Internet-accessible equipment, weak authentication, default credentials and exposed industrial protocols. It went as far as recommending local operation and disconnection from the Internet when minimum security measures could not be implemented. It also reported a case that stopped a wind farm for several hours. [8]

July and August 2026: cyber attacks produced physical effects in US water systems

On 30 July, the FBI and EPA warned of attacks against Internet-facing Rockwell Automation / Allen-Bradley MicroLogix PLCs in water and wastewater facilities. Attackers changed addresses and passwords and caused loss of visibility or control. The FBI reported loss of pressure and flooding; depending on circumstances, pressure loss can also create water-quality risks. The point is decisive: cyber compromise can alter the physical conditions of an essential service. [10]

On 19 August, NSA, CISA, FBI, DOE and EPA issued a joint warning about active targeting of Siemens S7 PLCs. The advisory described actors using Internet-scanning services and AI-generated or AI-assisted exploitation scripts, sometimes disguised as legitimate monitoring tools. Water, energy, manufacturing, chemicals and food were among the affected sectors. Siemens then provided an essential counterpoint: it said it had not observed a surge in attacks or an unknown vulnerability, and stressed known configuration weaknesses. That nuance should not be lost; the issue is not a secret universal Siemens flaw, but the persistence of exposure, obsolete configurations and weak hardening. [11][12]

THE QUESTION THAT CHANGES

The debate is no longer “could we have known?” but “we already knew a great deal; between the technical alert, political arbitration, funding and field verification, where is time being lost?”

II. When a foreign service warns: four instructive precedents

Cyber-security is not the only field in which receiving information and acting on it are different operations. The Thalys case, the 2015 terrorist attacks, intelligence before Russia’s 2022 invasion of Ukraine and the 2017 MacronLeaks episode illustrate four different failure or success modes: transmission, interpretation, prioritisation and prepared response.

Thalys and the 2015 terrorist attacks

Parliamentary work revisited the case of Ayoub El-Khazzani, who had been signalled by Spanish services before boarding the Amsterdam–Paris Thalys in August 2015. The sources do not show that French services had a simple operational opportunity to arrest him beforehand; they do show the difficulty of moving, harmonising and exploiting signals between European countries. [15]

“The 2015 attacks represent a global intelligence failure.” — Patrick Calvar, then head of the DGSI [14]

Calvar’s formulation matters because it came from the head of the service itself. It does not mean that individual analysts or police officers failed to work. It means that a complex system can fail despite surveillance, information and cooperation. Criticising the decision chain is not the same as attacking the professionals who produce the warnings.

Ukraine 2022: the information existed, but interpretation diverged

Before Russia’s invasion, the United States and United Kingdom adopted a much more alarmist reading of Russian force concentrations. French services had allied information but assessed Moscow’s intentions differently. After the invasion, Chief of Defence Staff Thierry Burkhard acknowledged publicly that the Americans had correctly anticipated the attack. [24]

“The Americans said the Russians were going to attack; they were right.” — General Thierry Burkhard, March 2022 [24]

This precedent is about interpretation rather than transmission. Intelligence is not merely data; it must become an assessment and then a decision. Accurate information can lose operational value if filtered through an overly reassuring or rigid analytical frame.

MacronLeaks 2017: a counter-example in which preparation worked

For intellectual balance, the cases in which the chain works matter too. Before the 2017 French presidential election, warnings about influence operations and intrusion attempts led to stronger preparation. When emails and documents were released shortly before the second round, measures taken by authorities, media and the campaign helped limit the operation’s effect. [17]

That counter-example shows that international cooperation and intelligence are not inherently ineffective. They produce value when an alert is understood, responsibility is clear and measures are prepared before the incident.

III. What is intelligence for if the final kilometre of decision-making fails?

The DGSI defines intelligence gathering, centralisation and exploitation in support of national security and fundamental national interests as core missions. The national intelligence coordination structure exists to ensure coherence and inform the President. In cyber-security, ANSSI, CERT-FR, intelligence services, ministries, judicial authorities, operators, sector CSIRTs, European partners and allies already form a substantial ecosystem. [18][19][25][26]

The final kilometre of national security

The weak point can lie between detection and correction. An expert identifies an exposed interface; a note is escalated; a recommendation is published. Then somebody must decide who pays, who orders the shutdown, who replaces a twenty-year-old PLC, who checks the contractor, who verifies implementation and who accepts a temporary service interruption to prevent something worse. That is the final kilometre.

In water, fragmentation makes the problem particularly visible. The State can warn, while the physical correction may depend on a municipality, public utility, private concession holder, industrial contractor or locally voted budget.

Why invest so much in warning systems if the decision cycle remains slower than the attacker?

France employs analysts, engineers, police officers, soldiers, diplomats, magistrates and operational centres to detect threats early. That investment has value only if the information advantage buys time. Attackers do not need a budget vote, an inter-ministerial circular or a validation meeting before testing an exposed configuration. AI further reduces the cost of reconnaissance, script generation and adaptation. The problem is not only that attackers become more capable; their decision cycle can become far shorter than the defender’s. [11]

If information arrives quickly but action arrives slowly, a State can become paradoxically better informed than before while still unable to reduce risk fast enough. The problem is then not absence of intelligence but organisation of political will.

IV. Can one speak of “political incompetence”?

The expression is severe. Used as a blanket personal accusation, it would be intellectually lazy. Used as a political judgment about measurable governance results, it can be debated. Four objective elements make that debate legitimate: the Prime Minister’s own admission of insufficient ministry cyber maturity; the Cour des comptes’ criticism of steering and resources; European infringement proceedings for delayed transposition; and ANSSI’s continuing need to repeat elementary hardening rules in 2026. [6][8][13]

None of those facts alone proves that “the State is incompetent”. Together they support a narrower claim: persistent governance, homogenisation and implementation failures can reasonably be described as political incompetence when decision-makers have warning, authority and time but do not obtain verified correction.

Do not blame the wrong people

This criticism should not be aimed indiscriminately at ANSSI engineers, DGSI personnel, police or military staff. The cited documents show that many of them are precisely the people raising alarms. Political responsibility begins where expertise fails to become prioritisation, resources, binding action and verification. [3][6][8][14]

V. Water, energy and industry directly concern the fundamental interests of the Nation

Article 410-1 of the French Criminal Code defines the fundamental interests of the Nation broadly, including security, protection of the population and essential elements of scientific and economic potential. Water concerns population safety; energy conditions economic continuity; industrial processes contribute to national productive capacity. [20]

A legal distinction is essential: saying that poor policy may expose the fundamental interests of the Nation is not the same as alleging that a public official has committed the criminal offence of attacking those interests. The dossier concerns political and administrative responsibility, not an accusation of crime.

VI. Questions the State should answer publicly

A generic statement that “services are mobilised” is not an answer. The result is measured in eliminated exposure, intrusion-detection capability, service continuity and time to return to a safe state.

VII. Is anyone at the controls?

It would be false to write that the French State does nothing. France has a national cyber-security agency, powerful intelligence services, European and international cooperation, legal obligations and professionals working every day to reduce risk. The troubling fact is that this impressive architecture coexists with weaknesses its own institutions have described for years.

What worries is not the absence of reports, but their accumulation; not the absence of warnings, but their repetition; not the absence of cooperation, but uncertainty over how quickly information becomes verified field action. In a modern State, intelligence is supposed to buy time. If a known vulnerability must be exploited before the previously obvious arbitration is finally made, much of that intelligence advantage has been wasted.

CONCLUSION

We knew. So between the moment information reaches decision-makers and the moment the vulnerability is actually corrected, who is in charge?

Sources and references

Primary, institutional and press sources used in the dossier. Official titles are kept in their published language where useful.

  1. [1] LĂ©gifrance — Loi n° 2013-1168 du 18 dĂ©cembre 2013, chapitre relatif Ă  la protection des infrastructures vitales contre la cybermenace.
  2. [2] LĂ©gifrance — ArrĂȘtĂ© du 17 juin 2016 relatif aux systĂšmes d’information d’importance vitale du secteur « Gestion de l’eau ».
  3. [3] ANSSI / CERT-FR — Secteur de l’eau : Ă©tat de la menace informatique, CERTFR-2024-CTI-011, 28 novembre 2024.
  4. [4] Commission europĂ©enne — Recours du 8 juillet 2026 concernant la transposition de NIS 2 par la France et trois autres États.
  5. [5] SĂ©nat — Projet de loi relatif Ă  la rĂ©silience des infrastructures critiques et au renforcement de la cybersĂ©curitĂ©, dossier lĂ©gislatif.
  6. [6] Cour des comptes — La rĂ©ponse de l’État aux cybermenaces sur les systĂšmes d’information civils, juin 2025.
  7. [7] Cybermalveillance.gouv.fr — Étude 2024 sur la cybersĂ©curitĂ© des collectivitĂ©s territoriales de moins de 25 000 habitants.
  8. [8] ANSSI / CERT-FR — Recommandations Ă  destination des acteurs des secteurs de l’énergie et de l’eau, CERTFR-2025-DUR-003.
  9. [9] Commission europĂ©enne — Paquet d’infractions du 29 avril 2026 : saisine de la CJUE concernant la directive sur la rĂ©silience des entitĂ©s critiques.
  10. [10] FBI — Malicious cyber actors targeting water and wastewater sector Internet-facing PLCs, 30 juillet 2026.
  11. [11] WaterISAC — Joint Cybersecurity Advisory – Active Targeting of Siemens S7 PLCs, synthĂšse de l’alerte interagences amĂ©ricaine.
  12. [12] Reuters / Boursorama — RĂ©action de Siemens Ă  l’alerte amĂ©ricaine : pas de hausse dĂ©tectĂ©e des attaques ni de vulnĂ©rabilitĂ© inconnue, 20 aoĂ»t 2026.
  13. [13] TF1 Info / AFP — SĂ©bastien Lecornu : « Peu de ministĂšres sont au niveau requis » en cybersĂ©curitĂ©, 19 aoĂ»t 2026.
  14. [14] AssemblĂ©e nationale — Rapport d’enquĂȘte relatif aux moyens mis en Ɠuvre par l’État pour lutter contre le terrorisme depuis le 7 janvier 2015.
  15. [15] AssemblĂ©e nationale — Audition sur la coopĂ©ration et le renseignement : cas du Thalys et signalement espagnol d’Ayoub El-Khazzani.
  16. [16] AssemblĂ©e nationale — Rapport de suivi des conclusions de la commission d’enquĂȘte sur les attentats de 2015.
  17. [17] U.S. Senate / Congress — Rapport sur l’ingĂ©rence russe et l’expĂ©rience française lors de l’élection prĂ©sidentielle de 2017.
  18. [18] DGSI — PrĂ©sentation officielle des missions de la Direction gĂ©nĂ©rale de la sĂ©curitĂ© intĂ©rieure.
  19. [19] ÉlysĂ©e — Coordination nationale du renseignement et de la lutte contre le terrorisme : missions de coordination et d’aide Ă  la dĂ©cision.
  20. [20] LĂ©gifrance — Code pĂ©nal, article 410-1 : dĂ©finition des intĂ©rĂȘts fondamentaux de la Nation.
  21. [21] CISA — Siemens SIMATIC S7-1200 CPUs, avis industriel du 21 janvier 2025.
  22. [22] CISA — Siemens SIMATIC S7-1200 et S7-1500 CPU Families : avis de sĂ©curitĂ© et recommandations d’isolement rĂ©seau.
  23. [23] AssemblĂ©e nationale — SĂ©ance du 5 mai 2026 : dĂ©bat sur les fragilitĂ©s cyber de l’État aprĂšs l’attaque de l’ANTS.
  24. [24] Le Monde — Entretien du gĂ©nĂ©ral Thierry Burkhard sur les divergences d’analyse avant l’invasion russe de l’Ukraine, mars 2022.
  25. [25] ANSSI — Rapport d’activitĂ© 2025 et coopĂ©ration avec les CSIRT français et europĂ©ens.
  26. [26] ANSSI — PrĂ©sidence française du groupe de travail cybersĂ©curitĂ© du G7 en 2026.