What If We Trained Hackers to Defend the Republic?
In France, we train engineers, lawyers, police officers, diplomats and teachers. But we still do not train, at scale, the very people already fighting the battles of the 21st century: hackers.

In France, we train engineers, lawyers, police officers, diplomats and teachers. But we still do not train, at scale, the very people already fighting the battles of the 21st century: hackers.
And yet this is precisely where part of our sovereignty, our collective resilience, and even our ability to build a digital society worthy of the name is decided.
Hackers are not the problem. They are the solution.
I have spent my career crossing paths with these atypical profiles. Some at conferences, others in informal groups, sometimes in more underground circles. Whether they work for CERTs, companies, institutions or in the shadows, they share a very particular relationship with the world: radical curiosity, an eye for detail, distrust of hierarchies, a love of the beauty hidden inside systems.
A good hacker is an artist. A composer of logic. Someone who sees what most people do not perceive. Someone who understands that a bug is not a mistake but a door.
And those doors need to be known, mapped and closed. Because while we debate in committee or in the boardroom, others are walking through them: hostile states, mafia groups, well-organized cybercriminals... they are not waiting for a ministry's green light.

Why does France lack cyber talent?
The problem is not theoretical. Globally, the 2025 ISC2 study puts the number of unfilled cybersecurity positions at close to 4.8 million. In France, the cybersecurity jobs observatory published by ANSSI in June 2025 records a 49% rise in job postings between 2019 and 2024, with employers still facing severe recruitment difficulties, and four postings out of ten requiring a five-year degree.
So we are hunting for rare, highly credentialed talent, at the very moment when those who have the raw aptitude are teaching themselves, very early, far from the official pathways. The pool exists. What is missing is the road.
Early talents, often on the margins
What worries me most is not the lack of cybersecurity skills. It is that those who naturally possess them have no official path to put them at the service of the common good.
We sometimes spot them as early as 13 or 14. They modify video games, build bots, tinker with scripts... And at that critical moment, two paths open before them: the path of recognition or the path of exclusion.
If we do not reach out to them, the cybercriminals will. They already do. Promising fun, money, a community. Sometimes simply by telling them: "We've seen you, you're gifted."
The British figures give the measure of the phenomenon. In February 2024, the National Crime Agency estimated that one child in five, aged 10 to 16, was already behaving in ways the Computer Misuse Act prohibits, the law that punishes unauthorised access to a computer system, rising to as many as one in four among those who game online. Across the Channel, the average age of a suspect in a cybercrime investigation is around 17. These teenagers are not hardened criminals: they are, precisely, the profiles the Republic would gain from spotting before someone else does.
When school fails to understand these profiles, when institutions label them as "outside the norm", they end up believing they have no place. When in reality, they may be our best chance.
And I say this from experience: I was one of them. I grew up in that culture. I learned by exploring, taking things apart, testing, sometimes breaking them, to understand, never to harm. What I found in that world was a form of freedom, of power, of meaning. And later, a mission.
Is the United Kingdom already showing the way?
The British project "The Hacking Games", in partnership with the Co-op, has understood this well: identifying these young hackers as early as their learning phase, steering them toward careers as ethical hackers, giving them a framework and mentors, is an investment in our national security.
Announced in July 2025, in the wake of the cyberattack that had hit the Co-op, the programme is built on prevention, early intervention and awareness. It rests on a research study entrusted to Professor Jonathan Lusthaus, of the University of Oxford, and on a first pilot inside the Co-op Academies Trust, which educates 20,000 pupils across 38 schools. The finding behind it is brutal: according to figures put forward by the Co-op, 69% of European teenagers are said to have already committed some form of online offence. And when the alleged perpetrators of the attacks on M&S, the Co-op and Harrods were arrested, in July 2025, they were aged between 17 and 20.
The United Kingdom does not stop there. For years the National Crime Agency has run a scheme, Cyber Choices, whose mission is precisely to divert these young people away from computer crime and redirect them toward legal careers. Spot them early, explain where play ends and an offence begins, open a door instead of slamming one: that is a public policy, not a club.
It is also a political answer to a social problem: giving a future to young people who are often marginalized, neuroatypical, or simply misunderstood. This is not an IT program, it is a public policy in its own right.
And where does France really stand?
Why not do the same in France?
France is not starting from zero. The Ministry of the Armed Forces, through its cyber defence command, and the Éducation nationale run "Passe ton Hack d'abord" every year, presented as the country's largest educational cyber challenge: the fourth edition, in early 2026, brought together close to 10,000 high school and university students, against more than 7,000 a year earlier. ANSSI, for its part, runs the France Cybersecurity Challenge, which selects the best French profiles. The stated ambition is clear: to bring out a new generation of cyber talent.
But a challenge, however successful, detects and celebrates talent for the length of a competition. It does not identify it from middle school, does not divert it from the cybercriminal temptation, does not walk alongside it year after year all the way to a job. That is the whole difference between an event and a pathway.
We have talent, schools, associations. We even have introductory clubs in some high schools and fablabs. But nothing that ties all of it into a genuine republican ambition: a continuous chain, from early spotting to professional integration.
What I propose
I do not settle for calling things out. Here is a concrete proposal:
Create a public program to identify, train and integrate young hackers, starting in middle school.
Tie this program to certifying pathways in cybersecurity, in collaboration with the Éducation nationale, ANSSI and the grandes écoles.
Bring together experts, ethical hackers, companies and researchers to create a national mentorship scheme, capable of passing on an ethic, a framework, a future.
Hacker culture is a form of resistance
Yes, hacker culture is subversive. It challenges the established order. It explores, it disturbs, it dares. But that is precisely why we need it.
If we want a digital Republic worthy of the name, we must bring hackers into our collective story. Not as exceptions or threats, but as pillars of a new digital humanism.
It is time to stop chasing after cyberattacks. Let us train the people who will know how to prevent them, understand them and counter them.
Before others enlist them.
Discover my appearances in the media and the press.
Sources
- The Hacking Games, "Co-op partners with The Hacking Games to help prevent future cybercrime", 16 July 2025.
- Infosecurity Magazine, "Co-op Aims to Divert More Young Hackers into Cyber Careers", July 2025.
- National Crime Agency, "One in five children found to engage in illegal activity online", February 2024.
- National Crime Agency, Cyber Choices programme.
- Help Net Security, "Four arrested in connection with M&S, Co-op ransomware attacks", 10 July 2025.
- ANSSI, "Publication de la 4e édition de l'Observatoire des métiers 2025", 9 June 2025.
- ISC2, 2025 Cybersecurity Workforce Study.
- French Ministry of the Armed Forces (COMCYBER), "Passe ton Hack d'abord, le plus grand challenge cyber de France".
- French Ministry of Education, "Passe ton Hack d'abord".
- ANSSI, France Cybersecurity Challenge.
Frequently asked questions
Why should we train hackers to defend the Republic?
Because they are already the ones fighting the digital battles of the 21st century, and part of our sovereignty and collective resilience is at stake there. Yet close to 4.8 million cybersecurity professionals are missing worldwide: without an official path, rare skills stay unused for the common good.
Does France already have a program for its young hackers?
Partly. The "Passe ton Hack d'abord" challenge, run by the cyber defence command and the Éducation nationale, brought together close to 10,000 high school and university students in early 2026, and ANSSI runs the France Cybersecurity Challenge. But these are detection and awareness competitions, not a continuous pathway of identification, training and integration starting in middle school.
What does the author propose in concrete terms?
Creating a public program to identify, train and integrate young hackers starting in middle school, tied to certifying pathways with the Éducation nationale, ANSSI and the grandes écoles, and supported by a national mentorship scheme that passes on an ethic and a framework.
Which foreign model is cited as an example?
The British project "The Hacking Games", in partnership with the Co-op and a research study from the University of Oxford, which identifies young hackers as early as their learning phase and steers them toward careers as ethical hackers. The United Kingdom also runs Cyber Choices, a public scheme that diverts young people away from computer crime.
At what age are these young talents spotted, and why do they slip to the wrong side?
They are often spotted as early as 13 or 14. In the United Kingdom, one child in five aged 10 to 16 already behaves in ways the Computer Misuse Act prohibits, and the average age of a cyber suspect is around 17. Misunderstood by school, they can come to believe they have no place; if the Republic does not reach out to them, the cybercriminals do, promising fun, money and community.
How many cybersecurity professionals are missing?
The 2025 ISC2 study puts the number of unfilled positions worldwide at close to 4.8 million. In France, ANSSI's jobs observatory records a 49% rise in job postings between 2019 and 2024, with severe recruitment difficulties and four postings out of ten requiring a five-year degree.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
