Open letter to Emmanuel Macron. Cybersecurity is not a technical subject. It is a duty of the State.
Mr President Macron. I am not writing to plead a cause. I am writing because it is time to stop pretending.

Mr President Macron,
I am not writing to plead a cause. I am writing because it is time to stop pretending.
For more than ten years, cyberattacks have multiplied. Hospitals, local authorities, ministries, strategic companies: no one is spared.
Every time, resources are announced. Committees. Roadmaps. Millions. But on the ground, public bodies have neither the tools, nor the people, nor the training. They improvise. They wait. And they take the hit.
Meanwhile, the threat grows. In 2024, the public platform Cybermalveillance.gouv.fr alone recorded more than 420,000 requests for assistance, close to 50% more than a year earlier. And not only on the side of the cybercriminals. The threat is also political, industrial, cultural.
Why is cybersecurity a matter of sovereignty?
You cannot talk about a strategy of independence while depending on foreign clouds to host our public data.
You cannot talk about digital education while leaving teachers without support or any culture of data protection.
You cannot talk about a "startup nation" if the critical tools of young companies rest on American infrastructure, with no plan B.
There is no digital power without an ethic of security. And that ethic is not confined to the experts. It must be visible, active, taken on at the highest level of the State.

Are hospitals and local authorities really that defenceless?
These are not hypotheses. In August 2022, the Centre Hospitalier Sud-Francilien in Corbeil-Essonnes was hit by the LockBit 3.0 ransomware. According to the post-mortem of the attack, the attacker got in through a compromised third-party account that gave access to the hospital's VPN, stayed inside the system for about ten days, disabled the protections, exfiltrated the data, then encrypted everything. Nothing exotic: a badly guarded door.
And the case is not isolated. In 2024, ransomware ranked second among the threats recorded by Cybermalveillance.gouv.fr for local authorities. Town halls, care services and schools are the ones going down, often for want of one measure that no one judged to be a priority.
Leaving hospitals running Windows 7, town halls dependent on an untrained IT person who also happens to be the local cemetery gardener (a true story), or entire local authorities in the cloud without understanding what they are doing, is not a technical problem.
It is a political failing.
What does French law say about cybersecurity?
Cybersecurity can no longer remain a subject walled off among experts. It has to be placed at the heart of the national strategy, on the same footing as health, defence or energy.
It already appears, to some extent, in the 2024-2030 Military Programming Law (law of 1 August 2023): in early 2024, ANSSI put out for public consultation a draft decree imposing new obligations on internet access providers, hosting providers, software publishers and data centre operators.
At European level, the NIS2 directive (Directive (EU) 2022/2555 of 14 December 2022) extends these requirements to thousands of public and private entities, from the health sector to public administrations. France is transposing it through the Resilience bill, and ANSSI published its framework of measures, the ReCyF, on 17 March 2026.
So the framework exists, on paper. But despite these European directives and regulations, France is still struggling to find a way to Être en Cybersécurité.
This means acknowledging the gap between the rhetoric and the reality, and agreeing to overhaul what is not working:
- Elected officials' lack of interest in subjects deemed "too technical".
- Systematic outsourcing without verification.
- Steering by announcement effect.
You have the responsibility to change the framework, not to tweet in reaction
When a cyberattack hits a hospital or an administration, it is too late to make promises. Action was needed beforehand. Planning. Support. Anticipation.
What I am asking of you is not an additional budget. It is a clear, stable, public course. It is a form of steering that lasts longer than a single five-year term. It is a recognition of the fact that digital is not a tool: it is a vital infrastructure.
And like any infrastructure, it must be maintained, protected, monitored. Not only at the moment when everything breaks.
Mr President, if you want to be taken seriously on sovereignty, start with digital security
I am not asking you to understand the technical side. But to surround yourself with those who do understand it and whose sole ambition is not to tick boxes.
I am not asking you to become an expert. But to stop treating the experts as invisible technicians.
And above all, I am not asking you to talk about cyber. I am asking you to act as if France also existed in the digital world.
Because it already does. And for now, it is very much alone.
So start with the concrete.
Make cybersecurity a visible, owned, funded priority. Not through abstract billions, but through resources where they are truly missing: in the town halls, the hospitals, the schools. Where digital does not make anyone dream, but keeps things standing.
Impose a minimum sovereignty requirement on public procurement, give power back to on-the-ground IT departments, and train elected officials the way we train for civil protection: because they are the first links in the chain.
And above all, stop pitting the ground against the digital.
Yes, repairing a road is visible. Yes, securing Chantal's workstation does not make a nice photo. But both protect lives. Both fall (indirectly) under the responsibility of the State.
It is not about choosing between the tarmac and the cloud. It is about understanding that sovereignty, today, runs through both.
Sources
- Cybermalveillance.gouv.fr, 2024 activity report (more than 420,000 requests for assistance, +49.9% year on year): cybermalveillance.gouv.fr.
- Post-mortem of the cyberattack on the Centre Hospitalier Sud-Francilien (LockBit 3.0 ransomware, August 2022): LeMagIT.
- Cyber measures of the 2024-2030 Military Programming Law, draft decree under public consultation: ANSSI (cyber.gouv.fr).
- Directive (EU) 2022/2555 (NIS2) of 14 December 2022: EUR-Lex.
- Transposition of NIS2 in France (Resilience bill) and the ReCyF framework published on 17 March 2026: ANSSI (cyber.gouv.fr).
Frequently asked questions
Why does the author consider cybersecurity a matter of sovereignty?
Because you cannot claim digital independence while depending on foreign clouds to host public data. For him, there is no digital power without an ethic of security taken on at the highest level of the State.
What is the author concretely asking of the president?
Not an additional budget, but a clear, stable and public course that lasts longer than a single five-year term, resources where they are missing (town halls, hospitals, schools), a minimum sovereignty requirement in public procurement and training for elected officials.
Are hospitals and local authorities really exposed to cyberattacks?
Yes. In August 2022, the Centre Hospitalier Sud-Francilien in Corbeil-Essonnes was hit by the LockBit 3.0 ransomware, the attacker having got in through a third-party account that gave access to the hospital's VPN. And in 2024, ransomware ranked second among the threats targeting local authorities according to Cybermalveillance.gouv.fr.
Has France transposed the European NIS2 directive?
Cybersecurity already features in the 2024-2030 Military Programming Law, and the NIS2 directive (Directive (EU) 2022/2555) is being transposed through the Resilience bill: ANSSI published its framework of measures, the ReCyF, on 17 March 2026. The framework therefore exists, but the author believes France is still struggling to make it live on the ground.
What dysfunctions does the article point to?
Elected officials' lack of interest in subjects deemed too technical, systematic outsourcing without verification, and steering by announcement effect.
Is cybersecurity really the responsibility of the State?
For the author, yes. Digital is a vital infrastructure which, like a road or an energy network, must be maintained, protected and monitored continuously, and not only at the moment when everything breaks. Securing the workstation of a public servant protects lives just as much as repairing a road.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
