Why French SMEs are still stuck in 1980 (and why that's partly their own fault)
Let me be blunt: you can't ask cybersecurity to move forward if some companies refuse to leave the minitel behind. And that's exactly what we still see today in most French SMEs. Yes, threats are evolving.

Let me be blunt: you can't ask cybersecurity to move forward if some companies refuse to leave the minitel behind. And that's exactly what we still see today in most French SMEs.
Yes, threats are evolving. Yes, AI is reshuffling the whole deck. Yes, attacks are becoming more complex, faster, more systemic. But what's the point of having this conversation if, on the other side, no one really understands what we're talking about?
The latest Cybermalveillance.gouv.fr barometer confirms it without any hedging: nearly three companies out of ten still consider cybersecurity a non-priority subject, and that proportion has actually risen by eleven points in a year. You don't build a defense on that foundation.
"Cyber what?": the cultural divide
In many SMEs, the word "cyber" still triggers three kinds of reaction:
- "That's the IT guy's job, isn't it?"
- "We're not a bank, why would anyone target us?"
- "I installed an antivirus and a firewall, we're fine."
You can't build a security strategy on willful ignorance.
The third reaction is the most revealing. In the 2025 barometer, 84% of companies say they have an antivirus and 69% a firewall, but only 26% have switched on multi-factor authentication. The result: 58% consider themselves well or very well protected, while at the same time 80% admit they don't feel ready to face an attack. The whole divide sits in those two contradictory figures.
Leaders who won't take five minutes to understand digital risks expose their company to something far worse than a data breach: they put their business at risk.
And no, the blame doesn't lie solely with politicians or the evil Russian hackers. The blame also lies in this chronic inability to question oneself, to learn, to adapt.

Is an SME really a target?
"We're not a bank." It's the sentence I hear most often, and it's the most dangerous one.
The figures say the opposite. In 2024, Cybermalveillance.gouv.fr handled more than 420,000 assistance requests, a rise of almost 50% in a single year, and phishing remains by far the leading threat reported by professionals, ahead of account hijacking and ransomware. In the 2025 barometer, 16% of the companies surveyed say they suffered at least one security incident over the past twelve months.
Attackers don't pick their victims one by one like in the movies. They automate, they cast a wide net, and a poorly protected SME is an open door that costs less to force than a large group. Believing you're too small to be targeted isn't a risk assessment, it's a bet. And 58% of business leaders admit they are unable to assess the real consequences of a cyberattack on their activity.
AI: gadget or threat for SMEs?
Let's talk about artificial intelligence. We now have tools capable of analyzing logs, detecting suspicious behavior, anticipating incidents, correlating weak signals in real time. In short: superpowers for teams that are often understaffed.
But in SMEs, we still have leaders who think ChatGPT is a gadget for the comms interns.
Meanwhile, the cybercriminals aren't burdened with skepticism: they're using AI at full throttle. Generating phishing, targeted attacks, automating intrusions... And it works. The signal is already in the figures: the share of victims who attribute their incident to phishing jumped from 24% in 2024 to 43% in 2025. Better written emails, better targeted, without the spelling mistake that used to give the scam away: that is what AI looks like when it switches sides.
The heart of the problem? The regulatory vise
Let's be clear: most SMEs don't refuse cybersecurity out of bad faith. They refuse because they can't do everything. When you impose on them:
- ever more complex compliance obligations,
- endless regulatory audits,
- deadlines that are impossible to meet without resources,
- and compliance costs that explode...
The barometer measures it in black and white: the top three obstacles cited by companies are the lack of knowledge or skills (63%), budget (61%) and lack of time (59%). And while we keep piling up requirements, 75% of very small and medium businesses invest less than 2,000 euros a year in their digital security. The gap between what we ask of them and what they can absorb has never been so wide.
The European NIS2 directive, which ANSSI presents as an unprecedented extension of the regulated perimeter, will bring thousands of entities that had been spared until now into scope, including many mid-sized companies and SMEs. The associated French framework, the ReCyF, was only published on 17 March 2026. In other words, the obligations were announced before anyone had written the instruction manual.
So no, the real problem isn't that Chantal clicked on a booby-trapped link. The real problem is that Chantal doesn't even know whether her salary will land at the end of the month. And that's where the State, the software vendors, the experts need to stop talking into the void. You don't build a culture of cybersecurity with PowerPoint slides and overpriced platforms. You build it by starting from the reality on the ground. And that reality is that SMEs are drowning.
So what do we do?
1. Train the leaders, not just the technicians. As long as a CEO doesn't understand what an attack surface, an intrusion vector or a continuity plan is, they won't steer anything. They'll be at the mercy of events.
2. Simplify, automate, pool. Cybersecurity must not be a luxury. We need tools designed for small and medium businesses: simple to deploy, manageable with few resources, and above all affordable. SaaS isn't enough if no one understands the dashboard.
3. Build local cyber-solidarity networks. What if local authorities funded "shared SOCs" among companies in the same economic area? Pooling costs, sharing intelligence, collective responses.
4. Rethink public funding. Subsidizing 30,000 euro audits for recommendations that end up in a drawer serves no purpose. Better to fund training, concrete tools, ongoing awareness.
In conclusion
SMEs are the heart of the French economy. But that heart still beats to a pre-digital rhythm.
So yes, cyberthreats are exploding. Yes, AI changes everything. But no, that's no reason to keep burying your head in the sand. Things need to move, and fast.
Cybersecurity must no longer be seen as a luxury or a burden, but as a lever for survival, resilience, and competitiveness.
And if you run an SME and you still think "cyber isn't for you"... then you probably need it even more than the rest.
Sources
- 2025 barometer of cyber maturity among very small and medium businesses (risk perception, equipment, budgets, obstacles, and the subject judged a non-priority by nearly three companies out of ten): Cybermalveillance.gouv.fr.
- Volume of assistance requests (more than 420,000, up almost 50%) and phishing as the leading threat reported by professionals: Cybermalveillance.gouv.fr, 2024 activity report.
- NIS2, an unprecedented extension of the regulated perimeter, and publication of the ReCyF framework on 17 March 2026: ANSSI, cyber.gouv.fr.
Frequently asked questions
Why do we say French SMEs are "stuck in 1980"?
Because they often cling to pre-digital reflexes: the word "cyber" triggers denial or delegation to the IT guy, whereas the threats themselves have changed radically. Nearly three companies out of ten now judge the subject a non-priority, a proportion up eleven points in a year according to Cybermalveillance.
Is an SME really a target for cyberattacks?
Yes. The "we're not a bank, why would anyone target us?" reflex is dangerous: attackers automate and cast a wide net. Cybermalveillance.gouv.fr handled more than 420,000 assistance requests in 2024, up almost 50% in a year, and 16% of companies say they suffered at least one incident over the past twelve months.
What are the most common cyberthreats for an SME?
Phishing comes far ahead of everything else among the threats reported by professionals, followed by account hijacking and ransomware. In the 2025 barometer, 43% of victims attribute their incident to phishing, against 24% a year earlier.
Is AI an asset or a threat for SME cybersecurity?
Both. It gives "superpowers" to understaffed teams (log analysis, detection of suspicious behavior), but cybercriminals are already exploiting it to generate credible phishing and automate their intrusions, which is exactly what the sharp rise in phishing as a cause of incident reflects.
How much does an SME invest in its cybersecurity?
Far too little: 75% of very small and medium businesses spend less than 2,000 euros a year on their digital security. The three most cited obstacles are the lack of knowledge or skills (63%), budget (61%) and lack of time (59%).
Does regulation help or penalize SMEs?
As applied, it often penalizes: complex compliance obligations, endless audits, unworkable deadlines and skyrocketing costs. The NIS2 directive will bring thousands of entities previously spared into the regulatory perimeter, including many mid-sized companies and SMEs, while the French ReCyF framework was only published on 17 March 2026.
What can actually be done to move things forward?
Train leaders and not just technicians, simplify and pool tools, fund shared SOCs among companies in the same economic area, and redirect public funding toward training and concrete tools rather than costly audits with no follow-up.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
