New year: what are your cybersecurity resolutions?
The new year gives us a chance to ask ourselves a simple, honest question about cybersecurity: am I ready for the digital world as it is today, or as I wish it were?

December 2025 was a dark month for cybersecurity in France.
A massive breach of files linked to the national police, threats to leak sensitive data, a leak of personal data at Leroy Merlin, attacks on universities such as Lille exposing student data... The incidents piled up at an alarming pace.
These events are a reminder of a simple but uncomfortable reality: no one is safe.
Not public institutions.
Not big companies.
Not ordinary citizens.
Digital tools, so convenient day to day, can tip into nightmare very fast. And it is precisely in this context that the new year comes at just the right moment to rethink our habits.
Every January, it is the same ritual.
We promise to hit the gym.
To eat better.
To scroll less.
And then there is everything else.
What we put off.
What we do not see.
What we would rather believe is "under control".
Cybersecurity is one of those blind spots.
Not because the subject is complicated.
But because it is invisible... until the day it suddenly becomes very concrete.
A bank card blocked.
An account hacked.
An email sent "by you" that you never wrote.
Personal data circulating without your knowing where, or why.
The new year gives us a chance to ask ourselves a simple, honest question:
am I ready for the digital world as it is today, or as I wish it were?

Should you really feel concerned by cyberattacks?
This is the first resolution, and the most important one.
It is also the most uncomfortable.
Most victims of cyberattacks are neither careless, nor naive, nor "bad with computers".
They are normal. Busy. Trusting. Tired.
Modern attacks no longer look like crude scams.
They look like everyday life.
A credible message.
A well-written email.
A request that arrives at just the right moment.
The figures confirm it. In 2024, the French public platform Cybermalveillance.gouv.fr handled more than 420,000 requests for assistance, up nearly 50% in a single year, and welcomed 5.4 million visitors looking for help. The leading threat for individuals remains phishing, with close to 64,000 requests for assistance, followed by account hacking, up 55%.
And behind every incident there are ordinary people. When the breach at the University of Lille came to light in late December 2025, the sample of data published already exposed close to 2,000 students: names, dates of birth, postal addresses, email addresses, phone numbers. Enough to fuel identity theft for years.
Accepting that no one is too small, too under the radar or too insignificant to be targeted is already a form of protection.
The incidents of late 2025 proved it: when even the police, universities or big retail chains get exposed, the "I have nothing worth stealing" argument no longer holds.
How do you take back control of your accounts and passwords?
We collect accounts the way we collect keys... without ever taking stock.
Emails, social networks, banks, streaming platforms, work tools, government services.
Every account is a door.
And far too often, those doors are poorly locked.
This is the second resolution, and the most concrete one.
Change your critical passwords.
Stop reusing the same one everywhere.
Turn on two-factor authentication where it exists.
These are not dramatic gestures.
But they are the ones that make the difference between a contained incident and a total disaster.
Account hacking is precisely the second biggest reason individuals in France ask for help, often because a single password, stolen somewhere else, opened several doors at once.

Convenience or security: do you really have to choose?
Digital tools have got us used to ease.
One click. A saved memory. A password stored "for later".
Except that convenience is often the silent enemy of security.
Saving your passwords everywhere.
Trusting your browser blindly.
Using the same device for everything, with no separation.
Taken individually, these choices seem harmless.
Added up, they create an enormous attack surface.
The massive leaks seen in recent months show just how much a small weakness can have big consequences.
Being secure is not about living in fear.
It is about accepting that every shortcut has a price, even if it is invisible at first.
Can you delegate your vigilance to security tools?
Antivirus software, filters, artificial intelligence, "smart" services.
All of it is useful.
But none of it thinks for you.
Tools assist.
They do not replace judgment.
A message can slip past every filter and still be dangerous.
A request can be technically legitimate and humanly suspicious.
Cybersecurity always starts with a simple question:
does this situation make sense?
Understand before you suffer
Most people simply endure the digital world.
They use tools they do not understand.
They accept terms they do not read.
They adapt after the fact.
Changing that does not require becoming an expert.
Just understanding the basic mechanisms:
how you are manipulated, how you are rushed, how you are pushed to click.
This is exactly the approach I wanted to convey in Être en cybersécurité.
Not a technical book.
A book about clear-sightedness.
Because the first firewall is not a piece of software.
It is your ability to recognize an abnormal situation.
The best resolution: stop putting it off
Incidents always come "at the wrong time".
When you are rushed.
Tired.
Already too busy.
Cybersecurity works the other way around:
what protects you are the decisions made before the problem.
Not after.
The new year is not a magic promise.
But it is a starting point.
Not to become perfect.
Just to become a little more aware.
And in a world where attacks are increasingly credible, automated and invisible,
being aware is already a form of protection.
Sources
- Cybermalveillance.gouv.fr 2024 activity report: 420,000 requests for assistance, phishing the leading threat for individuals, account hacking up 55%: Cybermalveillance.gouv.fr.
- Cyberattack on the French Interior Ministry servers, December 2025: franceinfo, and on the TAJ criminal records file: franceinfo.
- Customer data leak at Leroy Merlin: L'Usine Digitale, and the official Leroy Merlin FAQ.
- Student data leak at the University of Lille, December 2025, close to 2,000 students exposed: IT-Connect.
Frequently asked questions
Why should I feel concerned if 'I have nothing worth stealing'?
The incidents of late 2025 (police, universities, big retail chains) show that even the best-resourced players are exposed. Modern attacks look like everyday life and target normal people who are busy and trusting.
What is the number one threat for individuals in France?
According to the 2024 activity report from Cybermalveillance.gouv.fr, phishing remains the leading threat for individuals, with close to 64,000 requests for assistance, ahead of account hacking, which rose by 55%. The platform handled more than 420,000 requests for help over the year.
What concrete steps can I take to regain control of my accounts?
Change your critical passwords, stop reusing the same one everywhere, and turn on two-factor authentication where it is available. These simple steps make the difference between a contained incident and a disaster.
Are security tools enough to protect me?
No. Antivirus software, filters and AI are useful but do not replace judgment. A message can slip past every filter and still be dangerous; cybersecurity starts with the question: does this situation make sense?
Do I need to become an expert to be secure?
No. You only need to understand the basic mechanisms: how you are manipulated, how you are rushed, how you are pushed to click. The first firewall is not a piece of software but the ability to recognize an abnormal situation.
Where do I start if I am not tech-savvy?
With three habits anyone can adopt: unique passwords for your critical accounts, two-factor authentication wherever it exists, and the reflex of asking yourself 'does this situation make sense?' before you click. Security comes first from decisions made before the incident, not from sophisticated tools.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
