Summary
- Prime Minister Sébastien Lecornu has ordered a new frontline response capability involving ANSSI personnel.
- The unit is intended to intervene when serious compromise of state information systems is suspected.
- Its creation follows repeated intrusions affecting French government systems, including the tax administration.
The French government has ordered the creation of a frontline cyber unit intended to respond more quickly when serious attacks threaten state information systems.
Prime Minister Sébastien Lecornu instructed the General Secretariat for National Defence and Security to establish a contact team made up of personnel from France’s National Cybersecurity Agency, ANSSI. The unit is intended to intervene at the first indication of a serious compromise and provide a stronger operational response while an incident is being investigated and contained.
The government gave officials until Friday to propose the unit’s organisation, rules of engagement, leadership and budget. The compressed timetable follows a series of incidents affecting French ministries and public bodies, including repeated compromises of the tax administration and a recent security incident involving the education ministry.
Lecornu has acknowledged shortcomings in the security maturity of parts of central government. His intervention follows an earlier order for ANSSI to conduct a detailed audit of the tax administration breach and accelerate a wider programme to strengthen state information systems.
ANSSI already provides national incident-response expertise through its existing structures, including CERT-FR. The new unit is therefore less about creating a cyber authority from scratch than about changing how specialist capability is brought into a developing government incident.
That distinction is operationally important. Major public-sector compromises can involve departmental security teams, outsourced providers, national authorities, investigators and senior officials, each with different responsibilities. Technical expertise may be available while decisions over containment, evidence preservation and service restoration still move too slowly between organisations.
A first-response model can reduce that fragmentation if the unit receives clear authority to establish incident command, coordinate investigation and remain engaged until affected services are stabilised. Its effectiveness will depend on the rules Lecornu has requested, including the threshold for intervention and the relationship between the new team and security personnel already embedded inside ministries.
The government’s recent incidents also demonstrate why recovery cannot be measured solely by whether an affected website returns online. Compromise of administrative systems can expose financial, identity and professional information long after immediate service disruption has ended, while stolen data may support subsequent fraud and targeted social engineering.
European public bodies face increasing expectations around resilience, incident reporting and accountability, but central government environments remain difficult to secure uniformly. Ministries can operate large technology estates with different suppliers, security controls and levels of technical debt, making a single national baseline difficult to enforce in practice.
The proposed unit gives Paris another mechanism for dealing with that unevenness during a crisis. The harder question will be whether the same weaknesses that make emergency intervention necessary are addressed before the next incident occurs.
France has already committed resources to a broader state cyber-security plan. The new unit will provide an early indication of whether the government can convert those strategic commitments into faster operational control when an intrusion is under way.





