Decoding the world of cybersecurity

· ·

France prepares critical infrastructure hybrid-threat plan

President Emmanuel Macron has ordered a plan to strengthen protection of French critical infrastructure and sensitive sites against cyber and drone attacks.

France prepares critical infrastructure hybrid-threat plan
Summary
  • Emmanuel Macron has directed the French government to prepare measures protecting critical infrastructure and sensitive defence and technology sites.
  • Macron says cyber operations, drones, and other hybrid activity attributed by France to Russia have intensified against Europe.
  • The development places cyber resilience alongside physical protection as France reassesses infrastructure exposure linked to the war in Ukraine.

France is preparing new measures to protect critical infrastructure and sensitive defence and technology sites against cyberattacks, drones, and other forms of hybrid activity, as the French government says threats linked to Russia are intensifying across Europe.

President Emmanuel Macron instructed the French government to draw up the plan following a meeting with political-party leaders at the Élysée Palace on 18 September.

Macron described a growing hybrid threat facing France and other European countries and said the activity includes cyber operations and drone incidents intended, in France’s assessment, to intimidate European governments and weaken their support for Ukraine.

Those claims about Russian responsibility remain French government attribution. Moscow’s responsibility for individual hybrid incidents varies by case, and the announcement does not establish that every cyber or drone incident cited by European governments is part of a single centrally directed campaign.

The French response nevertheless reflects how critical-infrastructure protection is moving beyond conventional distinctions between cyber and physical security. Energy, transport, communications, defence manufacturing, and technology sites increasingly depend on digital control systems while also facing threats to physical facilities and supply routes.

A drone incident around an airport, sabotage affecting fibre or energy infrastructure, and a cyberattack against an operator can produce different technical evidence while creating similar operational consequences: disruption, loss of capacity, uncertainty about attribution, and pressure on government response.

That convergence affects how resilience is planned. Operators cannot assume that continuity arrangements designed for malware will necessarily account for simultaneous physical disruption, while physical-security programmes may not cover the loss of digital control, communications, or supplier access during the same event.

France’s move also sits within a wider European effort to strengthen critical-entity resilience. EU rules including NIS2 and the Critical Entities Resilience framework place greater emphasis on risk management, incident handling, supply chain exposure, and continuity across sectors whose failure can have broad economic or societal effects.

Hybrid threats add a state-security dimension to those obligations. Organisations may be exposed not because they hold uniquely valuable data but because their disruption would create political, economic, or public-service pressure. Defence suppliers and technology companies can also become targets because of their place in wider industrial capacity rather than their individual scale.

Macron’s announcement did not set out the detailed controls, funding, or timetable that will form the final protection plan. Those decisions will determine whether the initiative changes operator requirements or mainly coordinates existing state capabilities.

The absence of detail also leaves open how France will divide responsibility between infrastructure operators and government agencies. Cyber incident response, counter-drone capability, intelligence sharing, physical security, law enforcement, and military responsibilities can involve different authorities even when they relate to the same facility.

France’s decision is therefore best read as the start of a resilience programme rather than a completed cyber policy. The government has identified critical infrastructure and sensitive industrial sites as a priority in its response to what it describes as an intensifying Russian hybrid threat; the substantive regulatory and operational consequences will depend on the measures now developed.

×