Decoding the world of cybersecurity

France strengthens ANSSI powers under REACTIV

France has strengthened ANSSI’s authority to direct urgent cyber measures across government departments as investigations continue into data breaches affecting state services.

France strengthens ANSSI powers under REACTIV
Summary
  • REACTIV strengthens ANSSI’s operational role in incidents affecting French ministries.
  • The agency can require ministries to implement urgent protective measures within constrained timeframes.
  • ANSSI says the current incident picture remains provisional because investigations are continuing.

France has strengthened the authority of its national cyber security agency to require emergency measures across government departments as the state responds to an intensifying series of account compromises and data breaches.

ANSSI said the REACTIV operation — Réponse & Action Interministérielle face aux Violations de données — was established after the French prime minister ordered a reinforced government response capability on 1 September.

The arrangement allows ANSSI to redirect operational resources immediately towards affected ministries, particularly for compromised user accounts and investigations into data breaches. The agency said the aim is to contain attacks more effectively and respond more rapidly to data exfiltration.

ANSSI’s authority has also been strengthened so it can require ministries to introduce urgent security measures within constrained timeframes where citizen data entrusted to public bodies is at risk. Technical crisis communications can be centralised through the agency when relevant attacks affect state services.

The change moves beyond a model in which a national cyber agency primarily provides guidance and incident-response assistance. During a serious compromise, the ability to require urgent action can reduce delays caused by fragmented departmental ownership, competing priorities, or uncertainty over who has authority to mandate disruptive containment measures.

That distinction becomes particularly important during identity-led incidents. A compromised administrative account may require immediate credential revocation, access restrictions, service changes, or other interventions that impose short-term disruption. Where individual ministries control timing independently, incident containment can compete with service availability and internal approval processes.

REACTIV sits alongside France’s 2026–2027 roadmap for priority digital-security improvements across the state, which departments have also been told to accelerate. The operation is therefore functioning both as an incident-response mechanism and as pressure for longer-term improvements in ministerial network security.

ANSSI has not presented its September report as a final account of the incidents behind the intervention. The agency explicitly says investigations remain under way, incidents are developing rapidly, and the associated figures can change.

That qualification is important because REACTIV addresses a wider pattern of government data exposure rather than one resolved breach with a settled cause or attacker attribution. Current figures should therefore be treated as an operational snapshot rather than a definitive measure of the affected systems or data.

The strengthened authority also reflects a wider European shift towards treating cyber resilience as an operational governance issue rather than one confined to individual IT teams. NIS2 and DORA place greater weight on responsibility, incident handling, continuity, testing, and remediation across regulated organisations. REACTIV applies a comparable logic inside government by reducing reliance on voluntary coordination once an incident reaches a sufficiently serious threshold.

Centralised crisis communication can address another recurring weakness in complex incidents. Different departments may initially hold incomplete evidence about affected accounts, systems, and data, while public statements can move ahead of forensic certainty. A single technical coordination point gives ANSSI greater control over how operational information is consolidated while investigations progress.

The trade-off is that stronger central intervention requires ANSSI to make rapid decisions across ministries with different systems, missions, and tolerance for interruption. Formal authority will only translate into resilience if departments can implement urgent measures quickly without losing the context needed to maintain essential services.

The September report remains provisional. The eventual scale, causes, and longer-term consequences of the incidents behind REACTIV are still subject to change as investigations continue.

×