A data breach is often described as an IT incident. That holds for a few hours. After that, the whole company is dealing with it, and under pressure.
The attacker may have needed very little time. On your side, you will have to understand, decide, notify, fix and reassure, from the very first hours and then for days, often weeks.
Security is therefore not only about keeping intruders out. It is also about deciding what an intruder would find if they got in anyway, and exactly what you would do, in what order.
What a breach sets in motion
The starting point is often mundane. Unusual activity in the logs, a message from a third party flagging an anomaly, a message from a hacker demanding a ransom in bitcoin, a file spotted where it should not be.
Very quickly, the questions arrive in no particular order, and almost all of them are urgent, and you find yourself under mounting pressure.
- Is the intruder still there, and should a service be shut down at the risk of halting operations?
- Which data was viewed or copied, since when, and how many people are affected?
- How do you investigate without erasing the traces the complaint and the insurer will need?
- Do you need to notify, and what do you tell customers, partners and staff?
- Who answers the phone, and who keeps the rest of the business running?
The guide for business leaders published by Cybermalveillance.gouv.fr, the French government's cyber victim assistance platform, sets out this path. Preserve the evidence, set up a crisis unit, alert the insurer, file a complaint, communicate transparently.
If personal data is compromised, the CNIL, France's data protection authority, must be notified within 72 hours. The clock therefore starts before you have all the answers.
The same guide asks leaders to take into account an aspect that is often overlooked. A cyberattack can cause “an exceptional overload of activity and a feeling of shock, humiliation, incompetence, even guilt”.
This is probably the most underestimated point. Decisions are made with incomplete information, and responsibility does not stop at 6 pm.
None of this is improvised well on the day. Knowing in advance who decides, who notifies and where the logs are shortens every one of these steps.
The people exposed live with the aftermath, often for longer
A breach has other victims than the company attacked: the people whose data is now circulating elsewhere.
Cybermalveillance.gouv.fr saw requests for help from individuals over data breaches rise by 107% in 2025. The data involved is often ordinary: name, address, phone number, sometimes bank details.
It then feeds personalised phishing, fake bank adviser scams, transfer fraud or identity theft. It gives the fraudster what they were missing: credibility.
A message that mentions your last order or your usual supplier is nothing like crude spam. It looks like the normal relationship, and that is what makes it work.
The effects travel back to the company the data came from. In a survey published by the CNIL in November 2025, 41% of respondents say they have already suffered fraudulent use of their data.
More telling still, 57% of those who suffered harm over the past three years gave up a digital service.
A stolen database therefore does not end the attack. It often fuels the next ones, and lost trust comes back far more slowly than a restarted server.
AI lowers the cost of a personalised attack
Personalising an attack used to take human time. Identifying a target's executives, staff and suppliers, then building a credible scenario, was not done on an assembly line.
What is already observed
That cost is falling. ANSSI, France's national cybersecurity agency, finds that generative AI is already used to profile victims, design social engineering content and develop malware.
For the most advanced attackers, the agency says, it is “a tool for gaining performance and scaling up”.
The DGSI, France's domestic intelligence service, describes the same shift on the business side. AI tools quickly analyse a target's public and private data to personalise the attack, or produce fake websites and deepfakes.
It recounts the case of an industrial site manager called on video by someone posing as the head of the group, face and voice included. The caller was asking for a funds transfer. The manager had the right reflex: end the call and check through the usual channels.
What is taking shape
The French Ministry of the Interior looks further ahead. Its 2026 annual report on cybercrime includes a section titled “The development of agentic artificial intelligence: towards autonomous attacks”.
It describes agents able to analyse a target, identify vulnerabilities, test several intrusion techniques and adjust their strategy to the defences they encounter.
Some perspective is needed. In February 2026, ANSSI stated that no generative AI system, “official or jailbroken”, had carried out every step of an attack on its own.
So the threat is not a fully automated attack in every case. The trajectory is nonetheless clear: more and more steps are becoming automatable, personalisable and repeatable at scale.
AI does not necessarily invent new attacks. Above all, it makes it possible to apply known attacks to far more targets, faster, with more precision.
Hence an asymmetry. The attacker automates reconnaissance, writing and follow-ups. The company hit still has to mobilise executives, technical staff, a lawyer, an insurer and a customer service team.
The ministry's report notes that this race sharpens “the asymmetry between attackers and defenders”. It cannot be offset with human hours. It is reduced upstream, by limiting what there is to find.
Your website has often become an information system without you being aware of it
Many companies still talk about “their website”. The word keeps the memory of a shop window, while the platform has taken on other roles over the years.
Look at what it really contains. You will often find:
- Years of order and invoice history.
- Thousands of accounts, including those of customers who left long ago.
- Attachments uploaded through forms: contracts, ID documents, job applications.
- Bank details or financial information.
- CSV exports generated for a one-off need, then forgotten on the server.
Each of these elements is legitimate. It met a real need at a given moment. Put together, though, they turn the platform into an information system exposed to the internet.
A word of caution along the way. Under the GDPR, “sensitive data” refers to specific categories, such as health, biometrics or political opinions.
Your database may contain none of it. A file combining name, email, phone number and purchase history is still enough to set up a credible fraud. The better question is: which data, once out, would help deceive someone?
The first form of control comes down to three questions. Where does this data live, who can access it, and how long has it been there?
Protect access, then limit what one account can open
The basic measures remain essential: updates, multi-factor authentication, web application firewall, encryption, backups, logging, monitoring, regular security testing.
Each makes an intrusion less likely, or faster to detect. None makes a system connected to the internet invulnerable.
We prefer to be clear on this point. The idea of a system that is “100% protected” is reassuring. It makes you forget the next question, though: what can a single compromised account reach?
The sanction imposed by the CNIL on Hôpital privé de la Loire, a private hospital, on September 3, 2026, gives a precise illustration. External access to the electronic patient record was protected neither by a VPN nor by multi-factor authentication.
Above all, a single account's rights opened the records of every patient. The attacker explored the system for several days. The data of 524,867 patients and 202,246 designated trusted contacts was accessed.
Among other things, the CNIL criticised an authorisation policy that did not restrict access by care team. Restricting rights does not remove the risk of intrusion. It reduces what an intrusion can carry away.
Keeping less means exposing less
One last lever is rarely filed under cybersecurity: the amount of data you keep. Deleted data can no longer be exfiltrated.
The sanction against Free and Free Mobile, two French telecom operators, in January 2026, shows this well. The intrusion concerned 24 million subscriber contracts, including the IBAN of some of them.
Among the failings identified, one point deserves attention. Free Mobile had kept “millions of items of its subscribers' data, without justification, for an excessive period”.
This finding is separate from the intrusion itself. Yet it says what matters most: data that has become useless keeps creating risk for as long as it exists.
The CNIL makes the point in its guidance on retention periods: personal data “cannot be kept indefinitely”. The period is set according to the purpose, then data leaves the active database for intermediate archiving, before deletion.
The subject carries growing weight. According to its 2025 annual report, in 2026 the CNIL is devoting half of its inspections and enforcement actions to cybersecurity failings.
In practice, this comes down to a few very down-to-earth decisions.
- A retention period for each type of data, written down, tied to a purpose and enforced by automatic purging.
- Inactive accounts closed, then deleted or anonymised once the set period is over.
- Attachments and exports given their own expiry date.
- Archives moved out of the active database, so they can no longer be read from the web application.
- Access rights kept to what is strictly needed, so that one compromised account does not open the whole database.
The test to run on your own application
This test requires no tool. It starts from one assumption: tomorrow, someone exports everything your application lets them read.
Then ask these questions, ideally with the person who knows the database best.
- How many people would be affected, and across how many years of history?
- Which documents would go with it, and how many contain an IBAN or an ID document?
- Who would need to be notified, and who would have to drop their work to handle the aftermath?
- What would the consequences be for you, in cost, in reputation and in legal obligations?
- How much of this data did you actually need to keep?
The last question is the only one whose answer depends entirely on you, starting today.
Nobody can guarantee that a connected application will never be attacked. You can, however, decide now what an attacker would find there. Securing access remains essential. Keeping only what is necessary matters just as much.
Sources
- Cybermalveillance.gouv.fr, "What to do in the event of a cyberattack? (Guide for business leaders)" (updated March 17, 2026)
- Cybermalveillance.gouv.fr, "Data breaches in 2025: an acceleration with very diverse consequences" (June 1, 2026, updated August 18, 2026)
- CNIL, "Cybercrime: risks and consequences for personal data" (November 26, 2025, Harris Interactive survey of 2,082 people)
- ANSSI, "Threat summary on generative AI in cyberattacks" (February 4, 2026)
- DGSI, Economic interference flash no. 117, "Risks associated with the use of artificial intelligence in the professional world" (December 2025)
- French Ministry of the Interior, "2026 annual report on cybercrime", chapter "Foresight and points of attention"
- CNIL, sanction against Hôpital privé de la Loire (September 3, 2026)
- CNIL, sanctions against Free Mobile and Free (January 13, 2026)
- CNIL, "Data retention periods" (updated April 2, 2026)
- CNIL, "Annual report 2025" (May 18, 2026)