In the wake of high-profile cyberattacks against the French tax administration and education ministry, Prime Minister Sébastien Lecornu has called for the creation of a “new cyber unit” to defend state information systems. Yet cybersecurity experts argue the proposed team already operates within the country’s national cybersecurity agency, raising questions about duplication, confusion, and misplaced priorities.
A Letter That Sparked Debate
On August 19, 2026, Lecornu sent a letter to the secretary-general for defense and national security, demanding a rapid response to repeated intrusions into government networks. The most damaging incidents targeted the Direction générale des finances publiques (DGFiP), France’s tax authority, and the Ministry of National Education, exposing sensitive data and shaking public confidence.
In the letter, the prime minister requested a “contact team composed of agents from Anssi,” the National Agency for the Security of Information Systems. This unit would be “responsible for intervening on the front line in the event of suspected serious harm to the integrity of the state’s information system.” Lecornu wants the team engaged before crises erupt, during active incidents, and after recovery, working directly alongside targeted ministries.
“This Team Already Exists”
Cybersecurity professionals quickly pointed out that such a capability is not new. “This team already exists, it’s called Cert-FR!” said Philippe Latombe, a member of parliament from the Les Démocrates party, referring to the Computer Emergency Response Team housed within Anssi’s operations sub-directorate.
Insiders describe Cert-FR agents as digital firefighters who can be dispatched on-site or remotely to diagnose breaches and apply first-response measures. Historical examples reinforce this role. Christian Daviot, a former special advisor to Anssi’s director general, recalled on LinkedIn that the agency spent three months in 2011 working inside the Bercy finance ministry to remediate an espionage intrusion. Anssi also responded to the 2015 TV5 Monde attack and a 2018 breach of the foreign ministry’s Ariane service.
“Lecornu’s proposal shows a misunderstanding of Anssi, because this is its primary role,” said an analyst at a private French CERT. Anssi declined to comment on the proposed new entity.
Risk of Adding Confusion
The exact shape of the new brigade remains unclear. Experts question whether it would be integrated into Anssi, placed in the same sub-directorate as Cert-FR, or established separately. “Will it be staffed by Anssi agents who already performed these missions, at the risk of robbing Peter to pay Paul?” asked one specialist at an independent French cybersecurity group.
Lecornu’s letter does introduce some novel elements. The unit could be reinforced by specialists from the armed forces and interior ministries, and it would allow the integration of reservists. It would also report directly to the prime minister with after-action analyses. However, critics warn that adding another structure to France’s already complex cybersecurity landscape could backfire.
Each ministry already has its own CERT or equivalent. There are also territorial and sectoral CSIRTs, the Cyber Defense Command (Comcyber), the Cyber Crisis Coordination Center (C4), and law enforcement cyber units. “By creating a new unit, we risk adding confusion and needing an extra layer of coordination,” warned one expert.
Political Timing Under Scrutiny
The political dimension of the announcement is hard to ignore. The secretary-general for defense and national security was given just three days—until August 21—to propose an organizational structure, rules of engagement, budget, and leadership for the new unit. “Three days to deliver such an opinion is extremely short,” noted Jean-Michel Mis, former vice-president of the National Assembly’s cybersecurity study group.
Mis suggested the prime minister wanted to demonstrate immediate action before parliamentary work resumes and the 2027 budget debate begins. “The prime minister wanted to show he is reacting right away, to avoid having to manage the cyber issue on top of the budget,” he said.
Experts Call for More Resources, Not More Structures
For many in the field, the real solution is not a new unit but a stronger Anssi. The agency operated in 2025 with a budget of €44.2 million and roughly 650 staff—far less than many private companies it oversees. “We ask a team to monitor all of France while having far fewer resources than most companies that depend on it,” said one analyst.
Recruitment is another challenge. The cybersecurity job market is fiercely competitive, and public-sector salaries often fail to attract or retain top talent. Beyond staffing, experts urge proactive measures: mandatory multi-factor authentication, rapid rotation of leaked credentials, continuous testing of public systems with transparent audits, and financial penalties for entities that fall short.
“Anssi can recommend cybersecurity measures to a ministry, but in the end, that ministry decides, balancing budgets and other factors,” explained a source familiar with the agency’s operations. “Anssi must be strengthened in its role, able to impose sanctions and substitute for a failing authority,” added Mis. “The gendarme needs a whistle and a revolver.”
NIS 2 Directive Still in Limbo
There is broad consensus on one urgent step: transposing the European NIS 2 directive into French law. Adopted at the EU level in 2024, it strengthens cybersecurity obligations—protection, training, incident reporting—for many public and private entities, with financial sanctions for non-compliance. However, the transposition bill remains stalled in parliamentary procedure, prompting the European Commission to launch legal action against France for delays.
Philippe Latombe also advocates for a full-fledged digital ministry attached directly to the prime minister, with a secretary of state dedicated to state cybersecurity. In April, Lecornu announced the merger of two interministerial digital directorates to create a “true digital authority of the state,” but that entity has yet to materialize.
What Comes Next
As the prime minister awaits proposals for his new cyber unit, the broader question lingers: will France duplicate existing capabilities or finally empower the structures it already has? For now, experts remain skeptical that adding another layer will solve the systemic weaknesses laid bare by recent attacks.

