Skip to content

Best Practices to Strengthen Your Company’s Cybersecurity

An employee plugs a personal USB drive into their work computer to transfer a file. Thirty minutes later, ransomware encrypts the directory…

Professionnelle en cybersécurité analysant des tableaux de bord de sécurité informatique sur un poste de travail en entreprise

An employee plugs a personal USB drive into their work computer to transfer a file. Thirty minutes later, a ransomware attack encrypts the shared directory of the accounting department. This type of common and documented scenario reminds us that a company’s cybersecurity primarily relies on precise operational actions, not on statements of intent.

Mapping Suppliers: The Link Most Companies Overlook

We often think of firewalls, antivirus software, and passwords. However, an increasing portion of cybersecurity incidents does not originate from within: it passes through a supplier, software publisher, or subcontractor connected to the information system.

ENISA, in its Threat Landscape 2025 published on October 1, 2025, confirms that attacks targeting the digital supply chain continue to produce large-scale incidents. An inadequately secured supplier accessing your network is an open door that you are not monitoring.

Specifically, you can start by listing the suppliers who have remote access to your systems or who host your data. Then, it is essential to verify their security commitments: encryption, update policy, incident notification procedure. Contracts should include reversibility and short-notice alert clauses. Without this mapping, you are exposed to risks that you may not even measure.

To structure this approach and identify the appropriate control points for your context, you can access the security page of Cyber Vista, which details the steps of a scope audit.

Network technician configuring servers in a secure IT room of a company

IT Security and Generative AI: Framing Usage Before an Incident

An employee copies and pastes an excerpt from the customer database into a generative AI tool to write a report faster. The data leaves the company’s perimeter, sometimes to servers located outside the European Union, without any traceability.

This scenario is becoming more common. ENISA notes that malicious groups are also using AI to enhance social engineering and prepare their attacks. Phishing emails are becoming more credible, and identity theft is harder to detect. Traditional phishing awareness training is no longer sufficient.

Two concrete measures change the game:

  • Implement a double verification procedure for any urgent request for a transfer, password reset, or transmission of sensitive information, through a separate channel (direct phone call, for example).
  • Draft a charter for the use of AI tools that specifies which data can be submitted and which are strictly prohibited.
  • Train teams on real examples of AI-assisted phishing, not on theoretical slides from three years ago.

Feedback varies on the effectiveness of charters alone, but when combined with technical controls (blocking certain online services on the professional network), they significantly reduce exposure.

Cyber Incident Response Plan: Test Before You Suffer

The majority of companies with an incident response plan have never tested it under real conditions. The day a ransomware attack occurs, it is discovered that the provider’s emergency contact number has changed, that backups do not cover the correct scope, or that no one knows who has the authority to isolate the network.

An untested response plan gives a false sense of security. Operational preparation involves simulation exercises, even if they are short or partial. You simulate a server encryption on a Friday at 5 PM and time the response.

What the Plan Must Cover at a Minimum

  • A list of people to contact immediately, with verified contact details every quarter.
  • The network isolation procedure: who has the authority to cut a segment, and how to do it without blocking critical activity.
  • The location and regular testing of backups, ensuring that restoration works properly in a test environment.
  • Notification obligations: the transposition of the NIS 2 directive into French law requires many companies to report significant incidents within short timeframes.

Team meeting for auditing and improving IT security practices in a company

NIS 2 Compliance: What SMEs Must Anticipate Now

The European NIS 2 directive, currently being transposed in France via the Resilience law, significantly broadens the scope of companies subject to cybersecurity obligations. SMEs that were not previously subject to any specific constraints now fall within the scope.

Waiting for the publication of decrees to act is like preparing for an audit the day before the inspection. The obligations focus on measures that every company should already have in place: risk management, incident notification, governance of information system security.

Three actions to take without delay: appoint a cybersecurity referent (even part-time), document existing protection measures, and identify gaps with foreseeable requirements. This documentation will serve as a basis for when the implementing texts are published.

Regulatory compliance is not an administrative exercise disconnected from the field. It requires formalizing what often exists informally, and it is precisely this formalization that protects when an incident occurs. An identified referent, written procedures, tested backups: these elements make the difference between a company that recovers in a few days and one that takes weeks to resume its activities.

Best Practices to Strengthen Your Company’s Cybersecurity