The majority of cybersecurity guides focus on traditional ransomware, which encrypt your files and demand a ransom. The landscape has changed. The Threat Panorama 2025 published by ANSSI documents a clear trend: more and more criminal groups are abandoning encryption in favor of data theft followed by extortion.
Your backups remain intact, but your client files, contracts, or personal data are already circulating on resale forums. Strengthening your cybersecurity requires rethinking protections in light of this shift.
Data Exfiltration: The Threat That Backups Do Not Cover
The classic reflex in response to ransomware is to maintain regular backups on a disconnected medium. This measure remains useful, but it no longer protects against the dominant scenario. When the attacker copies your data before any visible action, restoring from a backup does not solve the problem: the information has already left your network.
Market analyses of cyber insurance published in 2025-2026 confirm the increase in exfiltrations while the overall volume of incidents remains stable. The attackers’ business model has adapted: threatening to publicly disclose sensitive data generates pressure comparable to that of encryption, with less technical effort.
To address this, network protection must integrate monitoring of outgoing traffic. Detecting a massive copy of files to an external server requires continuous monitoring of network traffic, not just checking the integrity of endpoints. DLP (Data Loss Prevention) solutions or network anomaly detection systems are becoming more relevant in light of this evolution. The resources dedicated to cybersecurity on Cyber Huge detail several complementary approaches to structure this monitoring.

Phishing-Resistant Authentication: Beyond SMS Codes
Enabling two-factor authentication is mentioned in almost all cybersecurity guides. The advice remains valid, but the nature of the second factor is as important as its existence.
Several European authorities and regulators now consider that, for sensitive access, the simple SMS code is no longer state-of-the-art. The CNIL clarified in 2024-2025 that services involving financial operations or handling very sensitive data must prioritize phishing-resistant factors. Specifically, this refers to physical FIDO2 keys, passkeys, or any authentication method cryptographically linked to the service domain.
The difference is technical but decisive. An SMS code can be intercepted through SIM swapping or entered by the user on a fake site. A FIDO2 key automatically verifies that the domain matches the legitimate service. The user cannot inadvertently transmit their credentials to a fraudulent site.
Prioritize Deployment Based on Access
Protecting all accounts with a physical key is not realistic for most organizations. Deployment should first target high-privilege accounts:
- System and network administrator accounts, which provide access to the entire infrastructure
- Mailboxes of executives and financial officers, priority targets for spear phishing campaigns
- Access to databases containing personal information or trade secrets
For other accounts, an authentication app (TOTP) is preferable to SMS alone. The goal is to reduce the attack surface on the most critical entry points.
Vendor Vulnerabilities and Regulatory Compliance
The security of an information system does not stop at the organization’s perimeter. Data entrusted to vendors, hosts, or SaaS providers constitutes an often-underestimated exposure vector in current practices.
The European Cyber Resilience Act, for which the European Commission has published new guidelines to support its implementation, imposes security requirements from the design stage on manufacturers of digital products. This regulation alters the relationship with vendors: it becomes legitimate to demand proof of compliance before integrating software or equipment into one’s environment.
Regarding personal data protection, the GDPR already requires verifying that subcontractors provide sufficient guarantees. Field reports vary on this point: some organizations truly audit their providers, while others rely on contractual clauses that are never verified.
Vendor Verification Points
- Actual location of hosted data and applicable legal framework for transfers
- Notification policy in case of a security incident, with precise timelines and contractual commitments
- Results of recent security audits or recognized certifications (ISO 27001, SOC 2)
- Data return and deletion procedure at the end of the contract

Training and Detection: The Human Factor Against Targeted Threats
Phishing campaigns remain the primary vector for intrusion into information systems. Available data does not allow concluding that a one-time training session is sufficient to sustainably reduce risk. However, programs that combine regular awareness and attack simulations show more consistent results.
Training should go beyond simply reminding general rules. Learning to identify a fraudulent email is only useful if the exercise focuses on examples close to the actual context of the organization. An accounting firm does not receive the same attempts as a hospital service.
On the detection side, network segmentation limits the spread of an attacker who has breached the first perimeter. Isolating critical systems from office workstations significantly slows lateral movement, whether the goal is encryption or exfiltration.
Data protection relies on a balance between technical measures and human vigilance. Threats are evolving towards extortion models that bypass traditional defenses, and European regulatory requirements strengthen the obligations of each link in the chain. Adapting practices to these realities, rather than to a list of advice that has remained unchanged for ten years, constitutes the first line of truly effective defense.



