|8 min read|Yvann Lièvre

ANSSI 2025 Threat Landscape Report: Key Takeaways

Analysis of the ANSSI 2025 Cyber Threat Landscape report: 2,209 reports, 1,366 incidents handled, 128 ransomware cases, and the 2026-2030 strategic priorities.

ANSSIFrance

ANSSI has published its 2025 Cyber Threat Landscape report, and the numbers confirm a strong trend: the cyber threat is not weakening, it is diversifying. With 2,209 security event reports and 1,366 incidents handled by CERT-FR, 2025 marks a continued rise in solicitations. Here are the key takeaways.

Key figures from the 2025 Panorama

The ANSSI report provides a precise snapshot of the threat landscape in France:

  • 2,209 security event reports received by ANSSI

  • 1,366 incidents handled by CERT-FR, averaging 3.7 incidents per day

  • 128 confirmed ransomware incidents, with SMBs and mid-market companies remaining the primary targets

  • Education: 34% of incidents affected the education and research sector

  • Healthcare: 10% of incidents, with direct consequences on care continuity

Education sector on the front line

With 34% of handled incidents, education and research is the most impacted sector. Universities and research labs combine multiple risk factors: heterogeneous systems, limited IT budgets, high international exposure, and strategically valuable research data. State-linked APT groups exploit these weaknesses for intellectual property theft.

Ransomware: still the number one threat

The 128 confirmed ransomware incidents are just the tip of the iceberg. ANSSI estimates that many victims do not report attacks. Groups like LockBit 3.0, ALPHV/BlackCat, and their successors continue to operate through the Ransomware-as-a-Service (RaaS) model. The median time between initial intrusion and ransomware deployment has dropped to under 48 hours in several documented cases.

For organizations, this means early detection is critical. Continuous monitoring capable of identifying lateral movement within the first hours makes the difference between a contained incident and total paralysis.

Vincent Strubel and the G7 Cyber presidency

A notable development: Vincent Strubel, ANSSI's Director General, takes the presidency of the G7 Cybersecurity Working Group in 2026. This position allows France to influence international cybersecurity standards, particularly regarding cooperation between national CERTs and indicator of compromise (IoC) sharing among allies.

National cyber strategy 2026-2030

The 2025 Panorama feeds into the new 2026-2030 national cybersecurity strategy, which focuses on:

  • NIS2 transposition: expanding the scope of regulated entities to over 15,000 organizations in France

  • Strengthening detection capabilities: deploying sovereign probes on critical infrastructure operator (OIV) networks

  • Skills development: goal of training 75,000 cyber professionals by 2030

  • SecNumCloud certification: progressive requirement for hosting sensitive government data

What this means for your organization

The 2025 Panorama's lessons are directly actionable:

  • Assess your exposure: map your exposed assets with attack surface audit tools

  • Strengthen detection: static rules are no longer sufficient against attackers operating in under 48 hours. An AI agent like ThreatClaw correlates events in real time

  • Prepare for NIS2: the directive mandates incident notification within 24 hours. Your response process must be automated

  • Invest in training: the human factor remains the primary entry vector (phishing, credential compromise)

FAQ

Where can I find the ANSSI 2025 Cyber Threat Landscape report?

The full report is available for free download on the official ANSSI website (cyber.gouv.fr). It is published annually in the first quarter and serves as the reference for understanding the threat landscape in France.

Is my company affected by NIS2?

If your company operates in one of the 18 listed sectors (energy, transport, healthcare, digital, public administration, etc.) and exceeds 50 employees or 10M euros in revenue, you are likely affected. ANSSI provides a self-assessment tool on MonEspaceNIS2.

How does ThreatClaw help with threats identified by ANSSI?

ThreatClaw directly addresses the issues raised in the Panorama: detecting lateral movement preceding ransomware, multi-source event correlation, and automated response to reduce dwell time. Our plans are sized for SMBs and enterprises alike.

What is the average cost of a ransomware incident in France?

According to data compiled by ANSSI and the CESIN (Club of Information Security and Digital Experts), the average cost of a ransomware incident for a French mid-market company ranges between 250,000 and 1.5 million euros, including remediation, business interruption, and legal fees. This figure does not include any ransom payment.

Related articles