ANSSI 2025 Threat Landscape Report: Key Takeaways
Analysis of the ANSSI 2025 Cyber Threat Landscape report: 2,209 reports, 1,366 incidents handled, 128 ransomware cases, and the 2026-2030 strategic priorities.
ANSSI has published its 2025 Cyber Threat Landscape report, and the numbers confirm a strong trend: the cyber threat is not weakening, it is diversifying. With 2,209 security event reports and 1,366 incidents handled by CERT-FR, 2025 marks a continued rise in solicitations. Here are the key takeaways.
Key figures from the 2025 Panorama
The ANSSI report provides a precise snapshot of the threat landscape in France:
-
2,209 security event reports received by ANSSI
-
1,366 incidents handled by CERT-FR, averaging 3.7 incidents per day
-
128 confirmed ransomware incidents, with SMBs and mid-market companies remaining the primary targets
-
Education: 34% of incidents affected the education and research sector
-
Healthcare: 10% of incidents, with direct consequences on care continuity
Education sector on the front line
With 34% of handled incidents, education and research is the most impacted sector. Universities and research labs combine multiple risk factors: heterogeneous systems, limited IT budgets, high international exposure, and strategically valuable research data. State-linked APT groups exploit these weaknesses for intellectual property theft.
Ransomware: still the number one threat
The 128 confirmed ransomware incidents are just the tip of the iceberg. ANSSI estimates that many victims do not report attacks. Groups like LockBit 3.0, ALPHV/BlackCat, and their successors continue to operate through the Ransomware-as-a-Service (RaaS) model. The median time between initial intrusion and ransomware deployment has dropped to under 48 hours in several documented cases.
For organizations, this means early detection is critical. Continuous monitoring capable of identifying lateral movement within the first hours makes the difference between a contained incident and total paralysis.
Vincent Strubel and the G7 Cyber presidency
A notable development: Vincent Strubel, ANSSI's Director General, takes the presidency of the G7 Cybersecurity Working Group in 2026. This position allows France to influence international cybersecurity standards, particularly regarding cooperation between national CERTs and indicator of compromise (IoC) sharing among allies.
National cyber strategy 2026-2030
The 2025 Panorama feeds into the new 2026-2030 national cybersecurity strategy, which focuses on:
-
NIS2 transposition: expanding the scope of regulated entities to over 15,000 organizations in France
-
Strengthening detection capabilities: deploying sovereign probes on critical infrastructure operator (OIV) networks
-
Skills development: goal of training 75,000 cyber professionals by 2030
-
SecNumCloud certification: progressive requirement for hosting sensitive government data
What this means for your organization
The 2025 Panorama's lessons are directly actionable:
-
Assess your exposure: map your exposed assets with attack surface audit tools
-
Strengthen detection: static rules are no longer sufficient against attackers operating in under 48 hours. An AI agent like ThreatClaw correlates events in real time
-
Prepare for NIS2: the directive mandates incident notification within 24 hours. Your response process must be automated
-
Invest in training: the human factor remains the primary entry vector (phishing, credential compromise)
FAQ
Where can I find the ANSSI 2025 Cyber Threat Landscape report?
The full report is available for free download on the official ANSSI website (cyber.gouv.fr). It is published annually in the first quarter and serves as the reference for understanding the threat landscape in France.
Is my company affected by NIS2?
If your company operates in one of the 18 listed sectors (energy, transport, healthcare, digital, public administration, etc.) and exceeds 50 employees or 10M euros in revenue, you are likely affected. ANSSI provides a self-assessment tool on MonEspaceNIS2.
How does ThreatClaw help with threats identified by ANSSI?
ThreatClaw directly addresses the issues raised in the Panorama: detecting lateral movement preceding ransomware, multi-source event correlation, and automated response to reduce dwell time. Our plans are sized for SMBs and enterprises alike.
What is the average cost of a ransomware incident in France?
According to data compiled by ANSSI and the CESIN (Club of Information Security and Digital Experts), the average cost of a ransomware incident for a French mid-market company ranges between 250,000 and 1.5 million euros, including remediation, business interruption, and legal fees. This figure does not include any ransom payment.
Related articles
We detonated a live Phobos sample. Here is what it does, deleting shadow copies, killing the firewall, and the Sigma rule that catches it, validated across multiple samples with zero false positives.
Emotet, a notorious botnet and malware loader, remains a critical threat to SMBs. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this persistent adversary.
Drokbk, a remote access trojan, evades defenses with keylogging and screen capture. ThreatClaw now detects it with zero false positives—protect SMBs and MSSP clients.
Dosia malware targets SMBs with obfuscation and tool transfer tactics. Learn how ThreatClaw’s new YARA rules help MSSPs detect and mitigate this threat effectively.