Public administrations and institutions manage personal data at scale (civil records, health, taxation) and ensure the continuity of services whose disruption has a direct impact on citizens. This combination — sensitive data and essential services — makes the sector a recurring target for both opportunistic cybercrime and hacktivism, even as the resources allocated to information security often remain lower than in the private sector for a comparable, or higher, level of exposure.
Last updated — August 22, 2026
ENISA, Threat Landscape (annual report)
Sensitive information systems of public administrations are subject to law 05-20 and DGSSI directives, which notably provide for a periodic security audit.
Yes — this is one of the most common use cases for a virtual CISO: gaining a security governance function without hiring a full-time position.
A significant share of incidents in the public sector originate from human error (phishing, mishandling) rather than a technical flaw — awareness training therefore remains a direct lever for reducing risk.
Mainly law 05-20, decree 2-21-406, DGSSI's DNSSI, and, depending on the data processed, law 09-08 on the protection of personal data.