Home
>
Articles
articles

Cyber News

Headlines
Glossary

ReCyF 2.5 (Cyber France Reference Framework)

ReCyF is the French cybersecurity framework based on the European NIS 2 Directive. It sets out 20 mandatory security objectives for critical and essential entities and specifies the acceptable means for demonstrating compliance.

Read the article
All categories
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
compliance gap
Compliance
April 13, 2025
How to manage compliance gaps?

In an ever-changing regulatory landscape, companies must comply with a set of standards and regulations related to data protection, IT and employee security, and the functioning of their products. Beyond the penalties for non-compliance —which can be significant—a security breach or unaddressed vulnerability can seriously damage an organization's brand image.

Reporting
April 13, 2025
What tools should you use for your IT security plan?

Your management has just approved your information system security policy (ISSP). What now? It's time to draw up your IT security plan, which should detail the actions to be implemented to ensure the ISSP is applied. Defining objectives, monitoring current and future actions, measuring results... All this requires flawless project management.

Cyber management: risk-based or compliance-based approach?
Compliance
Risks
March 16, 2025
Cyber management: risk-based or compliance-based approach?

Risk-based approach and compliance-based approach: these two terms, which refer to the mindset with which the CISO builds his strategy, are sure to divide the world of cybersecurity...

CISO exemption
Compliance
March 3, 2025
How to manage compliance exemptions?

GDPR, LPM, NIS... Companies today are subject to an increasing number of regulatory and compliance frameworks. While these rules are essential to ensuring a high level of security within the organization, they can sometimes hinder the smooth running of operations.

The AI Act: a regulatory revolution for artificial intelligence
Glossary
February 24, 2025
AI Act

In 2024, the European Union undertook to regulate the use of artificial intelligence through the AI Act. This pioneering initiative aims to establish a legal framework for the general use of AI.

[Interview] Law and cybersecurity: an essential synergy
Governance
September 30, 2024
Law and cybersecurity: experts have their say

The law firm Fidal, founded in 1922 (no less!), has specialized in cyber issues for several years. When we met with them, we wanted to know how business law experts approach cybersecurity and its challenges, particularly in terms of regulatory compliance. Gaël Leroux and Cyril Chauvin answer our questions.

NIST-CSF: definition and application
Glossary
September 5, 2024
NIST Cybersecurity Framework

Everyone (or almost everyone) is familiar with the NIST Cybersecurity Framework (NIST-CSF). Developed by the National Institute of Standards and Technology—a U.S. agency within the Department of Commerce—this framework offers a structured and comprehensive approach to help organizations identify, assess, and manage cyber risks. It is specifically designed to strengthen the security of critical infrastructure, but its application extends to all sectors, regardless of the size of the organization or its field of activity. Let's take a closer look.

Everything you need to know about the CNIL
Glossary
Compliance
September 3, 2024
CNIL

The CNIL (Commission Nationale de l’Informatique et des Libertés) is a 100% independent French administrative authority. It was created in 1978 to protect personal data and individual freedoms—nothing less.

The CNIL quickly became a key player in the French digital landscape, positioning itself as the number one authority on privacy and personal data regulation in France.

Overview of the CNIL, its history, its missions, and its impact.

NIS 2 Directive under the microscope
Glossary
September 2, 2024
NIS 2: definition, objectives, and key points to remember about the directive

The NIS 2 (Network and Information Security 2) directive has been the subject of much discussion since its publication in the EU Official Journal on December 27, 2022. And with good reason: it represents a major milestone in the evolution of European cybersecurity regulations, replacing its 2016 predecessor, NIS.

PCI-DSS: definition and explanations
Glossary
August 30, 2024
PCI DSS

The Payment Card Industry Data Security Standard (also known as PCI-DSS for short) is a set of security standards designed to ensure that all companies accepting, processing, storing, or transmitting credit card information maintain a secure environment.

SOC 2 standard and certification: definition
Compliance
Glossary
August 30, 2024
SOC 2 Certification: The Complete Guide to Securing Your Services and Gaining Your Customers' Trust

In today's cyber landscape, it is no longer enough to simply implement protection solutions. Compliance with standards and regulations has quickly become an essential parameter for ensuring information security—and therefore user confidence. Among these standards is SOC 2 (Service Organization Control 2), which has become indispensable.

NIS2 Directive: guide to preparing for compliance
Compliance
Glossary
August 30, 2024
NIS Directive 2: the complete guide to preparing for compliance

The NIS 2 (Network and Information Security) Directive is the latest regulatory shake-up in European cybersecurity. Succeeding the 2016 NIS Directive, it massively expands the number of companies affected and tightens security requirements...