Compute
High-performance, scalable computing resources for your critical workloads. Orchestrate your cloud-native applications with our modern container solutions.
Discover the Compute offer
Virtual machines
VM Instances
An on-demand, flexible and secure virtual machine solution on a shared infrastructure.
Dedicated servers
OpenSource IaaS
Open source virtualised infrastructure in a trusted SecNumCloud-qualified cloud environment for complete technological sovereignty.
VMWare IaaS
Your VMware virtual machines in a trusted SecNumCloud-qualified and HDS-certified cloud environment.
Bare Metal
Dedicated, fully customisable servers for total autonomy over your sovereign infrastructure.
Containers
PaaS OpenShift
The unified platform for creating, modernising and deploying your large-scale applications in a sovereign cloud.
Managed Kubernetes
Managed container orchestration solution offering security, resilience and advanced automation on sovereign infrastructure.
Storage
Adaptable, high-performance storage solutions for all your needs. Optimise your data with our highly available block and object solutions.
Discover our Storage offer
Storage
Block storage
The adaptable block storage solution for optimum storage performance in a sovereign cloud.
Object storage
The scalable, cost-effective storage solution for your unstructured data in a sovereign cloud.
Backup
Backup solutions
Differentiated backup solutions tailored to your challenges and environments
Network
Advanced network solutions to connect and secure your infrastructures. Deploy your private networks automatically and securely.
Discover the Network offer
Network
Virtual Private Cloud
Deploy and manage your private networks 100% automatically and securely.
Private Backbone
Take full control of your network with extended Layer 2 connectivity, designed for hybrid architectures and bespoke configurations.
Firewall
Managed Firewall
Advanced security solutions for complete insulation and enhanced protection
Accommodation Dry
Housing - Dedicated space
Secure hosting for your equipment in a dedicated or shared environment, depending on your needs.
Security
Advanced security solutions to protect your critical infrastructures. Control access and defend against online threats.
Discover the Security offer
Detection
Managed SIEM
A centralised platform for collecting and correlating security logs, combining AI-based automation and advanced detection rules (MITRE ATT&CK).
Sovereign SOC
A sovereign SOC offering operated 24/7, deployable from our marketplace, on SecNumCloud-qualified infrastructure.
Protection
Anti DDoS
The shield against online attacks
Bastion host
Transparent, centralised access control for robust protection of your infrastructure
Managed KMS
Sovereign cryptographic key management, with HSM hardware root of trust, to protect your most sensitive data on SecNumCloud infrastructure.
AI
Artificial intelligence solutions to transform your data into insights and accelerate your business processes.
Discover the AI offer
AI
LLMaaS
Access cutting-edge language models on a sovereign, SecNumCloud-qualified and HDS-certified infrastructure for high-performance, secure AI applications.
GPU
NVIDIA GPU instances to accelerate your artificial intelligence and high-performance computing in a sovereign cloud.
Data
Data solutions to manage, analyse and exploit your critical data.
Discover the Data offer
Databases
Managed MariaDB
A fully managed MariaDB relational database and PITR backup on SecNumCloud sovereign infrastructure.
Managed PostGreSQL
The fully managed relational database solution on SecNumCloud sovereign infrastructure
Big Data
Managed Kafka
The open-source distributed platform for streaming data in real time
Managed File System
A managed, sovereign, high-availability distributed file system, accessible via NFS and SMB on the SecNumCloud infrastructure.
Management & Governance
Coaching and support services to help you with your cloud transformation.
Find out about our support services
Support
Support levels
Discover the 3 levels of support available to help you meet your challenges.
Professional services
From design to optimisation, Cloud Temple is with you every step of the way.
Governance
Console - API - Terraform Provider
A single interface for viewing and managing your products and services
Observability
Infrastructure metrics available in market standards
The magazine > Opinion | Transposing NIS2 in France: the challenges of a change of scale
Published on 06/17/2024 by Nicolas Abrioux, Head of Security Governance at Cloud Temple

By increasing the number of entities supervised by ANSSI in France by a factor of 40 or even 50, the Resilience Bill takes cyber security into a new dimension. NIS2 represents a major step forward in terms of increasing the level of security of entities deemed essential, but also in terms of disseminating a genuine cyber culture throughout the economic fabric. In this way, the directive is helping to create a virtuous circle towards a more secure digital environment, an essential lever for innovation. However, this reform raises a number of questions, which Cloud Temple set out in detail at its hearing before the Commission Supérieure du Numérique et des Postes.

One of the first pitfalls of the transposition of NIS2 in French law lies in the risk of regulatory stacking, which would be a factor of inertia for the players targeted by the text. Faced with a multitude of regulations, it becomes difficult to understand, and organisations may be tempted to put the brakes on their initiatives in the absence of a clear understanding of the requirements to be met. The issue of certifications and qualifications mentioned in the Resilience Bill adds a further layer of complexity. How will these new requirements fit in with existing regulations such as the Military Planning Act, the RGPD, SecNumCloud and the PCI, HDS and ISO 27001 standards?

Facilitating proof of compliance

A reform on the scale of NIS2 will have an impact on the entire relationship between the customer and the digital service provider. The administrative process for proving compliance is crucial in this development, as increased pressure on providers could complicate their task. The need to ensure the security of the supply chain could lead to an overload of regulatory compliance, with contract reviews, audit requests and security questionnaires. However, it is in everyone's interest for digital players to devote their time to increasing the level of security of their services rather than demonstrating that they are secure. To avoid these pitfalls, establishing criteria for presuming compliance would help to streamline the process for both service providers and customers. An effective approach would be to build a compliance matrix with recognised benchmarks and indisputable presumptions of compliance, backed up by audits and certification labels.

Making digital players facilitators of reform

Another question concerns the special status of digital players, who will be the subject of a European implementing act that has yet to see the light of day. It is therefore difficult at this stage to see how they will fit into the scheme. And this is all the more important given that it is essential for the success of this reform to make digital players vectors and facilitators of cyber progress, and not regulated entities like the others. Otherwise, the ANSSI will be on its own to carry out its mission for the 12,000 to 15,000 entities in France. The ability of cloud players to comply with NIS2 and provide effective support for their customers will depend on the final content of the performance contract. Will the rules be adapted to the specific characteristics of the cloud, which involves sharing responsibilities and pooling resources? Rapid publication of all the texts is key to ensuring a smooth transition.

Incident notification: who does what?

The notification of security incidents is another critical aspect of the Resilience Bill: defining clear severity thresholds, clear deadlines and determining the competent authority for notification are central elements of the system. In the emergency context of a cyber incident, it is crucial to have a notification framework that leaves no room for interpretation. Notifying too early or too late can have a real impact on the ability to resolve the crisis, particularly in the event of a cyber attack. The principle of "notification as soon as possible" must be clarified to avoid any uncertainty in crisis situations. The forthcoming decree on the procedures for reporting incidents should therefore be the subject of consultation with the sector, in order to establish rules that are pragmatic, realistic and easy to implement by the players concerned.

Supporting efforts to upgrade skills

Finally, talent remains the sinews of cyber warfare. With the change in scale brought about by the Resilience Bill, a large number of companies and local authorities that are new to the field will be starting their cybersecurity process, at a time when recruiting specialist talent is difficult and expensive. Ensuring that the cybersecurity ecosystem is able to support them is fundamental. The time it takes for service providers to carry out audits or provide services can also be an obstacle. The State must play a crucial role in helping companies and organisations to comply, while supporting the cyber ecosystem and efforts to train talent. The funding arrangements put in place will be key, particularly for the 1,653 local authorities affected by the reform.

ANSSI understands that listening to stakeholders - and in particular digital players - is essential to the success of NIS2 in France. The collection of needs and comments is a pragmatic contribution to the bill, to make it an unprecedented lever for cybersecurity in France and Europe. The hearings held by the Commission Supérieure du Numérique et des Postes will feed into this iterative consultation process. At a time when the parliamentary agenda is being disrupted by the new electoral deadlines, and the 17 October deadline is approaching, it is crucial not to sacrifice this co-construction effort on the altar of legislative efficiency. A law and implementing decrees adopted in haste would be a bad start for this structuring reform.

The magazine
Cookie policy

We use cookies to give you the best possible experience on our site, but we do not collect any personal data.

Audience measurement services, which are necessary for the operation and improvement of our site, do not allow you to be identified personally. However, you have the option of objecting to their use.

For more information, see our privacy policy.