Data breaches in companies do not always result from sophisticated attacks. Poor management of access rights, an inadequately audited service provider, or unencrypted file transfers are enough to expose sensitive information. The French regulatory framework, between GDPR and the NIS2 directive, pushes organizations to structure their IT data protection well beyond just backups.
Subcontracting Chain and Data Security: The Contractual Link
The threat does not only come from within. Dependence on suppliers (SaaS publishers, IT service providers, maintenance contractors) poses a significant security risk. The NIS2 directive requires the concerned organizations to assess the cybersecurity of their service providers. In practice, companies outside the NIS2 scope are contractually imposed these requirements through the tenders of regulated clients.
Auditing a supplier is not limited to checking that they have antivirus software. It involves mapping shared data flows, requiring incident notification clauses, and verifying the conditions for reversibility in case of contract termination. A company that entrusts its customer data to a cloud provider without a clause for encryption at rest takes a measurable risk.
Providers like Datta assist companies with these issues of information management and protection, a topic that goes far beyond the technical scope to touch on governance.

Data Exfiltration: Why Backup is No Longer Enough
Backup remains a pillar of IT security. However, recent attacks show a shift in the threat towards data exfiltration, even when ransomware slightly recedes. An attacker who copies a customer database before encrypting the servers makes backup restoration insufficient: the data is already out in the wild.
Effectively protecting data in a company requires combining several measures that are often less emphasized than traditional backup:
- Network Segmentation: isolating sensitive databases from the rest of the information system to limit the spread of an intrusion from one segment to another.
- Detection of Unusual Transfers: monitoring outgoing data volumes allows for spotting ongoing exfiltration before it is complete. DLP (Data Loss Prevention) or SIEM tools serve this function.
- Encryption of Sensitive Data at rest and in transit, including on portable workstations and shared cloud spaces.
- Strict limitation of access rights: each employee should only access the data necessary for their tasks, according to the principle of least privilege.
These practices form a coherent set. When applied in isolation, they lose some of their effectiveness.
Incident Notifications: Multiple Obligations in Case of Personal Data Breach
A often underestimated point concerns post-incident crisis management. Companies think about technical remediation, but the regulatory dimension imposes a tight timeline. The GDPR requires a notification to the CNIL within 72 hours after becoming aware of a breach posing a risk to the affected individuals.
The NIS2 directive adds an additional layer for entities within its scope: obligations for rapid reporting to ANSSI, with distinct deadlines and formalities. Incident preparation must anticipate several notifications and not just a single general procedure. Confusing the two circuits, or knowing only one, exposes the company to cumulative sanctions.
Preparing the Legal Aspect Before the Incident
Drafting a cold notification procedure that identifies the contacts (DPO, ANSSI, cyber insurer, forensic provider) and the respective deadlines of each regime allows for gaining critical time. A company that discovers a customer data leak on a Friday evening and does not have a formalized procedure risks exceeding the GDPR deadline before even understanding the extent of the compromise.

NIS2 in France: A Framework Still Under Construction but Already Binding
In France, the transposition of NIS2 via the Resilience Law is not yet fully enforceable. Field feedback varies on the exact implementation timeline. However, the indirect effect is already tangible: regulated clients are integrating NIS2 requirements into their supplier contracts, creating cascading compliance pressure.
For SMEs and mid-sized companies, this means that compliance with NIS2 can become a market access condition even before the law directly obliges them to do so. Mapping potential obligations, checking if their main clients are regulated NIS2 entities, and documenting their existing cybersecurity measures are concrete steps to take now.
Risks and Solutions for Small Structures
SMEs rarely have a dedicated CISO. Outsourcing network monitoring and backup management to a qualified provider can compensate for this lack, provided that the contract includes clear commitments on detection and remediation timelines. Secure cloud solutions with integrated encryption and access logging offer a foundation of protection accessible without heavy infrastructure.
Protecting IT data in a company is not just about stacking tools. It is a constant balancing act between governance, regulatory constraints, and operational reality. Companies that formalize their notification procedures, audit their subcontracting chain, and segment their network before an incident give themselves a margin of maneuver that others will not have.



