
Every week, French companies discover that one of their servers was accessible from the Internet without any particular protection. The problem does not always stem from sophisticated malware. Often, it is a misconfigured service or a forgotten access that opens the door. Recent cybersecurity news confirms this trend: cyber threats exploit more mundane vulnerabilities than spectacular techniques.
Systems Exposed on the Internet: The Underestimated Attack Vector
Have you checked which services on your network are visible from the outside? An email server, an administration interface, a database: each of these elements, if left accessible without restriction, becomes a direct target.
See also : The latest economic news and trends of the day not to be missed
The cyber risk associated with systems exposed on the Internet stands out as a major entry point for attacks, surpassing several more publicized vectors like targeted phishing. An attacker does not need to trick a user via email if they can connect directly to an open service.
This type of vulnerability affects both SMEs and large organizations. The difference: large companies have teams that regularly scan their own IP addresses to spot these exposures. Smaller organizations often do not have this habit, nor the tools to do so. To learn more about Critelab with Viruslab, specialized monitoring platforms allow for tracking these alerts in real time.
You may also like : The Latest Trends and Innovations in Transportation You Must Discover
The fix is rarely complex: close a port, restrict access to a range of IP addresses, disable an unnecessary service. The real problem is detection. Without an up-to-date inventory of what is running on the network, vulnerabilities remain invisible until an incident occurs.

Configuration Errors and DDoS Attacks: Two Persistent Cyber Threats
Configuration errors are not limited to servers. They affect firewalls, cloud applications, service accounts with default passwords. A simple example: a cloud storage bucket left publicly accessible. Customer data becomes readable by anyone, without any technical intrusion.
What “Misconfiguration” Covers
- An administrator account with a generic password never changed after installation
- Firewall rules that are too permissive, allowing incoming traffic on unused ports
- Cloud services whose sharing permissions are set to “public” instead of “private”
- The absence of encryption on internal flows, allowing an attacker positioned on the network to read communications
These errors do not make the headlines. However, they represent a massive share of data breaches in France and elsewhere.
DDoS Attacks Change Targets
Distributed Denial of Service (DDoS) attacks saturate a service by flooding it with requests. The principle has been known for a long time. What is evolving is the targeting: attackers now aim at specific services rather than showcase websites. A business API, a customer login portal, a payment service.
The goal is no longer just to make a site inaccessible, but to disrupt an operational chain. A DDoS attack on the login portal of an energy provider, for example, prevents customers from managing their accounts and saturates phone support.
Cybersecurity and Artificial Intelligence: A Strategic Imbalance to Watch
Artificial intelligence dominates discussions on cyber threats. Attackers use AI tools to generate more credible phishing emails, automate vulnerability searches, or create deepfakes to impersonate identities.
On the defense side, AI is used to detect abnormal behaviors on a network, sort security alerts, or accelerate incident analysis. So far, the picture seems balanced.
The problem lies elsewhere. According to Bitdefender’s 2026 assessment, some organizations focus their efforts on AI at the expense of more traditional threats. They invest in a machine learning detection tool but forget to update security patches on workstations. They train teams on the risks associated with deepfakes, but no one checks access rights on the file server.
This imbalance creates blind spots. An attacker exploiting a vulnerability known for six months does not need AI. They need a target that has not applied the patch.

NIS2 Compliance and Data Protection in France: What Changes Practically
The European NIS2 directive expands cybersecurity obligations to a much larger number of companies and communities. The sectors concerned include energy, transport, health, digital services, and other activities deemed critical.
For an SME that had never had formal obligations regarding IT security, NIS2 imposes a baseline of technical and organizational measures: risk management, incident notification, access control policy, continuity plan.
The Specific Case of the Energy Sector
Cybersecurity in energy illustrates the current tension well. Industrial systems (OT) that control electrical networks or production facilities operate with technologies different from traditional IT. Finding profiles capable of securing both environments remains difficult. The intersection of NIS2 constraints, threats to OT systems, and skills shortages places this sector under particular pressure.
- OT systems use specific, often outdated protocols that traditional IT security tools do not natively monitor
- Software updates on an industrial system do not deploy like on a desktop: they require planned maintenance windows
- Recruiting specialized IT/OT profiles takes significantly longer on average than for a traditional IT security position
The European cybersecurity regulation adopted in 2019 had already formalized the role of ENISA (the European Union Agency for Cybersecurity). NIS2 continues this trajectory but with more stringent obligations and an expanded scope.
Data protection and system security are no longer a strategic choice for the companies involved. It is a regulatory obligation with financial penalties. Organizations that have not yet begun their compliance efforts are accumulating a backlog that will be costly during the first audit or the first reported incident.