French Government Overhauls Cybersecurity Governance Following DGFiP Data Breach
- The French government is restructuring the cybersecurity governance of the Direction Générale des Finances Publiques (DGFiP) following a summer cyberattack that originated in the Ministry of National Education's...
- The breach of the DGFiP was not a direct assault on the tax authority's perimeter.
- This pattern of cross-departmental contagion mirrors a separate incident from late 2025.
The French government is restructuring the cybersecurity governance of the Direction Générale des Finances Publiques (DGFiP) following a summer cyberattack that originated in the Ministry of National Education’s systems. According to a September 26 letter from David Amiel to senators Jean-François Husson and Claude Raynal, obtained by Acteurs publics, the administration is elevating the role of the Chief Information Systems Security Officer (RSSI) and increasing the 2026 cybersecurity budget to 28 million euros.
Interministerial Vulnerabilities and the DGFiP Breach
The breach of the DGFiP was not a direct assault on the tax authority’s perimeter. David Amiel confirmed in the September 26 correspondence that cybercriminals first compromised several agent accounts within the Ministry of National Education. This initial intrusion allowed the attackers to gain access to the State Information Network, which they subsequently used to target the DGFiP.
This pattern of cross-departmental contagion mirrors a separate incident from late 2025. Investigations into a hack of the Ministry of the Interior revealed that the intrusion was made possible through a compromised account at the Ministry of Agriculture. In response to these systemic weaknesses, the Prime Minister has tasked the National Agency for the Security of Information Systems (Anssi) with establishing a cybersecurity task force to improve communication between different government administrations.

Governance Shifts and Budgetary Increases
The government is moving the RSSI function directly under the general management of the DGFiP to address criticisms regarding an “illegible” governance structure. Previously, cybersecurity professionals argued that the RSSI was positioned too low in the organizational chart to influence decision-making or budget allocations.
An former state official told Acteurs publics that the previous lack of dialogue between the executive and the RSSI hindered effective security, stating:

The dialogue between the executive and the RSSI doesn’t exist today: the RSSI is too low in the organizational chart, as we see in that of the DGFiP. If there is no dialogue between the minister and the people on the ground, it can’t work.
Former state official via Acteurs publics
To support these structural changes, the DGFiP is increasing its financial resources. The cybersecurity budget for 2026 has been increased by 10 million euros, bringing the total to 28 million euros. This funding level is expected to remain constant through 2027. A portion of these funds will be used to progressively increase staffing at the Security Operations Center (SOC), the unit responsible for detecting intrusions.
Technical Mandates for Authentication and Data Protection
The administration is accelerating the rollout of hardware-based security to prevent further account compromises. By the end of 2026, DGFiP agents will be required to use secured USB keys to access the administration’s information system. This requirement was originally scheduled for February 2027 but was moved forward following the summer attack.
Beyond hardware authentication, the DGFiP is implementing connection quotas on sensitive applications. These limits are designed to prevent the massive extraction of sensitive data by unauthorized users. The government aims to have these authentication and quota measures fully operational before the end of the year.
