Cybersecurity

French SMEs: 48% of ransomware victims in 2025 — what the ANSSI report reveals

48% of ransomware victims in France are micro-businesses and SMEs (ANSSI 2025 report). Why you are a target, the 5 most common mistakes, and how to respond.

By Équipe IMACS SERVICES · Ingénieurs IT & cybersécurité 6 min read
Cybersecurity for SMEs in Normandy — ransomware protection

You think you're too small to interest a hacker? ANSSI has just proved you wrong.

This is the figure that should headline every boardroom meeting in 2026: 48 %. That is the share of ransomware victims in France that are micro-businesses, SMEs, and mid-sized companies, according to the Panorama de la cybermenace 2025 published by ANSSI on 11 March 2026. The single largest category affected, ahead of local authorities (11 %) and healthcare establishments (8 %).

The reality is unambiguous: your business has become a priority target. Not through bad luck, but by design. Understanding that design is the first step towards protecting yourself.

What the ANSSI 2025 report actually says

ANSSI handled 3,586 security events in 2025, including 1,366 confirmed incidents. 128 ransomware attacks were recorded over the year — a high level, despite a slight decrease compared to the 141 cases recorded in 2024.

But the raw figures only tell part of the story. What ANSSI emphasises strongly is the qualitative evolution of the threat:

  • Data exfiltration is soaring. 196 incidents in 2025, compared with 130 in 2024. Attackers steal files before encrypting them, then threaten to publish them: double extortion.
  • The line between organised crime and nation-states is blurring. The most active strains: Qilin (21 %), Akira (9 %), LockBit 3.0 (5 %).
  • Perimeter devices remain the primary entry point. 29 % of vulnerabilities exploited in 2025 were exploited on the very day they were published.
  • IT service providers are being targeted. The use of subcontractors as a compromise vector is on the rise.

Why are SMEs the number-one target?

The answer comes down to one word: profitability. Cybercriminals optimise their return on investment. An SME with 20 to 200 employees represents the ideal trade-off: enough data and turnover to justify a ransom demand, yet rarely the defences of a large corporation.

The average cost of an attack on a French SME falls between £110,000 and £215,000 (€130,000–€250,000), including downtime. The ransom itself accounts for only 10 to 15 % of the bill. The remainder comprises:

  • production shutdown and loss of revenue for 2 to 6 weeks;
  • complete reconstruction of the IT infrastructure;
  • legal and crisis-communication costs;
  • CNIL penalties in the event of a personal data breach;
  • loss of clients and lasting reputational damage.

What about insurance? Since 2025, insurers have been refusing claims where basic measures (MFA, offline backups) were not in place. The question is no longer about taking out cover, but about proving you were prepared.

The 5 mistakes that open the door to ransomware

1. Shared passwords that are never changed

Phishing remains the number-one attack vector: 91 % of cyberattacks begin with an email.
What to do: mandatory MFA on email, VPN, and cloud applications; enterprise password manager (we deploy LockSelf, ANSSI CSPN-certified).

2. Backups permanently connected to the network

Any backup accessible from the local network will be encrypted along with everything else.
What to do: 3-2-1 strategy (3 copies, 2 media types, 1 offsite/immutable). Test your restores every quarter.

3. Patches applied "when we find the time"

In 2025, 29 % of exploited vulnerabilities were targeted within hours of their publication.
What to do: automated and supervised patch management; a fully inventoried estate updated according to a defined schedule.

4. No network segmentation

On a flat network, a single compromised workstation grants access to servers, backups, and client data — lateral movement.
What to do: at minimum, separate the office network from critical servers. For law firms and notarial practices, this is an absolute requirement (professional secrecy obligations).

5. Zero team training

The weakest link is the human element — through lack of training, not incompetence.
What to do: regular awareness sessions, phishing simulation exercises. A trained team detects and reports before clicking.

What the regulations now require of you

The NIS 2 Directive, currently being transposed into national law, extends obligations to approximately 15,000 entities. If you have more than 50 employees or €10 M in turnover in a covered sector, you may well be in scope: fines of up to 2 % of global turnover, with the potential for personal liability for directors.

The European Cyber Resilience Act (CRA), first phase in 2026, imposes a reporting obligation within 24 hours on manufacturers and software publishers.

The good news: ANSSI published the Référentiel Cyber France (ReCyF) in March 2026 — 152 concrete measures across 20 objectives, accessible even without a dedicated IT team.

Why outsourcing your cybersecurity to a local MSP makes all the difference

Cybersecurity is not a project; it is continuous supervision. An MSP such as IMACS SERVICES takes on that vigilance on your behalf:

  • 24/7 monitoring of your infrastructure;
  • Systematic patch management;
  • Supervised immutable backups, tested and documented;
  • Rapid on-site response — based in Évreux, covering the whole of Normandy and Île-de-France within 4 hours;
  • Contractual confidentiality — NDA from the very first exchange, no client logos published.

We do not practise marketing security: we apply concrete frameworks (ANSSI, GDPR, RGAA) to real infrastructures that we supervise every day.

Where to start? The free IMACS pre-assessment

You may not know what your business is exposing, or whether your backups are actually working. That is precisely what our free pre-assessment identifies. Within 48 hours, you receive:

  • an overview of your current security posture;
  • the critical vulnerabilities to address as a priority;
  • a costed, prioritised action plan — you set the pace.

No commitment, no jargon, no surprise invoices.

"We have the means to counter, deter, or at the very least make life significantly harder for attackers."
— Vincent Strubel, Director General of ANSSI, Panorama de la cybermenace 2025

The threat is real. So are the tools to defend against it. It simply takes that first step.

Request my free pre-assessment · Contact the IMACS SERVICES team


Sources: Panorama de la cybermenace 2025 — ANSSI/CERT-FR (March 2026) · Verizon DBIR 2025 · IBM Cost of a Data Breach 2025 · CESIN Baromètre 2025.

Keywords

  • ransomware PME France
  • ANSSI
  • NIS 2
  • sauvegarde 3-2-1
  • MFA

Does this article resonate with your situation?

Our free 15-question pre-assessment gives you a personalised report within 24 hours. No commitment.

Related articles

Read next.