Paralyzed local authorities, blocked administrations, and threatened hospitals—these headlines have unfortunately become all too common.
Cyberattacks in the public sector have been rampant in recent years, making it an ideal target for cybercriminals.
Digitalization and the Covid-19 pandemic have played a key role in this. Government agencies and public administrations manage vast amounts of confidential information, making this data particularly vulnerable.
Where does the public sector stand in terms of digital security, what challenges is it facing, and how is TEHTRIS committed to protecting it? We will attempt to answer all these questions.

- What is the level of security in this sector?
- Nature of the attacks
- The needs of public organizations
- Solutions for public organizations and data security
What is the level of security in this sector?
Cyber Assessment
The BDO Cyber Threat Insights report for Q4 2018 already warned that critical infrastructure operators worldwide were at risk due to aging IT equipment. Legacy technology leaves gaping holes in IT system security. When you add staffing issues, partly due to the retirement of experienced personnel, it is difficult to envision a secure environment.
For the past three years, attack campaigns against public services have become increasingly frequent. One only needs to look at the news to see that not a day goes by without a healthcare facility, town hall, school, or local authority having to deal with a cybercriminal act.
During the 2017 WannaCry attack, (according to a 2019 Verizon data breach report), "public sector organizations were the number one target across 19 examined sectors." In the United States, entire cities were temporarily brought to their knees by attacks on government departments, and the same occurred in Great Britain and France. Spain is no exception; the Spanish government contained over 600 attacks in 2021. Spain is the third most targeted country in the world for cyberattacks.[1]
When crime hits a hospital, the entire system is impacted (see our article: The Healthcare World Facing Cyberattacks): surgeries are postponed, patients are transferred, and entire departments are completely disorganized.
Faced with such an onslaught, some organizations are left helpless.
Financially On one hand, millions of euros are at stake. Public sector CIOs are sometimes forced to choose between modernizing and innovating without impacting budgets. Most French local authorities spend less than 10% of their budget on cybersecurity. [2] Local authorities cite a lack of resources, time, and the existence of "other priorities."
In such a tense environment, IT security is prioritized, sometimes at the expense of innovation.
Technically On the other hand, some departments need to renew their equipment and invest in robust technology.
Downtime caused by an attack targeting IoT or OT would have catastrophic effects. Every sector must ensure the continuity of public service. This was the case for the hospitals in Dax, Oloron-Sainte-Marie, and Villefranche-sur-Saône, as well as the Assistance Publique - Hôpitaux de Paris (AP-HP), all of which suffered cyberattacks in 2021. In March 2020, several Spanish hospitals were also hit.
Other examples are emerging across Europe:
- On May 14, 2021, the HSE (the Irish public health service) was hit by a "Conti" ransomware attack in Ireland.
- In Germany, the number of successful cyberattacks against healthcare service providers more than doubled in 2020 compared to 2019.
- In Spain, the healthcare sector has been and continues to be one of the most affected. In 2020, more than 50,000 attacks against organizations were reported in the sector, 375 of which were successful.
The healthcare sector is often in the media spotlight and considered highly exposed, which is true, but... no public service is immune to cyber risk.
When crime hits public bodies, such as local authorities or town halls, it leads to data loss, costs for restoring systems, and costs related to staff downtime—where employees cannot continue their work and are forced into temporary unemployment. All of this causes harm not only to the local authority itself but also to government agencies, regions, and the public.
It is clear that, unfortunately, most public organizations are not prepared in terms of security.
According to a study by GIP Cybermalveillance published on May 17, 2022, 65% of municipalities with fewer than 3,500 inhabitants believe they are safe from cyberattacks. [3]
The cyberattack on the city of Marseille during the 2020 municipal elections and the December 2018 DDoS attack, where cyber-activists targeted several institutional websites, unfortunately prove this point.
The risk of devastating effects on services, as well as the loss of public trust and non-compliance with regulations (the Network and Information System Security (NIS) Directive), are driving the development of security programs.
The digital transformation in this sector is massive; it requires further upgrades and, above all, it has expanded the attack surface that cybercriminals are exploiting.
New methods, new tools, and new protection processes must be implemented. The journey has begun and is far from over!
Nature of attacks
The nature of attacks is shifting due to the protection of organizations.
They can stem from extremely basic vectors that still prove effective, such as an infected USB drive (52%[4] use unapproved devices for work), a phishing email, a zero-day vulnerability, data theft (48% of public sector entities surveyed report having experienced a cyberattack or data theft.[5]) combined with doxing[6], or even DDoS attacks, as we have just seen.
It is also worth noting that a fairly common vulnerability in this sector stems from the fact that "nearly half of the elected officials surveyed use their personal tools for both municipal and non-municipal use.”[7]
At the European level, the latest report Deloitte, from 2021, states that 94% of Spanish companies have experienced at least one serious cybersecurity incident. A study by Checkpoint confirms these figures, reporting an average of 1,040 cyberattacks per week per organization, an increase of 79% compared to 2020. Education and research are the most affected sectors.
The needs of public organizations
The public sector, just like the private sector, is affected by digital risks, but it stands out due to its specific security needs. Digitalization has created new IT environments, increasing threats and posing new challenges. Here are a few:
Growth of digital services
The growth of digital services involves:
- Taking into account the requirements for data protection
- The application of specific regulations
- Involving staff in security
- Imposing rules on service providers
- Support and assistance.
To achieve this, they must choose specialized providers who understand the specificities of this sector and who are essential to integrate. It is also necessary to remember that these structures are highly diverse, and we observe a heterogeneity regarding:
- IT equipment, medical devices, software, information systems, and more. In any country, we see large government agencies with hundreds of thousands of civil servants alongside very small municipalities. For example, the education system involves both students and teachers across various IoT systems, which explains why national education and higher education sectors have specific cybersecurity needs.
- the diversity of personnel, roles, organizations, and processes.
The public sector has embarked on an essential digital transformation, accelerated by recent events (the pandemic, the crisis in Ukraine, etc.). The watchword is resilience, which requires:
- Better visibility across an expanded attack surface (IoT and OT protection), and the expertise to cover all these assets.
- Catching up on technological lag
Transition to the cloud
39% of public organizations worldwide have adopted the cloud as their primary IT operating model. [8]
Cloud deployment and planning: “cloud-centric” is also on the list of challenges this sector must address.
- The public sector has made this choice for budgetary reasons, allowing for multiple providers and thus avoiding dependence on a single cloud vendor, as well as to facilitate customization.
- Another advantage of the shift to the cloud for this sector concerns application mobility.
- Finally, it also allows governments to gain greater flexibility.
Competitiveness
To secure funding, this sector must define its cybersecurity requirements during the public procurement process.
- The pandemic forced this sector to invest in security: 50% based on AI, 40% on upgrading existing IT infrastructure.
- Strategic imperatives remain: the issue of data storage and the implementation of 5G to maintain a competitive edge.
Solutions for public organizations and data security
A public-private partnership
The public sector will struggle significantly to recruit cyber talent. This sector is already facing a severe shortage, so the solution is to work with specialized companies like TEHTRIS. The public and private sectors are cooperating to strengthen cybersecurity.
By pooling our resources and adding an automated incident response, we learn from one another and fight attackers more effectively. TEHTRIS understands this well, and the public sector has trusted the company for several years.
Examples include the collaboration between the police and the private sector. Police authorities have the power and capability to arrest cybercriminals, seize their equipment, and destroy their infrastructure, while the private sector contributes by anticipating and analyzing cybercriminal attack techniques and providing information on data flows and threats.
The Campus Cyber is proof that mindsets are changing: many OIVs (operators of vital importance) and OSEs (operators of essential services) are present in this ecosystem to share threat intelligence and understand how it evolves. Many private companies are present on-site, including TEHTRIS. The Numeum cybersecurity commission is also working toward this goal.
Data privacy
The other concern for the public sector involves data privacy. Private and public stakeholders must be independent. We must strengthen our economic and digital sovereignty.
Given the value of data, it is imperative to ensure it does not get lost or fall into the wrong hands. Where is the data stored? Who has access to it? Is it secure? TEHTRIS offers a sovereign solution. Our sovereign XDR, developed and hosted in France and Europe, can be interfaced with your existing cybersecurity solutions to improve their performance (Open XDR). TEHTRIS XDR operates 24/7 and is labeled "Used by the French Armed Forces."
Other initiatives are emerging, such as the TeleTrusT "IT Security made in EU" initiative and "Cybersecurity made in Europe," via our partner ECSO.
Furthermore, choosing TEHTRIS means ensuring you have local teams capable of supporting you operationally and on-demand in R&D. It is more productive to have local teams than teams thousands of miles away.
A financial boost
In France, the government is committed and recognizes the urgency, as evidenced by the France Relance project, which plans to release 136 million euros. The ANSSI website details the plan here: https://www.ssi.gouv.fr/actualite/france-relance-et-cybersecurite-proteger-letat-et-les-collectivites-territoriales/
You can find the breakdown of the funding that makes up the national cyber strategy on the government website: https://www.entreprises.gouv.fr/fr/strategies-d-acceleration/strategie-d-acceleration-cybersecurite
This plan is designed for small and medium-sized organizations, agencies, and both public and private entities.
There are two options: one is for "co-financing cyber projects and pathways for existing information systems," and the other is for creating an incubation plan for the regional CSIRT.[10] regional.
In Spain, the government has announced a new measure through the creation of a Cybersecurity Operations Center (COCS) to reduce the number of cyberattacks. This center aims to assist the General State Administration (AGE) and its public bodies. In addition to this initiative, the "Shock Plan" includes measures such as protection against malicious code, the expansion of cyber threat detection services on user devices, and the implementation of remote access monitoring.
Awareness
43% of public sector respondents say they are "not at all informed" about cyber risks.[11]
It is essential to pair any technical arsenal with awareness of good digital habits. Even though local elected officials are now fully aware of cyber risks, it is important to continue training plans and simulations for this group. It is crucial to understand both internal and external threats.
The website cybermalveillance.gouv.fr offers various awareness and training initiatives through videos, campaigns, and resources.
France is ranked 12th in cybersecurity awareness among the 28 countries of the European Union. [12]
Many public organizations help support this awareness; we have mentioned ANSSI, but theEC3 also fights against cybercrime, ENISA The European Union Agency for Cybersecurity handles IT security expertise at the European level. In France, CERT-FR, the government center for monitoring, alerting, and responding to computer attacks, handles alerts and responds to cyberattacks.
Robust and tailored technology
The attack surface of public organizations is growing, becoming more complex, and harder to defend. Maintaining visibility across these IT estates can be challenging. It is essential to secure infrastructure, critical assets and data, the cloud, IoT, and more.
Robust policies and frameworks are fundamental to creating more secure environments. Modernizing IT platforms is a priority. Security teams need better collaboration tools to defend against future cyberattacks. It is imperative to combat these cyberattacks using high-performance tools. Cyber protection is a key issue for public sector entities.
We help government agencies, regions, public services, and municipalities protect their information systems. Depending on the IT, IoT, or OT systems we need to protect, TEHTRIS offers its EDR, Mobile Threat Defense, SIEM, and Deceptive Response technologies.
Our solution protects all your Windows, Linux, and Mac OS.
A key differentiator for TEHTRIS is its compatibility with older versions of Windows, Linux, and Mac, which is of the utmost importance for public administrations.
Public sector organizations must reduce the time between compromise and detection, ensuring that attacks are identified as early as possible.. XDR solutions from TEHTRIS are highly automated and respond in real time. This agility is a real asset for securing your perimeter.
Our team of specialists is available to support you.
[1] Cyber Defense Command (MCCE).
[2] Fortinet 2022 Analysis
[3] https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/etude-cybersecurite-collectivites-moins-de-3500-habitants
[4] "Public Sector IT in 2022: Tackling Shadow IT in a Hybrid World" report by NinjaOne. 2022
[5] "Public Sector IT in 2022: Tackling Shadow IT in a Hybrid World" report by NinjaOne. 2022
[6] Personal data breach
[7] https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/etude-cybersecurite-collectivites-moins-de-3500-habitants
[8] According to Vanson Bourne. 2022
[9] https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/etude-cybersecurite-collectivites-moins-de-3500-habitants
[10] Regional Cyber Incident Response Centers
[11] Study conducted by Infopro. 2021
[12] BDO Cyber Threat Insights - Q4 2018

