Skip to content

Boozox

References and Portfolio

Why Cybersecurity is Essential to Protect Your Data in 2024

Cybersecurity refers to the set of technical and organizational measures aimed at protecting systems, networks, and data against unauthorized access...

Experte en cybersécurité analysant des données chiffrées sur deux écrans dans un bureau moderne en 2024

Cybersecurity refers to the set of technical and organizational measures designed to protect systems, networks, and data against unauthorized access, modifications, or destruction. In 2024, this discipline is no longer the sole responsibility of the technical department: recent European regulations make it a governance obligation that directly engages leaders.

NIS2 Directive and DORA Regulation: the regulatory framework that changes the game

Two European texts redefine the obligations of organizations regarding cybersecurity. The NIS2 directive was to be transposed by member states before October 17, 2024. It significantly expands the scope of the entities concerned, imposes formalized risk management, notification of significant incidents, and increased accountability for leaders.

In France, the transposition was still not completed by October 2026. This legislative delay places French companies in a zone of legal uncertainty, while other European countries have already adapted their national laws.

The DORA regulation, on the other hand, has been in effect since January 17, 2025. It specifically targets the financial sector: banks, insurers, investment firms, payment service providers, and crypto-asset service providers. DORA covers the management of IT risks, resilience testing, incident notification, and monitoring of critical technology service providers.

These two texts share a common point: data protection is no longer a technical recommendation, it is a legal obligation accompanied by sanctions. Any organization that handles sensitive information (customer data, financial data, health data) must formalize its cybersecurity strategy or expose itself to regulatory consequences.

Risks related to third-party providers: an underestimated vulnerability in cybersecurity

One aspect that general articles rarely address is the management of supplier dependencies. A company can implement rigorous security measures internally while remaining vulnerable through its technology providers. Delving deeper into cybersecurity with Viruslab helps to better understand how these risks are structured and how to anticipate them.

The DORA regulation requires financial entities to maintain a structured register of their IT service contracts. This requirement reveals a principle applicable far beyond finance: every organization depends on software, hosting services, cloud solutions, or maintenance providers, whose compromise can lead to data breaches.

Man working from home managing a cybersecurity alert on his laptop

Specifically, mapping out one’s providers involves answering several questions:

  • Which suppliers have access to the organization’s sensitive data, and at what level of privilege?
  • Do the contracts include notification clauses in case of a security incident at the provider?
  • Are audits or resilience tests regularly conducted on outsourced services?

This approach transforms cybersecurity: it is no longer limited to protecting an internal perimeter; it integrates the entire digital value chain.

Cyberattacks and data protection: what the threat technically implies

Ransomware attacks remain the most visible threat vector. The principle is known: malware encrypts the files of a system and demands a ransom for their return. What has changed is the sophistication of the initial access methods.

Social engineering remains the primary entry point for compromises. A well-crafted phishing email is enough to obtain valid credentials. From there, the attacker moves laterally within the network, elevates their privileges, and accesses the most sensitive data before triggering encryption.

Three technical measures significantly reduce this attack surface:

  • Multi-factor authentication on all privileged accounts, which blocks the majority of access obtained through credential theft.
  • Network segmentation, which limits an attacker’s ability to move from one system to another after an initial intrusion.
  • Access management according to the principle of least privilege: each user only accesses the resources strictly necessary for their function.

These measures are not new. Their effectiveness depends on their actual implementation, not on their existence in an internal policy document.

Leaders’ responsibility: cybersecurity becomes a governance issue

NIS2 introduces a paradigm shift for the organizations concerned. Leaders can be held personally accountable in case of failure to meet risk management obligations. The directive stipulates that governing bodies must approve security measures and oversee their implementation.

This is no longer a topic delegated to the IT manager. Compliance requires decision-makers to understand the cyber risks their organization is exposed to, validate the corresponding budgets, and ensure that teams are trained.

Team of cybersecurity professionals analyzing a network map and threats in real-time in an operations center

For French companies, the delay in transposing NIS2 does not mean that these obligations are postponed. The directive sets a framework that national jurisdictions will need to integrate, and organizations that anticipate this compliance avoid the risk of a rushed catch-up once the text is adopted.

Data protection in 2024 therefore relies on three mutually reinforcing pillars: rigorously applied technical measures, contractual management of providers, and documented involvement of management. The absence of any one of these pillars weakens the entire system, regardless of the size of the organization.

Why Cybersecurity is Essential to Protect Your Data in 2024