If your company or your authority falls victim to a hack, a payment fraud or a ransomware attack, the first useful reflex has a name: 17Cyber. It is the free one-stop service set up in late 2024 by the French Ministry of the Interior and Cybermalveillance.gouv.fr, the national cybersecurity assistance platform, and it is open around the clock: an online diagnostic points you in the right direction according to the type of attack, and where the case warrants it, police officers and gendarmes support you through the first hours. This article explains how to use it in practice, and above all how to reduce the risk of ever having to.
How 17Cyber works for an organisation
17Cyber.gouv.fr is a public online assistance service, for individuals as much as for companies, associations and public authorities. The principle is simple: you describe your situation by answering a few questions, and the tool identifies the type of threat you are facing (account takeover, phishing, ransomware, payment fraud, extortion, denial of service, and so on). You then receive tailored recommendations and, where relevant, the steps to take.
What is new compared with the previous Cybermalveillance.gouv.fr route is the direct link with law enforcement. For threats that warrant it, a police officer or a gendarme takes over by messaging to give first-response advice and help you start the judicial formalities, filing a complaint in particular. For an SMB or a town council discovering an incident on a Sunday evening, knowing immediately who to turn to saves valuable time.
For professionals, 17Cyber also points to listed cybersecurity providers, able to step in to analyse the incident, restore the system and secure it. IT1 Connect is one of those providers listed on Cybermalveillance.gouv.fr. One point is worth stating plainly from the outset: being put in touch through the platform leads to a quote. This is professional work (diagnosis, remediation, hardening), not a free service. Many victims arrive from the public scheme without having read that detail and are surprised to find the support is chargeable. Better to know in advance: calling on a qualified provider is an investment, whether you do so in an emergency or, preferably, beforehand. Because this link in the chain comes into play once the attack has happened, whereas the ideal is to already have someone who knows your environment before the incident occurs.
Why this reflex matters: the 2025 threat picture in figures
The 2025 activity report from Cybermalveillance.gouv.fr, published in March 2026, confirms a trend that concerns organisations in the Provence-Alpes-Côte d’Azur region directly. The scheme passed the mark of 500,000 victims assisted over the year, up 20 % on 2024. Behind that volume, several signals point at professionals.
Phishing ranks first among threats across all audiences, up 70 %, fed by the year’s many data breaches (assistance requests linked to data breaches jumped 107 %). Account takeover is the leading threat aimed specifically at professionals, up 45 %. And when an account falls, what follows is often financial: payment fraud is up 170 %, now extended to electronic invoicing and payroll management. Finally, online harassment, which can target the reputation of a company or an elected official, is up 205 % for companies and 209 % for public authorities.
These figures describe a simple mechanism: data leaks, an account is compromised, a fraud follows. Micro-businesses and SMBs are not outside the picture, quite the reverse. The 2025 national cyber maturity barometer for micro-businesses and SMBs shows that while 44 % of them now feel highly exposed, three quarters spend less than 2,000 euros a year on their cybersecurity. Awareness is rising, budgets are not following: it is precisely that gap which turns an attempt into an incident.
17Cyber repairs, it does not protect
It is worth being clear about what 17Cyber is, and what it is not. It is a scheme for assistance and guidance, called on once the attack has happened. It helps you understand, react and file a complaint. It does not back up your data for you, does not segment your network and does not detect the intrusion before it does damage.
In other words, turning to 17Cyber should remain plan B. The real objective for a director or an IT manager is not to depend on an emergency service, because preventive measures have already absorbed most of the risk. An attack that is avoided, or contained on an isolated workstation, is not counted in days of lost business.
Preparing so that you never have to call 17Cyber
The good news is that the measures which push these threats back are well known and within reach, including for an organisation with limited means. We go into detail in our article on the 5 priority measures for SMBs; four areas of work cover most of the scenarios described by the 2025 report:
- Lock down access. Since account takeover is the leading threat for professionals, multi-factor authentication on mail, remote access and privileged accounts is the measure with the best effort-to-protection ratio. Combined with a password policy, it cuts off most intrusions using stolen credentials.
- Back up, and test the restores. A backup that follows the 3-2-1 rule (three copies, two media, one off site), checked regularly to confirm it really does restore, turns ransomware into a technical incident rather than a shutdown.
- Segment the network. Partitioning, which our teams implement on Stormshield firewalls (French technology certified by ANSSI, the national cybersecurity agency) and Alcatel-Lucent OmniSwitch switches, stops an attack spreading from one compromised workstation to the whole information system.
- Detect and monitor. EDR-type endpoint protection, such as the Trend Micro solutions we deploy, together with centralised monitoring and logging, makes it possible to spot abnormal behaviour early, while there is still time to act.
None of this demands a budget out of reach. What makes the difference is doing it in the right order, according to your real exposure, rather than stacking up tools without a plan. The same logic of anticipation applies to regulation: the NIS 2 directive will soon impose these fundamentals on many SMBs, mid-sized companies and public authorities.
In practice, for your organisation
Write the 17Cyber reflex down and put it where your teams will see it: whenever there is doubt about a message, an account or a suspicious transfer, going through 17Cyber.gouv.fr saves time and prevents wrong moves. But do not stop there. A review of your exposure, followed by a prioritised action plan, is worth more than reacting under pressure.
IT1 Connect works with SMBs, mid-sized companies and public authorities across the Provence-Alpes-Côte d’Azur region on both sides: prevention (strong authentication, tested backups, Stormshield and OmniSwitch segmentation, Trend Micro protection, monitoring and managed services over the long term) and response, with an engineer who already knows your environment on the day an incident happens. To review your level of protection, or simply to find out where to start, call +33 4 22 14 04 63.
Securing your organisation
- A review of your exposure and of your weak points
- A prioritised roadmap, matched to your size and your means
- Strong authentication, tested backups and network segmentation
- Certified hardware deployed and monitored: Stormshield, OmniSwitch, Trend Micro
- One point of contact who already knows your environment on the day
