Summary
- France is preparing stronger protection for critical infrastructure and sensitive defence-industrial sites against cyber and drone attacks.
- The government is treating physical security, cyber operations, logistics, energy resilience, and foreign interference as connected risks.
- The approach increases the operational burden on private infrastructure operators and suppliers whose systems support nationally important services.
France is preparing stronger protection for critical infrastructure and sensitive defence-industrial sites as cyber attacks, drones, foreign interference, and physical disruption increasingly converge into the same resilience problem.
The Élysée said President Emmanuel Macron had instructed the government to develop a plan protecting critical infrastructure and particularly sensitive parts of the defence industrial and technological base from drone and cyber attacks following a national-security meeting on 18 September.
French intelligence, military, national-security, and energy officials briefed political leaders on international threats and their domestic consequences, while regional authorities have been asked to raise vigilance. The presidency connected the measures with what it describes as an intensification of Russian hybrid threats in Europe, including cyber activity, foreign interference, and physical attacks.
The programme is therefore broader than a conventional cybersecurity initiative. Cyber defence sits beside protection from drones, disruption to energy and logistics, and attacks on strategically important facilities, reflecting the way infrastructure operators increasingly have to prepare for incidents that cross digital and physical systems.
Digital systems now sit inside physical resilience
Critical infrastructure has long depended on industrial control systems, communications networks, remote monitoring, and connected suppliers, although responsibility for those systems is often organisationally fragmented. Cyber teams protect networks, facilities teams manage access, and continuity specialists plan around outages even when a real attacker has no reason to respect those boundaries.
A drone near a power facility, for example, creates a physical-security problem while also forcing operators to assess sensors, communications, operational technology, and whether simultaneous network activity forms part of the same incident. A cyber attack against an energy or logistics operator can produce equally physical consequences without anyone crossing a perimeter.
The French approach fits a wider European shift towards resilience models that treat infrastructure as interconnected systems rather than isolated assets. Communications, energy, transport, public services, and industrial production all rely on technology chains in which disruption at one provider can spread far beyond that organisation.
Recent work around embedded security in connected machines illustrates the same convergence at equipment level: once software controls a physical process, cybersecurity becomes part of operational safety and continuity rather than an external IT control.
Defence industry broadens the supply chain
Including sensitive defence-industrial sites gives the French plan an additional economic dimension. European governments are increasing defence investment and seeking additional manufacturing capacity, making factories, component suppliers, communications systems, and logistics networks more consequential to national resilience.
Those environments can contain cloud-connected services alongside legacy equipment and specialised operational technology. Protecting them therefore requires more than securing a single corporate network, because disruption can enter through software suppliers, contractors, telecommunications providers, energy systems, or the physical movement of components.
Macron also pointed to France’s existing work against foreign digital interference through structures including VIGINUM. The latest instructions extend that posture towards attacks where physical and digital effects may be coordinated rather than treated independently.
Much of Europe’s critical infrastructure is privately operated, while defence manufacturers rely on long supplier chains extending into businesses that may never have considered themselves part of national-security planning. Higher resilience expectations can consequently travel well beyond the largest utilities or defence groups.
Compliance does not guarantee readiness
European regulation is already increasing security obligations through measures including NIS2 and the Critical Entities Resilience framework. Even so, an organisation can satisfy governance requirements while remaining poorly prepared for an incident affecting networks, premises, power, suppliers, and communications at the same time.
Exercises become more important under that model because technology teams need to understand how facilities staff, executives, authorities, emergency services, vendors, and communications functions will behave when several operational assumptions fail together.
Backup systems also need testing against scenarios in which the primary site or supporting utility is unavailable, rather than merely against the failure of an individual server. Resilience becomes a property of the wider service chain rather than a checklist attached to one technology environment.
France has not yet published the detailed protection plan described by Macron, so its exact obligations, financing, and timetable remain open. The government’s framing already shows the direction, however: cybersecurity is being folded into a wider defence of industrial capacity and continuity, placing technology operations firmly inside the protection of the physical economy.












