"making it possible to immediately mobilize the skills and resources needed by the Agency alongside the ministries concerned," the Agency said in a statement dated September 7.
REACTIV: a new interministerial mechanism at ANSSI
The French national cybersecurity agency (ANSSI) announced on September 7 the creation of a dedicated cyber incident response mechanism named REACTIV — Réponse & Action Interministérielle face aux Violations de données. ANSSI framed the measure as a way to strengthen the agency’s authority by enabling it to mobilize skills and resources alongside ministries concerned during data-breach incidents.
Two explicit prerogatives granted to ANSSI
According to ANSSI’s statement, REACTIV gives the agency two concrete new powers. First, it can require ministries, under tight deadlines, to take immediate measures to protect citizens’ data entrusted to government administrations. Second, it establishes centralized technical crisis communication led by ANSSI in the event of an attack that threatens state services. Those two prerogatives are presented as operational tools to speed response and to coordinate public-sector activity during a breach.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleContext: the DGFiP attack and the prime minister’s response
The announcement arrives a few weeks after the Directorate-General for Public Finance (DGFiP), France’s national tax authority, suffered a major cyber-attack that exposed sensitive and personal data for between 350,000 and 678,000 taxpayers. That incident prompted the French Prime Minister to request an “extensive audit” of ANSSI and the creation of a new incident response unit within the agency — the unit that ANSSI is now naming REACTIV.
Arrests and attribution details tied to the DGFiP incident
In follow-up action related to the DGFiP breach, two individuals, aged 16 and 18, were arrested at the end of August on suspicion of participating in the hack as members of the “ZeroBytes” hacking group. ANSSI’s new mechanism is announced against this backdrop of a high-impact breach and recent detentions tied to that incident.
Resources undisclosed; observers voice skepticism
ANSSI’s statement did not disclose the human or financial resources that will be assigned to REACTIV. That omission has prompted some observers to question whether the initiative will have the “necessary teeth” to deliver on its ambitions. Absent published staffing levels, budgets, or operational details, the new prerogatives can be read as stronger in mandate than in immediately visible capacity.
What this means for ministries, taxpayers, and ANSSI
- Ministries: Under REACTIV, ministries can expect binding, time-limited requirements from ANSSI to implement immediate protective measures for citizen data. That creates a short chain of command for incident mitigation but also obliges ministries to meet deadlines imposed by the national cybersecurity agency.
- Taxpayers (affected citizens): The DGFiP breach exposed between 350,000 and 678,000 taxpayers’ sensitive and personal data. For those citizens, centralized technical crisis communication led by ANSSI is intended to standardize technical messaging when an attack threatens state services.
- ANSSI: The agency gains formal tools to compel ministry action and to lead crisis communications, but it also faces an “extensive audit” at the request of the French Prime Minister and scrutiny over undisclosed resources assigned to REACTIV.
REACTIV ties a new set of powers to an agency already placed at the center of a high-profile breach response and a follow-on audit requested by the prime minister. Whether the mechanism changes outcomes will depend on the details that were not released on September 7: the personnel, budgets, and operational posture that will back the two prerogatives ANSSI has been given. For now, the French government has formalized a faster, centralized route for demanding action and for speaking about technical crises — and in doing so has acknowledged the scale of the challenge laid bare by the DGFiP attack and the arrests connected to it.




