Back to blogCybersecurity

ANSSI recommendations: the essential cyber hygiene guide for SMEs

NRNicolas Renard·February 16, 2026· 11 min read

ANSSI, the French national cybersecurity agency, is the reference authority for cybersecurity in France. Its cyber hygiene guide lists a set of simple, non exhaustive measures that rule out most of the common incident scenarios observed in companies.

Why rely on ANSSI recommendations

Close-up of hands typing on a laptop keyboard, illustrating good computer hygiene practices

These recommendations are not obtained like a certification: they are implemented, and nothing formally attests that they are. That is both their strength and their limit. They are free, public and designed for organizations of any size, including the smallest structures without internal technical expertise, but they carry no label that can be shown to a client, an insurer or a partner, unlike an ISO 27001 certification.

What the numbers say about the urgency of acting

In its 2024 Cyber Threat Overview, ANSSI handled 4,386 security events, up 15% year over year, and confirmed 144 ransomware compromises. SMEs account for 37% of recorded ransomware victims, more than any other category of organization. On the Cybermalveillance.gouv.fr side, the French public assistance service for cyberattack victims, assistance requests topped 420,000 in 2024, up nearly 50% year over year, with phishing remaining the top threat reported by companies. Yet according to the OpinionWay 'Cyber Impact' study commissioned by Cybermalveillance, 68% of SMEs spend less than €2,000 a year on IT security. It is precisely the simplest and least costly measures in the ANSSI guide, such as multi factor authentication or tested backups, that are most often missing.

Cybersecurity Diagnostic·See a diagnostic preview

The priority measures to put in place

ThemeRecommended measure
AuthenticationStrong passwords and multi factor authentication on sensitive accounts
UpdatesSystematic application of security patches, on both workstations and servers
BackupsRegular, tested backups, isolated from the main network
Accounts and accessSeparation of administrator accounts from standard user accounts
NetworkNetwork segmentation and filtering of inbound and outbound traffic
AwarenessEmployee training on phishing and social engineering risks

Going further: other useful measures from the ANSSI guide

The full ANSSI guide includes 42 recommendations, grouped into broad themes. Beyond the priority baseline, several additional measures are worth implementing once the fundamentals are in place:

  • Keep an up-to-date inventory of user and privileged accounts, and review it at every departure or role change.
  • Limit administrator rights on workstations to the strict minimum, including for technical teams.
  • Separate personal and professional use on devices and email accounts.
  • Encrypt sensitive data on mobile devices and removable media.
  • Define an incident handling procedure known to everyone, even a basic one, rather than improvising it on the day.
  • Contractually bind vendors with access to the information system, particularly on security and incident notification clauses.

A progressive rather than exhaustive rollout

  1. Identify the measures already in place, without judgment.
  2. Prioritize the measures whose absence exposes the organization to the highest risk (authentication, backups).
  3. Plan the rollout of missing measures over several months rather than aiming for immediate completeness.
  4. Document the measures applied, so they can be demonstrated when needed (cyber insurance, tenders, audits).

Common mistakes

  • Assuming cybersecurity is reserved for large companies.
  • Deploying tools without reviewing practices: an antivirus does not replace a backup policy.
  • Training teams only once, with no regular refresher.
  • Treating the guide as a one-time checklist, when it assumes ongoing vigilance against evolving threats.

Checking, measure by measure, which of these recommendations are already applied and which ones remain to be prioritized produces a far more useful roadmap than a list of good intentions nobody has verified.

Ready to assess your organization?

Try for free