A shifting threat landscape
Cyberthreats are constantly changing. Attackers now seek financial or competitive gain and use hybrid methods that blend technology with psychological manipulation. While “classic” attacks such as DDoS persist, artificial intelligence is driving the rise of “Cybercrime 2.0”: sophisticated ransomware, deepfakes, and increasingly realistic CEO fraud, all harder to detect. In this context, no single technology can provide complete protection. True resilience relies on a holistic approach that combines innovation, anticipation, and a shared culture of security — a principle at the heart of the Group’s strategy.
The structuring role of regulations
At Foyer, compliance with the European DORA regulation has translated into a series of concrete, coordinated actions. We have implemented a centralised cyber risk management framework, supported by annual reviews and a dedicated monitoring tool that allows each risk to be identified, assessed, and controlled in a structured manner. In parallel, robust incident management processes ensure rapid detection, thorough analysis, and timely reporting to the authorities within regulatory deadlines — guaranteeing both effective and transparent responses to every event.
Operational resilience is also tested regularly through crisis simulations, penetration testing, business continuity and disaster recovery plans, as well as adversary-type assessments. These exercises help challenge our systems, measure our ability to withstand attacks, and strengthen our responsiveness.
Recognising that security extends beyond corporate boundaries, the Group has also enhanced third-party risk management. Each critical supplier undergoes in-depth due diligence and continuous monitoring to ensure the protection of the entire value chain.
Regulations such as NIS2 and DORA are far more than administrative obligations: they establish a rigorous and measurable risk management framework that reinforces both resilience and corporate security culture. They bring a clear methodology and tangible indicators, ensuring that every investment is justified by a verifiable reduction in residual risk.
people. They can be the first line of defence — or the greatest vulnerability
People at the heart of resilience
Now a central pillar, risk management enables not only the anticipation of threats but also the consideration of a factor too often overlooked: people. They can be the first line of defence — or the greatest vulnerability. Errors, negligence, or lack of vigilance account for a large proportion of security incidents.
Foyer places training and awareness at the core of its cybersecurity strategy. A structured programme — combining phishing simulations, practical exercises, targeted training, and innovative educational tools such as our cybersecurity TV series — helps to firmly embed a culture of vigilance. Each employee thus becomes an active contributor to collective security, capable of adopting the right reflexes — identifying a suspicious message, rejecting an unusual request, or reporting risky behaviour — and contributing directly to the protection of the Group.
From obligation to continuous improvement
Frameworks such as NIS2, DORA, and ISO 27001 embed cybersecurity in a process of continuous improvement. Regular audits, compliance assessments, and mandatory reporting prevent complacency and ensure steady progress in overall security levels.
In a constantly evolving cyber landscape, regulations are not a constraint but a catalyst for transformation
This proactive dynamic of evaluation and enhancement is deeply ingrained within our organisation: every lesson learned from a test, incident, or audit is immediately integrated into our processes. This approach goes far beyond avoiding penalties — it transforms cybersecurity into a sustainable investment, generating value, trust, and performance.
This commitment to improvement fully aligns with our core values of excellence and integrity. By placing rigour, transparency, and quality at the heart of our practices, we ensure not only regulatory compliance but also the safety and peace of mind of our partners and clients, who remain at the centre of everything we do.
Constraint or opportunity?
In a constantly evolving cyber landscape, regulations are not a constraint but a catalyst for transformation. They structure risk management, elevate the human factor, and foster continuous improvement.
At Foyer, we turn them into a genuine strategic lever for resilience and competitiveness — because effective cybersecurity is, above all, a foundation for lasting trust.

