The French Approach to Cybersecurity in the Energy Sector
摘要
The very specific nature of the French energy sector, when compared to other major Western countries, with a very important share of nuclear is the legacy of French energy independence policy during the 1950–1980s. This specific orientation toward nuclear considered as an energy security issues, following the two “oil shocks,” tended to structure a national energy sector where the central administration and state-owned companies had the upper hand over most aspects. This very strong centralization—usual within the French policy context—also helped to have a centralized approach of security regarding all energy facilities with the central role of SGDSN. This orientation soon extended to cybersecurity aspects and policy with the elaboration of the “critical operator” concept and the management of cybersecurity requirements and regulation for critical operators under the French Prime Minister administration (SGDSN and ANSSI). Interagency cooperation under the umbrella of SGDSN, encompassing MoD, Ministry of Interior, and ministry in charge of energy, allowed the development of a unified policy regarding cybersecurity, also including some privacy elements with the 1978 “Loi Informatique et Libertés.” The central approach to cybersecurity in the energy sector also helped France to be at the forefront of EU legislation elaboration, especially NIS Directive, which was based on the similar mechanism of “critical operator” for the cybersecurity incident management and requirements. Yet this administrative and legal architecture is perfectly suitable for a very centralized energy sector, with a few facilities and companies in charge of production, transportation, and distribution. The evolution coming with the energy transition, including the decentralization of production and consumption, and the rise of prosumers, yet poses a dilemma to the French administration and advocates for an evolution of this framework.