{"id":26349,"date":"2025-06-18T15:46:15","date_gmt":"2025-06-18T14:46:15","guid":{"rendered":"https:\/\/www.riskinsight-wavestone.com\/?p=26349"},"modified":"2025-06-19T08:25:55","modified_gmt":"2025-06-19T07:25:55","slug":"enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification","status":"publish","type":"post","link":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/","title":{"rendered":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification"},"content":{"rendered":"\n<h1><span data-contrast=\"auto\">A new guide amid growing attention to industrial cybersecurity<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h1>\n<p><span data-contrast=\"auto\">As cyber threats become more targeted, sophisticated and persistent\u2014particularly against industrial systems and critical infrastructure\u2014the ANSSI (French Cybersecurity Agency) has strengthened its cybersecurity framework by publishing a revamped version of its guide for the classification of industrial systems, originally released in 2012.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This guide is intended for all stakeholders involved in industrial system security: operators, operators of vital importance (OIV), essential service operators (OES), integrators, and service providers responsible for aligning technical requirements with business imperatives.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Its aim is to provide a methodology for determining the criticality of industrial systems, classifying them into one of four cybersecurity levels\u2014<\/span><i><span data-contrast=\"auto\">minor, moderate, major or catastrophic<\/span><\/i><span data-contrast=\"auto\">\u2014based on the maximum severity of potential impacts on: the population, the economy, and the environment. This classification helps identify the appropriate level of security needed and guides the implementation of cybersecurity measures.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-26342 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1.png\" alt=\"\" width=\"1567\" height=\"543\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1.png 1567w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1-437x151.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1-71x25.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1-768x266.png 768w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo1-1536x532.png 1536w\" sizes=\"auto, (max-width: 1567px) 100vw, 1567px\" \/><\/p>\n<p style=\"text-align: center;\"><i><span data-contrast=\"none\">Figure 1: The 4 cybersecurity classes of the guide<\/span><\/i><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\">\u00a0<\/span><\/p>\n<h1><span data-contrast=\"auto\">Why revisit the existing framework?<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h1>\n<p><span data-contrast=\"auto\">The first edition of the classification guide, published in 2012, laid the foundation for a tiered security approach by introducing a three-class segmentation model based on risk (impact \u00d7 likelihood).<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-26338 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2.png\" alt=\"\" width=\"1567\" height=\"685\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2.png 1567w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2-437x191.png 437w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2-71x31.png 71w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2-768x336.png 768w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo2-1536x671.png 1536w\" sizes=\"auto, (max-width: 1567px) 100vw, 1567px\" \/><\/p>\n<p style=\"text-align: center;\"><em>Figure 2: Key differences between the first and second versions of the guide\u00a0<\/em><\/p>\n<p><span data-contrast=\"auto\">While this initial version played a key role in fostering a culture of industrial cybersecurity in France\u2014at a time when sector-specific references were still scarce\u2014it encountered several limitations over time.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Firstly, the integration of likelihood into the classification process led to a so-called &#8220;<\/span><i><span data-contrast=\"auto\">looping effect<\/span><\/i><span data-contrast=\"auto\">&#8220;, as described in the new guide. As security measures were implemented, the likelihood of an attack was considered to decrease, which in turn could lower the system\u2019s classification level. This phenomenon compromised the stability of classification over time, making it difficult to maintain consistency between classification and actual protective measures.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Moreover, the initial guide proposed only three classes, which resulted in systems being assigned to the highest one too often. There was also a lack of granularity in perimeter definition and limited alignment with international standards such as IEC 62443.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The new version addresses these challenges by basing classification exclusively on impact, ensuring more stable classifications, consistent comparisons between zones, and better integration with structured risk analysis frameworks like EBIOS RM. This evolution also makes the approach more adaptable to the diversity and complexity of modern industrial systems.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h1><span data-contrast=\"auto\">A methodology compatible with existing frameworks<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h1>\n<p style=\"text-align: center;\"><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-26334 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo3.png\" alt=\"\" width=\"603\" height=\"498\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo3.png 1042w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo3-231x191.png 231w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo3-47x39.png 47w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo3-768x635.png 768w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" \/><\/span><i><span data-contrast=\"none\">Figure 3: Classification methodology diagram from the new guide<\/span><\/i><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The new methodology is structured around three key activities:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li><span data-contrast=\"auto\">Definition of the technical perimeter<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Segmentation into coherent zones<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Classification of each zone based on the potential severity of impacts in case of compromise<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ol>\n<p><span data-contrast=\"auto\">This approach enables organizations to assign each zone to one of the four cybersecurity classes according to the severity of potential impacts. It provides a rational and scalable understanding of security needs, with a focus on two key criteria: availability and integrity, which align with the core concerns of industrial environments.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The guide does not replace risk analysis frameworks but is designed to integrate seamlessly with them. It was specifically built to feed into EBIOS RM workshops, providing a classification baseline that supports the identification of feared events and associated security measures. This structure eliminates the need to adapt or distort EBIOS RM to accommodate industrial contexts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The guide also draws on concepts from IEC 62443, such as zones, conduits, and security levels, helping align with international industrial cybersecurity best practices.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This alignment is part of a broader push toward a structured deployment of cybersecurity. The guide provides a practical framework organized around key thematic areas, as illustrated below, to help effectively integrate cybersecurity into industrial environments.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p style=\"text-align: center;\"><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-26330 aligncenter\" src=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo4.png\" alt=\"\" width=\"415\" height=\"406\" srcset=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo4.png 865w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo4-195x191.png 195w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo4-40x39.png 40w, https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/annsi_vo4-768x752.png 768w\" sizes=\"auto, (max-width: 415px) 100vw, 415px\" \/><\/span><i><span data-contrast=\"none\">Figure 4: Key themes for deploying cybersecurity (Chapter 3.1 of the guide)<\/span><\/i><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\">\u00a0<\/span><\/p>\n<h1><span data-contrast=\"auto\">What comes next: a detailed measures guide \u2014 bridging the gap between strategy and action<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h1>\n<p><span data-contrast=\"auto\">Expected in the coming months, the detailed measures guide is the logical continuation of the classification methodology. It aims to equip industrial stakeholders with practical tools to move from theory to implementation, translating the cybersecurity classes into concrete operational requirements.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Inspired by the 2012 guide, which already proposed a set of baseline measures for each class, this new version promises a more refined, up-to-date approach that reflects current threat landscapes and security practices. It will offer decision-makers and system owners a clear and actionable toolbox, detailing technical, organizational, and human measures adapted to the criticality level of each zone.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Scheduled for publication in 2025, the guide will ensure continuity with risk analysis and compliance efforts already underway, while clarifying expectations regarding the concrete implementation of protective measures.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h1><span data-contrast=\"auto\">Securing the present, anticipating the future<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h1>\n<p><span data-contrast=\"auto\">Beyond its publication, the real challenge now lies in adopting the methodology and integrating it into the cybersecurity strategies for both existing and upcoming industrial systems.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For existing systems, the new guide naturally fits into the security lifecycle recommended by ANSSI in its EBIOS RM guide. Impacts should be assessed on a case-by-case basis to determine whether modifying current architectures is worthwhile, weighing the cost of change, evolving business needs, and expected security benefits. Integration can occur:\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">During the strategic cycle, typically conducted periodically or following a major change, which offers an opportunity to revise perimeter definitions, update functional zones, and reassess system classifications using the new methodology;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Or during the operational cycle, focused on reviewing feared events, checking whether existing measures align with the defined cybersecurity classes, and adjusting protection strategies as needed.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">For new industrial projects, the new guide officially replaces the 2012 version and should be incorporated from the earliest design phases. It provides a framework for building a secure architecture aligned with business priorities, while also easing compliance with current and upcoming regulatory frameworks (NIS2, LPM, etc.) or contractual obligations.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">At Wavestone, we are integrating this guide into our industrial cybersecurity maturity evaluation framework and Cyber Benchmark methodology, alongside international standards such as IEC 62443 and NIST SP 800-82. All that remains is to wait for the operational measures guide to complete the picture!<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new guide amid growing attention to industrial cybersecurity\u00a0 As cyber threats become more targeted, sophisticated and persistent\u2014particularly against industrial systems and critical infrastructure\u2014the ANSSI (French Cybersecurity Agency) has strengthened its cybersecurity framework by publishing a revamped version of its&#8230;<\/p>\n","protected":false},"author":1347,"featured_media":26361,"comment_status":"open","ping_status":"closed","sticky":false,"template":"page-templates\/tmpl-one.php","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2777,3977,3274],"tags":[],"coauthors":[3141],"class_list":["post-26349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-digital-trust","category-focus","category-manufacturing-industry-4-0-en"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight\" \/>\n<meta property=\"og:description\" content=\"A new guide amid growing attention to industrial cybersecurity\u00a0 As cyber threats become more targeted, sophisticated and persistent\u2014particularly against industrial systems and critical infrastructure\u2014the ANSSI (French Cybersecurity Agency) has strengthened its cybersecurity framework by publishing a revamped version of its...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\" \/>\n<meta property=\"og:site_name\" content=\"RiskInsight\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-18T14:46:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-19T07:25:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1855\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lo\u00efc Lebain\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lo\u00efc Lebain\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\"},\"author\":{\"name\":\"Lo\u00efc Lebain\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/b74db063222565f0b973370928e4815c\"},\"headline\":\"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification\",\"datePublished\":\"2025-06-18T14:46:15+00:00\",\"dateModified\":\"2025-06-19T07:25:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\"},\"wordCount\":991,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg\",\"articleSection\":[\"Cybersecurity &amp; Digital Trust\",\"Focus\",\"Manufacturing &amp; Industry 4.0\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\",\"name\":\"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight\",\"isPartOf\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg\",\"datePublished\":\"2025-06-18T14:46:15+00:00\",\"dateModified\":\"2025-06-19T07:25:55+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg\",\"width\":2560,\"height\":1855},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#website\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"name\":\"RiskInsight\",\"description\":\"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants\",\"publisher\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#organization\",\"name\":\"Wavestone\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"contentUrl\":\"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png\",\"width\":50,\"height\":50,\"caption\":\"Wavestone\"},\"image\":{\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/b74db063222565f0b973370928e4815c\",\"name\":\"Lo\u00efc Lebain\",\"url\":\"https:\/\/www.riskinsight-wavestone.com\/en\/author\/loic-lebain\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/","og_locale":"en_US","og_type":"article","og_title":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight","og_description":"A new guide amid growing attention to industrial cybersecurity\u00a0 As cyber threats become more targeted, sophisticated and persistent\u2014particularly against industrial systems and critical infrastructure\u2014the ANSSI (French Cybersecurity Agency) has strengthened its cybersecurity framework by publishing a revamped version of its...","og_url":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/","og_site_name":"RiskInsight","article_published_time":"2025-06-18T14:46:15+00:00","article_modified_time":"2025-06-19T07:25:55+00:00","og_image":[{"width":2560,"height":1855,"url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg","type":"image\/jpeg"}],"author":"Lo\u00efc Lebain","twitter_misc":{"Written by":"Lo\u00efc Lebain","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#article","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/"},"author":{"name":"Lo\u00efc Lebain","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/b74db063222565f0b973370928e4815c"},"headline":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification","datePublished":"2025-06-18T14:46:15+00:00","dateModified":"2025-06-19T07:25:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/"},"wordCount":991,"commentCount":0,"publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg","articleSection":["Cybersecurity &amp; Digital Trust","Focus","Manufacturing &amp; Industry 4.0"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/","url":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/","name":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification - RiskInsight","isPartOf":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage"},"thumbnailUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg","datePublished":"2025-06-18T14:46:15+00:00","dateModified":"2025-06-19T07:25:55+00:00","breadcrumb":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#primaryimage","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2025\/06\/mihaly-koles-SRhUCjVBuVs-unsplash-scaled.jpg","width":2560,"height":1855},{"@type":"BreadcrumbList","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/2025\/06\/enhancing-industrial-cybersecurity-changes-introduced-by-the-new-anssi-guide-for-industrial-systems-classification\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.riskinsight-wavestone.com\/en\/"},{"@type":"ListItem","position":2,"name":"Enhancing Industrial Cybersecurity: Changes Introduced by the New ANSSI Guide for Industrial Systems Classification"}]},{"@type":"WebSite","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#website","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","name":"RiskInsight","description":"The cybersecurity &amp; digital trust blog by Wavestone&#039;s consultants","publisher":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.riskinsight-wavestone.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#organization","name":"Wavestone","url":"https:\/\/www.riskinsight-wavestone.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","contentUrl":"https:\/\/www.riskinsight-wavestone.com\/wp-content\/uploads\/2021\/08\/Monogramme\u2013W\u2013NEGA-RGB-50x50-1.png","width":50,"height":50,"caption":"Wavestone"},"image":{"@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.riskinsight-wavestone.com\/en\/#\/schema\/person\/b74db063222565f0b973370928e4815c","name":"Lo\u00efc Lebain","url":"https:\/\/www.riskinsight-wavestone.com\/en\/author\/loic-lebain\/"}]}},"_links":{"self":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/26349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/users\/1347"}],"replies":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/comments?post=26349"}],"version-history":[{"count":3,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/26349\/revisions"}],"predecessor-version":[{"id":26356,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/posts\/26349\/revisions\/26356"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media\/26361"}],"wp:attachment":[{"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/media?parent=26349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/categories?post=26349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/tags?post=26349"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.riskinsight-wavestone.com\/en\/wp-json\/wp\/v2\/coauthors?post=26349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}