[ad_1]
Protecting sensitive data? This is obvious to everyone in a digital economy that feeds on data to create added value. It is when it is necessary to pass to the phase of qualification that the task becomes more difficult: personal data, financial information, research and development work, terms of commercial negotiations…
All of this naturally falls into the category of secrecy and confidentiality. But what about certain correspondence, preparatory work, ancillary contracts and other technical statements? They do not deserve a priori any particular security, however they constitute a mine of information which can prove to be extremely revealing if they land in expert hands.
To the point of constituting choice targets for foreign entities, which then conduct legal proceedings or administrative steps ad hoc in order to recover these files. This permanently weakens the targeted companies. This mode of appropriation, which exploits institutional, judicial or administrative mechanisms, has led to the promulgation of the Law n° 68-678 of July 26, 1968 known as the blocking law, relating to the communication of documents and information of an economic, commercial, industrial, financial or technical nature to foreign individuals or legal entities.
Reform of the “blocking” law
In 2022, it was necessary to to bring him some elements of modernity in the face of the intensification of these sometimes very intrusive communication procedures. A necessity increased by the plurality of the information henceforth produced and being able henceforth to be the object of exploitations until then very theoretical.
It is thus that a decree of February 18, 2022 and a order of March 7, 2022 expand the list of information that may not be disclosed in the event of a request from abroad. For example, it includes details of insurance coverage, particularly in the area of cybersecurity. It also includes legal opinions on compliance or internal audits, which may allow access to internal control plans in the area of information systems security.
Support for companies
In case of doubt as to the nature, detail or period of information that may be transmitted to foreign authorities, private or public, the French Ministry of the Economy has set up a support system for companies within the Strategic Information and Economic Security Department (SISSE). A centralized point of contact can be reached at loi.deblocage@finances.gouv.fr to ensure that the possible provision of information requested by bodies outside France does not constitute a risk to the strategic interests of the Nation.
A guide co-written by the Medef and the French Association of Private Enterprises (AFEP) in March 2022 will be useful in assessing the criticality of the information that may be the subject of these external solicitations, which are not always benevolent but very interested. This approach to evaluating the information assets of companies is one of the essential components of a security policy that takes into account the evolution of criteria for assessing the value of economic actors. A salutary exercise in the face of constantly changing organizations.
Nicolas ArpagianTrend Micro’s Director of Cybersecurity Strategy
Author of Frontières.com, Editions de l’Observatoire (2022)
The opinions of experts are published under the whole responsibility of their authors and do not engage the editorial staff
[ad_2]


