Highlights: AGRÉPI technical day 2026

by SPAC Alliance | June 2026 | News

Highlights from the AGRÉPI Technical Day, held on 11 June 2026 at SMABTP’s premises under the theme “Cyber risk in safety and security”. Presentations, first-hand accounts and discussions, followed by a round-table session, provided valuable insights and clarification as several major deadlines, including the NIS 2 Directive and the CRA, draw closer.

Security presentations

Following an introduction by Laurence Marchal, President of AGRÉPI, we attended five presentations exploring several aspects of security.

  • Regulation and cybersecurity: challenges, objectives, entities in scope and timeline (Ronan JEZEQUEL / CNPP)
  • Fire safety and physical security technologies: cybersecurity of connected systems (Ronan JEZEQUEL / CNPP)
  • Securing video surveillance cameras and feedback from a cybersecurity forum (Claire ALBERIO / Orange)
  • The insurer’s perspective: cyber risks and insurance coverage (Frédéric ROUSSEAU / Abeille Assurances)
  • Lessons learned from BPCE: hybrid cyberattacks and defence in depth (Jeremy BEAUDENUIT / BPCE)

The presentations

Ronan Jezequel (CNPP) opened the day with an overview of the major regulatory developments under way, before taking a closer look at the cybersecurity of connected systems. The convergence of physical and cyber threats is now a reality and requires an appropriate response.

Claire Alberio (Orange) then focused on the need to secure video surveillance cameras, which are highly exposed and increasingly targeted. She also shared feedback from a cybersecurity training forum, highlighting the essential role users play in protecting an organisation.

The audience was then given plenty of food for thought by Frédéric Rousseau (Abeille Assurances), who shared an insurer’s perspective and practical examples relating to cyber risk and insurance coverage. The key takeaways included:

  • A 3-2-1 data backup strategy is essential;
  • Malicious insider activity remains one of the most destructive threats;
  • Insurance policies must be reviewed carefully: cyber coverage does not necessarily include compensation for business interruption losses;
  • Declarations made when taking out a policy must be accurate and complete, otherwise coverage may be denied.

The morning concluded with another highly impactful presentation by Jeremy Beaudenuit (BPCE) on hybrid attacks and defence in depth: attacks using petrol-powered angle grinders or ram-raiding techniques, as well as attempts to tamper with access control readers.

Key takeaways

  • The cybersecurity of a system also depends on effective control of its physical access points;
  • The end-to-end security approach promoted by NIS 2 must rely on trusted products compliant with the CRA and form part of solutions aligned with recognised security frameworks.
  • Organisations urgently need to embark on a genuine security roadmap that includes control over the entire supply chain.
  • The quality of evidence is critical in insurance matters. A comprehensive risk-transfer strategy is necessary to ensure effective protection.

Security round-table discussion

The round-table discussion, moderated by Benjamin Cherdrong and Jean-Michel Le Gall, provided an opportunity to explore several topics in greater depth and discuss best practices for achieving compliance.

Evolving systems: a risk that has become systemic

Pierre-Nicolas Carron and Alexandre Baleige (Chubb / Chubb Delta) highlighted the evolution of fire safety systems, which are now highly connected and potentially exposed to cyberattacks with disastrous consequences, such as the silent disabling of fire detection systems. This evolution requires greater accountability across the entire ecosystem: manufacturers, project owners, integrators, maintenance providers, remote monitoring operators, system operators and users. Four key recommendations were identified:

  • Segment networks
  • Implement strong authentication as standard
  • Establish a strict OT patch management policy
  • Maintain a comprehensive inventory of equipment and be able to detect abnormal behaviour in real time

Tangible impacts on operations

Georges Ouffoué (Cyver) and Jean-Sébastien Bonte (Honeywell) focused on OT systems, which have specific vulnerabilities and can be affected by incidents with dramatic consequences. We explored how ransomware caused a fuel shortage in Florida (Colonial Pipeline – 2021) and how a computer worm physically destroyed centrifuges (Stuxnet – 2010). Their recommendations included:

  • Segment systems to limit the tangible impact on users
  • Implement real-time detection capabilities
  • Plan maintenance operations
  • Test degraded operating modes
  • Document procedures and raise awareness

Standards, frameworks and market expectations

Further clarification regarding standards, frameworks and market expectations for fire safety systems was provided by Yohan Corberand (Hikvision) and Ismail Miqdad (Honeywell). Pending the transposition of NIS 2 into French law, several frameworks can already be used to structure an organisation’s approach. These include:

  • The French Cybersecurity Framework ReCyF, designed to support the implementation of NIS 2 in France;
  • ISO 27001, covering information security management systems (ISMS);
  • ISO 27002 and its 93 physical and cybersecurity controls;
  • ISO 27017 and ISO 27018, covering cloud security;
  • EBIOS (ISO 27005), used to identify and understand digital risks, determine appropriate measures and implement a continuous improvement cycle;
  • The APSAD D32 framework for monitoring and detecting cyber incidents and D31, which defines requirements for monitoring centres.

Integrating cybersecurity by design

Yohan and Jean-Sébastien also emphasised the importance of integrating cybersecurity from the design stage. This principle must be understood broadly and applies both to the product itself and to the associated processes. Ideally, several stakeholders should be involved:

  • The manufacturer: designs a reliable product, provides updates and shares best practices;
  • The operator and engineering consultancy: define the technical specifications;
  • The integrator / maintenance provider: follows the technical specifications, installs and commissions the system, provides training and maintains it in operational condition.

Cybersecurity can therefore no longer be treated as a patch added to an otherwise functional product. Once again, security evidence is essential, including documentation, certification and proof of compliance relating to both the product and the partner.

SPAC Alliance conclusion

What does modern security look like?

SPAC Alliance, represented by Tibaud Estienne, was responsible for summarising the round-table discussion. Whether addressing access control systems, fire safety systems or OT, the various first-hand accounts and lessons learned all led to the same conclusions.

Modern security relies on:

  • Clear and documented governance of security within the organisation (ISMS);
  • Products, both hardware and software, that are compliant, certified or independently evaluated (CRA, NF A2P, SSCP Certified, EN 17640 – FITCEM, etc.);
  • Solutions with a demonstrable level of security (APSAD, CSPN, BSZ, etc.);
  • Trusted partners that assume long-term responsibility and provide evidence of their own security maturity (ISO 9001 / 27001, EN 62443, ANSSI qualification, etc.).

Documentation and technical evidence provide the foundation for sustainable security, enabling organisations to anticipate evolving threats, regulatory obligations and technological innovation.

Where should you start?

Every organisation aims to deploy solutions that are suited to both the threats it faces and its regulatory obligations, while being able to demonstrate compliance. The following preliminary steps should form the basis of any security roadmap:

  1. Audit / test your existing system
  2. Create a comprehensive map of your systems, including third-party dependencies
  3. Conduct two assessments: a risk assessment covering physical and cyber risks, and a compliance gap analysis
  4. Develop a set of technical specifications that includes training and awareness requirements
  5. Prioritise the required actions

Ideally, this approach should involve all relevant internal stakeholders (CIO, CISO, security manager and operations manager) and external stakeholders (manufacturers, engineering consultancies, integrators, installers, maintenance providers and insurers).

These initial steps are critical and will directly influence your actual level of security. We therefore recommend involving an independent service provider capable of supporting and managing your security roadmap.

Our service offerings can cover specific or cross-functional assignments, depending on your needs and level of criticality.

Closing remarks

More than ever, a strong security culture can make a real difference, highlighting the importance of organisations such as AGRÉPI and SPAC Alliance in providing ongoing monitoring, sharing relevant lessons learned and helping organisations identify trusted service providers.

We would once again like to thank AGRÉPI for the invitation and SMABTP for hosting the event, as well as all the speakers and exhibitors who contributed to this Technical Day (CNPP, STid, Siemens, Cordia, Desautel, Eaton, Réseau DEF, Chubb, Ubiquiti, Hikvision, Artemis, Andrieu and Honeywell)!