ANSSI's 42 hygiene measures as a diagnostic base
Why ANSSI's cyber hygiene guide is still the best starting point for a small-business security diagnostic, and how to turn it into a costed plan.
Sitting across from the owner of a small business, the worst possible opening is the exhaustive framework. Pull out 93 ISO controls, or the ten obligations of Article 21 of NIS2, at a first meeting and the result is always the same: stunned silence, then postponement.
The guide d'hygiène informatique — the cyber hygiene guide published by ANSSI, France's national cybersecurity agency — solves that problem. Forty-two measures, written in language a non-specialist can follow, covering most of what actually stops a routine attack. Short enough to be read through in a meeting, and serious enough to carry everything you build on top of it.
Why start from ANSSI's 42 hygiene measures rather than another framework?#
Three reasons, in this order: the owner understands it, it is free and it carries weight, and it covers most of the real risk.
The owner understands it. "Keep the components of the information system updated on a regular basis" is something you can discuss with a company owner. "A.8.8 — Management of technical vulnerabilities" is not discussed; it is endured.
Vocabulary counts for more than people think in a governance sale. ANSSI's framework was written to be read by non-specialists, which makes it a conversation aid and not only an audit tool.
It is free, and it carries weight. ANSSI is France's national cybersecurity authority. Leaning on a national agency's publication avoids two traps: the in-house framework, which the client suspects was cut to fit the services you sell; and the paid proprietary framework, which adds a cost before the engagement has even started.
It covers most of the real risk. The most frequent compromises in small businesses do not rely on advanced techniques. They come through a weak or reused password, an unpatched machine, a backup that is missing or never tested, an administrator account used for daily work, a flat network with no segmentation.
The 42 measures address those cases head-on. A client who applies them honestly has removed most of its exposure — before buying a single tool.
What do the 42 measures cover?#
The guide sorts its 42 measures into ten chapters: raise awareness and train (measures 1 to 3), know the information system (4 to 7), authenticate and control access (8 to 13), secure workstations (14 to 18), secure the network (19 to 26), secure administration (27 to 29), manage mobile working (30 to 33), keep the information system up to date (34 and 35), monitor, audit and respond (36 to 40), and going further (41 and 42). In a client report, those ten chapters group neatly into five blocks:
Raise awareness and train. Train the operations team, make users aware, keep outsourcing risks under control. The cheapest chapter, and the one most consistently neglected.
Know the information system. An inventory of equipment, applications, access rights, interconnections. Without that inventory every measure that follows rests on assumptions — and this is very often where the first diagnostic turns up surprises.
Authenticate and control access. Named accounts, password policy, separation of privilege, revoking leavers. The area where the gap between what is said and what is true is widest.
Secure endpoints, the network and mobile working. Hardening, segmentation, filtering, Wi-Fi, encryption of laptops that leave the office, patching and end-of-support.
Secure administration and monitor. Dedicated administration workstations, logging, tested backups, audits, an incident procedure — then, going further, risk analysis and qualified products.
How do you turn a diagnostic into a quote?#
A diagnostic that ends with a score has no commercial value. The score is an observation; what sells is the route out of it.
Measure a gap, not a grade. What helps is not "47 / 100". What helps is: here are the eleven measures not covered, here are the three that expose you most, here is what it costs to deal with them.
Prioritise by exposure, not by ease. The temptation is to start with the quick measures so the score moves. It is comfortable, and it is dishonest. A client whose score climbs fifteen points without a single restore test is no better protected — only better graded.
Prioritise by what actually stops a real attack: tested offline backups, multi-factor authentication on external access, separate administrator accounts, patching.
Put a price on every gap. This is the step that turns a report into an order. Every uncovered measure becomes a line: what has to be done, how long it takes, what it costs, in licences and in professional services.
An owner does not sign off on "improve access management". They sign off on "deploy MFA across the 34 external accounts — 2 days of work, €4 per user per month".
Repeat the diagnostic. An annual diagnostic that shows progress is the best renewal argument a recurring contract has. It makes visible a job that, by its nature, is invisible when it works.
What does this diagnostic become for NIS2, ISO 27001 and cyber insurance?#
Here is the decisive argument for using this framework as the way in: nothing is wasted afterwards.
- Towards NIS2: the 42 measures cover a large share of what Article 21 expects — hygiene, access control, continuity, incident handling. The diagnostic becomes the first building block of the compliance file. See the NIS2 guide for IT service providers.
- Towards ISO 27001: the answers transpose directly onto a good part of Annex A. A client who has been assessed does not answer twice. See the 93 controls of Annex A.
- Towards cyber insurance: insurers ask for precisely these items — MFA, backups, patching, user awareness.
One questionnaire, three outlets. That is what makes the approach pay for a service provider: the effort of collecting the information is amortised across several billable deliverables.
What mistakes make a hygiene diagnostic fail?#
The self-declared questionnaire nobody verifies. "Do you have backups?" — "Yes." That answer is worth nothing without the next question: when was the last restore actually tested? The value of a diagnostic lies in the quality of the follow-up questions.
The 60-page report. Nobody reads it. One page of summary for the owner, the detail in an appendix for the IT team.
No date. Undated evidence is not evidence. It is the first thing an auditor checks, and the first thing missing.
The diagnostic with nothing after it. A diagnostic delivered without a costed action plan and a deadline produces nothing — no security for the client, no revenue for you.
Read next
NIS2 and ReCyF self-assessment: 20 questions
One question per objective of ANSSI's ReCyF, with the evidence that answers it: enough to place a company in an hour, before a real assessment.
ReCyF: the ANSSI cyber framework for MSPs
What ANSSI's ReCyF framework is, how it differs from the French cyber hygiene guide and from ISO 27001, and how an MSP runs an assessment.
ReCyF, NIS2, ISO 27001: the mapping table
ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.