FIELD NOTES / 04 THE INTERVIEW
Bénédicte Steinhard:
Protecting
the whole chain.
From protecting buildings to protecting information systems. A conversation about cybersecurity, GDPR, the realities of healthcare and digital sovereignty that reaches the last mile.

FIVE QUESTIONS / ONE CONNECTED VIEW
With more than 15 years in electronic security, Bénédicte Steinhard now supports small and medium-sized businesses and healthcare professionals, particularly pharmacies, with cybersecurity, GDPR and digital governance.
Originally in French. Translated into English. GDPR: General Data Protection Regulation. GRC: governance, risk and compliance.
QUESTION 01 / SYSWARDEN
Tell us about yourself.
Bénédicte Steinhard
I'm Bénédicte Steinhard. My background is very much in security. I have more than 15 years of experience in electronic security: video surveillance, alarms, access control, protecting sites and securing buildings. I've worked in very different settings, including industry, local authorities, town halls, healthcare and pharmacies.
And, contrary to what people might think, we were already talking a great deal about networks and cybersecurity in electronic security. Cameras are connected. Alarm systems communicate over networks. Access control is managed remotely. There are servers, IP addresses, remote connections, passwords, user permissions and service providers logging in.
So the boundary between physical security and cybersecurity was already very thin. For me, moving into cyber is certainly not a complete change of direction. It's a natural continuation of my work.
For years, my job was already about protection. Protecting a site. Protecting access. Understanding who can enter, where and when. Identifying vulnerabilities. Putting the right protection in the right place. Today, I do exactly the same thing in the digital world.
Before, I would ask: who can enter the building? Today, I ask: who can enter the information system? Before, I checked who had a badge. Today, I check who has administrator privileges. Before, I secured a door, a warehouse or a pharmacy. Today, I also secure data, remote access, service providers and digital practices.
That gives me a fairly broad view of security, because the physical and digital worlds are now completely intertwined. A poorly secured camera is a physical device that becomes a cyber risk. Connected access control is physical security that depends on a network. A service provider working remotely raises technical, organisational and governance questions at the same time.
So when I became more deeply involved in cybersecurity and GDPR, it felt entirely natural. I haven't changed professions. I've simply expanded what I protect.
Today, I mainly support SMEs and healthcare professionals, particularly pharmacies, with cybersecurity, GDPR and digital governance. And a pharmacy brings all of this together: the building, access points, cameras, the safe and the dispensing robot.
But also the business software, patient data, employees, suppliers, accounting, remote maintenance, backups, email and now artificial intelligence. That whole picture is exactly what interests me. Not just the front door. Not just the server. The whole chain.
QUESTION 02 / SYSWARDEN
Cybersecurity, GDPR and GRC: three pillars for a company's legal, operational and organisational compliance. What do your working days look like?
Bénédicte Steinhard
My days are never quite the same, but there's always a common thread: understanding what's really happening inside the business. I might arrive at a client with a GDPR issue and leave with a significant cybersecurity issue. Or the other way around.
I might start with a pharmacy that tells me, 'Our IT is taken care of.' Naturally, I dig deeper. I look at who has access, who can connect remotely, where the backups are, whether multi-factor authentication is enabled, which providers handle the data and who administers what. Often, that's where the real questions begin.
Because there can be a world of difference between what we think is secure and what actually is. What I enjoy is making that connection between the technical, legal and organisational sides.
For me, GDPR is more than filling in a record of processing activities. Cybersecurity is more than installing antivirus software or a firewall. And GRC is more than writing impressive procedures. Everything has to work together.
If we write that access is limited to three people, I want to know whether, technically, only those three people really have access. If we say we have backups, I want to know whether anyone has ever tested them. If we have a critical service provider, I want to know what happens if it goes down tomorrow morning.
That's what my days look like. I ask a lot of questions. Sometimes very simple ones. But it's often the simplest questions that reveal the most. Who has the passwords? Who can revoke access? Who calls whom in an incident? Who decides? Who notifies people?
Above all, I enjoy making these subjects understandable. I don't want a business owner to feel that they need to be an engineer or a lawyer to understand what's happening in their own organisation. I want them to know where their risks are, what they have under control, what they don't yet control and what we need to fix first.
I also spend a significant part of my day keeping up with developments. I follow new vulnerabilities, attacks, regulatory changes, AI and decisions by CNIL, the French data protection authority. But I always come back to the same question: does this change anything in practical terms for my clients?
If the answer is yes, I translate it. I turn a vulnerability, an obligation or a rule into something simple and actionable. That's really my job today: bridging cybersecurity, GDPR, governance and the everyday reality of a business.
“I haven't changed professions. I've simply expanded what I protect.”
QUESTION 03 / SYSWARDEN
France has been hit hard by data leaks for more than four months. If you were appointed Minister for Digital Affairs, what would your first actions be?
Bénédicte Steinhard
First, I'd start with something very simple: education. And not just for IT professionals. We should teach the fundamentals of digital hygiene from school onwards. You don't use the same password everywhere. You don't click on just any link. You don't share your access codes. You understand what phishing is. You learn to protect your data.
For me, that should become as natural as learning to cross the road at a pedestrian crossing. And we should keep developing that digital culture in businesses, public administrations, local authorities and healthcare. Even today, a huge number of incidents begin with something very basic.
My second decision would be very clear: I'd create a proper Ministry of IT and Cybersecurity. Digital matters shouldn't be scattered across ten different administrations. We need an identifiable ministry with clear responsibility, a clear strategy and resources.
IT and cybersecurity are everywhere today: in hospitals, pharmacies, town halls, schools, public finance, businesses and critical infrastructure. So I believe we need a proper digital chain of command.
At state level, I'd appoint a government CIO. Someone with an overall view of the state's information systems, able to roll out a common policy across all ministries. If every ministry moves forward on its own, with its own tools, providers, rules, security standards and habits, we're creating complexity ourselves.
I want a CIO who can say: here are our minimum standards; here is how we manage access; here is where MFA is mandatory; here is how we manage providers; here is how we back up; and here is how we respond to an incident. Then we roll that out across ministries, local authorities, healthcare, education and public bodies. We need a backbone.
The third priority would be proper resources to support businesses. We can't tell a small company, 'You need to be more cyber-resilient,' and then leave it alone with a fifty-page list of recommendations.
I want practical support: to implement MFA, buy security keys, secure backups, carry out audits, train employees and secure administrator access. An SME doesn't necessarily have a CISO, a CIO, a security operations centre and a cybersecurity team. Yet it still needs to protect itself.
Finally, underpinning all of this, I want to build genuinely sovereign digital governance. That means more than saying the data is hosted in France. I want to know: who owns the infrastructure? Who owns the data? Who holds the keys? Who administers the systems? Who can access them? Which providers do we depend on? And could we keep operating if one of them went down tomorrow?
So my first decisions would be: teach these skills from school onwards; create a proper Ministry of IT and Cybersecurity; appoint a government CIO with real authority across ministries; and give businesses the means to secure their foundations in practice. Behind all of that is the need to regain control of our digital governance.
Before we start talking about the next technological revolution, I'd like us to be solid on the basics.
QUESTION 04 / SYSWARDEN
Digital sovereignty: a misuse of terms or marketing bullshit?
Bénédicte Steinhard
Honestly, there's still a lot of bullshit around digital sovereignty today. We talk about sovereign cloud, sovereign data and sovereign infrastructure, but sometimes we completely forget the people on the ground.
I work a lot in healthcare, and people in healthcare are overwhelmed. A pharmacist, a doctor or the owner of a small business doesn't spend their day wondering whether their firewall is properly configured, whether MFA is enabled everywhere or whether their hosting provider depends on American technology. That's not their job.
When you talk to them about firewalls, network segmentation, VPNs, MFA and cloud sovereignty, at some point they switch off. Not because they don't care, but because they have other things to manage: patients, employees, suppliers, shortages, obligations, revenue and the urgent demands of everyday work.
If we keep speaking to them only in technical language, they end up thinking, 'Well, never mind. My IT person must be handling it.' And that's precisely where we lose them.
Digital sovereignty is about more than building French infrastructure. It also means being able to bring security all the way to the people on the ground. Making it understandable, accessible, affordable and, above all, something they can put into practice.
If sovereignty remains a conversation among experts, ministries and large companies, while an SME or a pharmacy still doesn't know who can access its data or whether MFA is enabled, then we haven't made anything sovereign at all. We've just changed the vocabulary.
The sovereignty that interests me is the kind that reaches the last mile. Where the business owner understands what they need to protect. Where they're given the means to do it. And where they no longer answer, 'I don't know. Speak to my IT person!'
QUESTION 05 / SYSWARDEN
Recommend three books or sources that inform your work and your passion.
Bénédicte Steinhard
The first is La Gangrène – Comment l'argent sale pourrit le monde, by Nathalie Goulet. Cybersecurity doesn't exist in a separate world. Behind attacks, fraud and ransomware, there are also financial flows, criminal organisations and an entire economy. What interests me is understanding what's behind the attack, beyond the technical vulnerability.
Next, I'd name ANSSI and CERT-FR. They're my sources for what's happening on the ground. When a vulnerability is disclosed and a technology is affected, you need to understand quickly who's concerned and what needs to be done. I like that practical approach: what's happening, and what do we fix?
Rémi Simier: I follow his publications to spot vulnerabilities and patches quickly, then cross-check them against official sources.
KEEP THE CONVERSATION GOING