Ransomware and cyberattacks: protecting learner data and your Qualiopi audit evidence
A Qualiopi evidence folder fully encrypted by ransomware the day before an audit, learners’ attendance sheets and contact details exfiltrated onto the dark web, a management platform unreachable for several days: these scenarios are no longer reserved for large companies. A training organisation, even a modest one, depends entirely on digital tools — LMS platform, management software, email, shared storage — to produce and keep the evidence expected by the Référentiel National Qualité and to handle its learners’ data. Here’s how to limit the risk and react correctly if the incident happens.
Why training organisations are an exposed target
Contrary to a common assumption, ransomware attacks rarely target a specific victim. A landmark empirical study by Connolly, Wall, Lang and Oddson, published in the Journal of Cybersecurity (2020) and based on 55 real cases in UK and North American organisations, found that an organisation’s size has no significant effect on the severity of an attack — what determines the extent of the damage is the organisation’s security posture (backups, updates, staff awareness) and whether the attack was targeted or opportunistic. In other words, a small training organisation with no backup policy is statistically as exposed as a larger company, and can suffer consequences just as severe relative to its size.
Several features of training activity heighten this exposure:
- Dependence on multiple digital tools: management software, LMS platform, email, spreadsheets tracking indicators — every tool is a potential entry point.
- The sensitivity of the data processed: identity, contact details, sometimes health data shared with the disability accessibility contact, assessment results — all high-value information for attackers who resell it or threaten to publish it.
- The centralisation of the evidence folder: in many organisations, the supporting documents for the 32 indicators (agreements, attendance sheets, trainer CVs, satisfaction surveys) sit in a single digital space, with no physical copy or offsite backup.
What a cyberattack actually puts at stake
Three categories of consequences pile up after a successful ransomware attack:
- Data availability: encrypted files, an unreachable management platform, a temporary inability to invoice, to summon learners, or to issue a certificate.
- Confidentiality: many recent attacks combine encryption with exfiltration — data is copied before being locked, with a threat of publication if the ransom isn’t paid (double extortion).
- The integrity of the audit file: if the evidence for Indicator 17 (human and technical resources) or other criteria of the framework disappears with no backup, the organisation ends up unable to present it to the auditor — a situation that reflects a lack of organisational foresight more than technical fatality.
The legal framework: what GDPR requires after an incident
As soon as personal data belonging to learners or staff is involved, a ransomware attack constitutes a data breach under GDPR, because it simultaneously harms availability (encryption) and, often, confidentiality (exfiltration). As detailed in our article on the GDPR obligations of a training organisation, this triggers:
- notifying the CNIL within 72 hours whenever the breach is likely to create a risk for the individuals concerned (GDPR Article 33);
- individually informing affected learners if the risk to their rights and freedoms is high;
- documenting the incident internally, even when notifying the CNIL ultimately isn’t required.
On top of these obligations, it’s strongly advisable — though not legally required — to report the incident on the public cybermalveillance.gouv.fr platform and to file a police report, which feeds national threat statistics and helps connect the organisation with qualified remediation providers.
Preparing before the incident: prevention reflexes
The best protection remains preventive. A handful of measures, proportionate to the size of a training organisation, sharply reduce the likelihood and severity of an attack:
| Measure | Why it matters |
|---|---|
| Regular, disconnected backups (the “3-2-1” rule: three copies, two different media, one offline or offsite) | Ransomware also encrypts backups that stay permanently reachable over the network; a disconnected copy remains intact |
| Systematic updates of software and operating systems | Most attacks exploit vulnerabilities for which a patch already exists |
| Strong authentication (robust passwords, two-factor authentication) on email and sensitive tools | Phishing remains the most frequent entry point |
| Awareness training for trainers and administrative staff on fraudulent emails | The human factor remains decisive in the success of an attack, whatever the sophistication of the technical tools |
| Access segregation (each contributor only accesses the data needed for their role) | Limits the spread of an attack if one account is compromised |
This staff awareness effort fits naturally into the skills development expected under Indicator 22 of the Référentiel National Qualité: a cybersecurity awareness point can appear in your staff development plan, alongside pedagogy or subject-matter regulation.
What to do during an ongoing attack
If ransomware strikes despite these precautions, the order of priorities is as follows:
- Isolate the affected machine or network — unplug the network cable or turn off Wi-Fi to stop the spread, without shutting the machine down if possible (some evidence useful to the investigation is lost on power-off).
- Never pay the ransom. There is no guarantee of data recovery, the payment funds criminal networks, and organisations known to have paid are statistically retargeted.
- Call in a qualified remediation provider, potentially found via cybermalveillance.gouv.fr, to assess the extent of the compromise before reconnecting anything.
- Assess whether personal data is involved and, if so, trigger the 72-hour CNIL notification window.
- File a police report with a unit specialising in cybercrime — a report is also required for any claim with an insurer.
- Restore from disconnected backups, once the network has been confirmed clean, rather than reconnecting compromised systems directly.
Rebuilding the Qualiopi evidence folder after an incident
Once the technical emergency has passed, the certification-specific challenge remains: reconstructing lost supporting documents. The practical avenues are the same as for any document loss covered in our article on document retention periods: copies held by funders (OPCOs, the Caisse des Dépôts for EDOF), digital duplicates emailed to learners or trainers, paper archives if any still exist, and periodic exports from your management software to an external location.
As unpleasant as this incident is, it can also become evidence of a continuous improvement approach under Indicator 32 of the Référentiel National Qualité: documenting the event, the corrective actions taken (a new backup policy, staff training) and the follow-up over time turns a one-off weakness into tangible proof of quality management — provided you don’t wait for the audit to address it. Add this point to your regulatory monitoring log alongside regulatory changes.
Take action
Cybersecurity isn’t a topic reserved for large organisations: a simple backup plan and clear incident reporting cover most of the risk for a training organisation. The Complete Kit Certif provides procedure templates and the evidence table for the 32 indicators to structure your documentation starting today; the ebook Create your training organisation in 30 days sets the right administrative reflexes from day one; and the complete pack combines both to secure your compliance and your business continuity at the same time.
Frequently asked questions
+Should you pay the ransom after a ransomware attack?
No. France's national cybersecurity awareness platform, cybermalveillance.gouv.fr, and the national cybersecurity agency ANSSI consistently advise against paying. Nothing guarantees you'll recover your data or the decryption key, the payment funds criminal groups, and organisations known to have paid are statistically more likely to be targeted again.
+Does a cyberattack need to be reported beyond the CNIL notification?
Yes. Beyond notifying the CNIL (France's data protection authority) within 72 hours if personal data is involved, it is recommended to file a police report with a unit specialising in cybercrime and to report the incident on the cybermalveillance.gouv.fr platform, which directs victims to vetted remediation providers.
+Is a small training organisation, sole trader or otherwise, really a target?
Yes. Ransomware attacks are overwhelmingly opportunistic: they don't target a specific organisation but exploit automatically detected weaknesses (a weak password, an unpatched piece of software), regardless of the organisation's size. The sensitivity of the data a training provider processes makes it an attractive target regardless of its revenue.
+Can a cyberattack cause a Qualiopi audit to fail?
Indirectly, yes, if it destroyed the expected evidence with no backup in place. The auditor doesn't sanction the incident itself, but the absence of reconstructed documentary evidence can generate a non-conformity on the affected indicators, for lack of presentable proof on the day of the audit.