Skip to content

Note · 2026

Ce que la construction du Campus Cyber apprend sur la coopération public-privé

[What building the Campus Cyber teaches about public-private cooperation — retrospective note, 2026]

Year
2026
Type
Note
Institution
Written for bonnet.bzh · author: Yann Bonnet
Role
Co-founder

Retrospective note on the design and early years of the Campus Cyber: what the public-private cooperation model allows, and what it does not.

An original note, written for this site. It covers a period I lived through from the inside, first at ANSSI, then as co-founder and deputy chief executive of the Campus Cyber. This is therefore not an independent evaluation, and should be read as such.

What was built

The idea was born in 2019-2020 at ANSSI, with Guillaume Poupard: faced with a growing threat, cyber risk cannot be mastered by state action alone; the ecosystem has to be activated. A pre-figuration mission was entrusted to Michel Van Den Berghe, whom I supported in that capacity as co-founder: designing the governance, drafting the by-laws with the lawyers, seeking public and private funding, winning over the undecided. 29 million euros raised, and everything to build from a blank page. The Campus Cyber was inaugurated in February 2022: 26,000 m² at La Défense, a company jointly owned by public and private actors, with no hierarchical authority over its members.

Three years after opening, the site brought together more than 300 organisations, including 60% of CAC 40 companies. The Studio des Communs (the Campus’s shared-commons studio) gathered around 750 contributors into working groups and produced some thirty shared resources, made freely available to the whole ecosystem, on AI applied to cybersecurity, threat intelligence, post-quantum cryptography and eco-design. Five regional campuses have been officially recognised: Hauts-de-France, Nouvelle-Aquitaine, Normandie, Brittany, Région Sud. A European consortium on AI and cybersecurity was entrusted to the Campus by the Commission and the Île-de-France region, and a talent consortium funded by France 2030 brought together Radio France, the ONISEP, Pix and the CNED.

This is the most counter-intuitive result: in a competitive sector where confidentiality is an asset, rival companies agreed to jointly produce commons they could not appropriate for themselves. In 2017, the commons-based approach passed for ideological; by 2022, it passed for logical. That shift, in five years, is the least visible and the most solid of the gains made.

The founding story, on video

Two interviews from the Portrait Cyber series revisit this story, from the perspective of two of the people who lived it.

An interview from the Portrait Cyber series, with Yann Bonnet, then deputy chief executive of the Campus Cyber (in French).

Same series, with Guillaume Poupard, director general of ANSSI (the French national cybersecurity agency) at the time, now Chief Trust Officer at Orange (in French).

Three design choices

The scheme rested on three explicit choices, which need naming because they are transferable independently of everything else.

The diversity of participants, deliberately including members who are not cybersecurity specialists.

The decoupling of capital contribution from decision-making power: a majority shareholder does not hold a proportional vote. The reasoning was ecological: land is productive when no single species dominates it, and an over-dominant actor marks the onset of the pollution that breaks the fertility chain. This is the condition that made the state’s participation acceptable to the private sector, and the private sector’s acceptable to the state.

And the production of commons, rather than the provision of services: the Campus does not sell; it builds, together with its members, what none of them would have built alone.

The 2025 target: neither met nor missed

The national cybersecurity acceleration strategy, backed by 1 billion euros, 720 million of which was public funding, set two quantified targets for 2025: raising the industry’s employment from 37,000 to 75,000 jobs, and its revenue from 7.3 to 25 billion euros. The Campus Cyber was presented as the spearhead of that strategy.

The outcome depends entirely on which scope is used, which is in itself the most interesting result. Within the strict cybersecurity scope, the direction générale des entreprises (the directorate general for enterprises) measured a 50,000-job, 10.45-billion-euro industry in 2023: the trajectory would not have reached the target. Within the broader scope of digital trust, the observatory of the Alliance pour la confiance numérique (the digital trust industry alliance) measured 107,000 jobs and 21.3 billion euros in revenue in 2024: the target is exceeded.

Two ways of counting, two opposite conclusions, no dishonesty required. When a public policy sets quantified targets without first settling what it is actually counting, it deprives itself of the one instrument that would make its evaluation binding. I do not exempt myself from this criticism: I used these figures in public interviews without questioning how they were constructed.

What the model makes possible

Three things, which I believe are solid.

It produces commons that no single actor would have produced alone, because the cost is shared and the benefit cannot be appropriated. This is the most literal application of externality theory, and it works.

It builds mutual familiarity. Public researchers, chief security officers of large companies, startup founders and civil servants who used to have no idea of each other’s existence now work together and understand each other better. This asset is invisible in any indicator, and it is probably the most durable one.

It gives the field an address. Some fifty foreign delegations a year, a campus copied in Lithuania, interest from Germany and the Netherlands: an identifiable physical place has a diplomatic effectiveness that no equivalent administrative arrangement has.

What the model does not make possible

The cost of cooperation. Bringing competitors together makes it possible to build commons, but that synergy comes at a price. It requires considerable energy spent maintaining consensus, complex trade-offs that are often dodged, and a regular scaling-back of ambition to secure unanimity.

The fragility of the business model. An excessive dependence on real-estate revenue, to the detriment of other sources of value.

What is transferable

Lithuania has opened its campus, Germany and the Netherlands are showing interest. What remains is to distinguish what belongs to a reproducible scheme from what depended on a specifically French set of circumstances: an explicit presidential push, an entrepreneur who carried both the private sector’s trust and the state’s, a moment when the wave of ransomware attacks against hospitals had made the subject politically legible, and a national agency respected enough to become a shareholder without being suspected of wanting to control everything.

A few souvenir photos to revisit the key milestones of the Campus Cyber's creation

  • Aerial view of a construction site at La Défense, with two large yellow cranes and office towers in the background.

    January 2019

    Things were already moving on the ground… with no idea that, a few months later, hundreds of cyber-defenders would gather in Puteaux.

  • Prime Minister's press release dated 23 July 2019, announcing the pre-figuration mission for a cybersecurity campus entrusted to Michel Van Den Berghe.

    July 2019

    The pre-figuration mission entrusted by the Prime Minister gets under way. A cheerful team sets out to lay the groundwork for the future Campus Cyber.

  • Four photos of a co-design workshop at the Liberté Living-Lab: an audience seated for a talk, a screen reading “Matinée spéciale Cyber Campus”, small working-group tables, and a poster outlining four thematic workshops.

    November 2019

    Co-design workshops at the Liberté Living-Lab: rich exchanges, collective energy, and the first concrete directions for shaping the future Campus Cyber.

  • Cover of the report “Campus Cyber: fédérer et faire rayonner l'écosystème de la cybersécurité”, by Michel Van Den Berghe, shown on a screen.

    January 2020

    Fine-tuning the report “Campus Cyber: uniting and showcasing the cybersecurity ecosystem”.

  • Four photos of the Campus Cyber construction site in autumn 2020: the façade under construction, a hard-hatted and masked group tour, a team in high-visibility vests, and interior fit-out work under way.

    Autumn 2020

    Time to pick up the pace to stay on schedule…

  • Two photos of the first founding members meeting: a group portrait in a lounge area, and a meeting around a large conference table.

    December 2020

    The first “founding” members come together.

  • Two images from an online Campus Cyber event: a broadcast set with panellists seated in a circle, and a LinkedIn post by Guillaume Poupard announcing the session.

    March 2021

    The goal: win over the last sceptics. More than 1,000 people are watching live.

  • A masked crowd looking through glass at the architectural model of the future Campus Cyber, at the International Cybersecurity Forum.

    FIC 2021

    The Campus Cyber model draws crowds of the curious…

  • Four photos from inauguration day: the Campus Cyber logo projected before an audience, the building's model surrounded by visitors, a view from an office over the construction site, and a packed hall with a giant screen.

    15 February 2022

    The inauguration!

  • A team of around ten people jumping in the air, arms raised, in front of the Campus Cyber building at La Défense.

    The Campus Cyber launch team.

1 / 10