← All articles

consultant

Authentication logs: key evidence (French Conseil d’État, 26/06/2023) and NIS 2

The Conseil d’État validated purpose‑bound access to authentication logs. To meet NIS 2 (24h) and CSSF expectations, a Logging + SIEM + Forensics setup is now essential.

Summary. The French Conseil d’État (26/06/2023) confirms purpose‑bound access to authentication logs to secure public services. In practice, complete logs are essential to detect and investigate, meet NIS 2 timelines (24/72h), and satisfy CSSF expectations.

Key facts

On 26 June 2023, the Conseil d’État (France) held that authorised staff may lawfully access logging data tied to the use of an electronic identification means, provided such access is purpose‑bound, proportionate, and controlled. Ruling No. 465329 states that this access for authentication security and investigation respects fairness and purpose limitation (GDPR Art. 5(1)). Source: Conseil d’État, decision No. 465329 of 26/06/2023.

Operational reality matches this signal: incident detection and investigation rely on complete, exploitable logs. Recent example: on 24 July 2026, OnTrac disclosed a breach after a network compromise; the probe relied on access/file activity analysis between 20–22 March. Source: BleepingComputer — OnTrac, 24/07/2026.

Applicable legal framework

Executive takeaway (2026): fast alerting (NIS 2) and evidence of proportionality/effectiveness (CSSF, GDPR) require exploitable, tamper‑evident, and governed logs.

The technical solution to deploy

Goal: implement a robust “Logging + SIEM + Forensics” chain covering authentication, access, endpoints, network, and cloud. This can be in‑house or via a managed SOC focused on incident detection.

Collection and normalisation

  • Aggregate: authentication (IdP/SSO, VPN, PAM), application access, EDR/XDR, firewall/WAF, cloud (CloudTrail, Azure AD Sign‑in, Audit Logs), and critical SaaS logs.
  • Normalise (ECS/CEF/LEEF), time‑stamp (NTP), enrich (geolocation, identity, asset criticality).

Detection and correlation

  • Correlated rules: repeated failures + success from unusual ASN; abnormal token exchange; privilege escalation; volumetric extraction; suspicious OAuth app creation; CERT/ISAC IoCs.
  • UEBA for anomalous sessions and behaviours.

Evidence and integrity

  • Immutable/locked storage (WORM/S3 Object Lock), role separation, time‑chained custody.
  • Risk/criticality‑based retention (6–24 months for security; longer if prudential), documented legal basis.

Investigation and reporting

  • Investigation playbooks: timeline, impacted accounts/systems, affected data, entry point, IoCs; ready for ILR 24h alert, 72h notification, 30‑day report.
  • Signed/time‑stamped exports, hashing, evidence vault.

Frameworks

  • ISO/IEC 27001:2022 Annex A — A.5.10, A.8.16, A.8.15, A.8.23.
  • NIST CSF 2.0: DETECT (DE.AE‑03, DE.CM‑07), RESPOND (RS.AN‑01).
  • CIS Controls v8: 8, 6, 17.

How Luxgap delivers

  • 24/7 managed SOC: fast onboarding of IdP/SSO, EDR/XDR, cloud and critical SaaS logs; NIS 2‑aligned correlation; “notification‑ready” boards with 24/72h countdowns and SERIMA‑ready exports. See our managed SOC and detection service.
  • ISO 27001 governance: legal bases (GDPR), risk‑based retention, access procedures aligned with the CE’s purpose and proportionality principles.
  • Externalised DPO and CISO: bridge “tech ↔ compliance” (DPIA, records, log access clauses, integrity proofs) and notification drills. Need an externalised CISO for cyber leadership?

Starting point: a 10‑day “Log Readiness Assessment” to map sources, close coverage gaps, set retention, and activate NIS 2 alert boards — then industrialise in your SIEM (or a Luxgap‑operated SIEM).

Real‑world case in Luxembourg/EU

An investment firm subject to NIS 2 and CSSF centralised its SSO/VPN authentication, application access, and EDR logs in an operated SIEM within 6 weeks. Results:

  • Malicious OAuth token detected in 12 minutes; two exposed accounts contained; evidence of no exfiltration via access logs.
  • ILR alert within 6 hours with timeline and IoCs; no additional report requested.
  • CSSF audit: retention policies improved and WORM integrity proofs accepted.

First concrete steps

  1. Map critical sources: IdP/SSO, EDR/XDR, VPN, cloud (Audit/Sign‑in), firewalls, core business apps. Verify time, format, retention, integrity.
  2. Define 3 minimal use cases: a) SSO account takeover, b) abnormal privilege escalation, c) out‑of‑hours volumetric extraction.
  3. Secure evidence: immutable storage (WORM) for critical logs, role separation, documented GDPR legal basis and retention periods.
  4. Prepare NIS 2 alerting: 24h/72h/30‑day templates, named roles, NTP reference clock, “NIS 2 timer” dashboard.
  5. Test: half‑day “compromised SSO account” drill with exports, hashing, and ILR‑ready dossier.

Official sources

  • Conseil d’État (France), decision No. 465329 of 26/06/2023 — purpose‑bound access to authentication logging data: link.
  • ILR — NIS 2 Luxembourg (Law of 5 May 2026) and press briefing: link ; link.
  • CSSF — ICT & cyber risk (DORA and non‑DORA) and Circular 20/750: link ; link ; link.
  • Cyber news — role of logs in investigations: BleepingComputer, OnTrac (24/07/2026).

In short: case law validates purpose‑bound access to authentication logs; NIS 2 and CSSF require rapid detection and evidence. A governed Logging + SIEM + Forensics capability can be implemented in weeks, not years. Need support? Contact Luxgap.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →