The classic trap
Recital 104 targets telecom operators and ISPs (Proximus, POST, Orange, Tango, Eltrona and their B2B equivalents). The ILR sanctions two recurring failures: the absence of security by design on CPE equipment (routers, boxes, ONT) shipped to subscribers with default passwords or outdated firmware, and the lack of proactive subscriber information during massive phishing campaigns or active exploitation of critical vulnerabilities (such as home router compromises). The 'we didn't want to alarm customers' defense is no longer acceptable under NIS 2.
What this recital adds to Articles 21 and 23
Recital 104 clarifies three operational obligations for electronic communications providers:
- Security by design: distributed CPEs must be securely configured on delivery (no default admin password, WPA2/WPA3 mandatory, WAN-side management ports closed, signed firmware).
- Security by default: the most protective options are enabled without subscriber action (optional filtered DNS offered, IoT segmentation, automatic firmware updates).
- Proactive information: alert subscribers to significant cyber threats affecting them (smishing campaigns abusing the operator's name, router model compromises, credential leaks) and recommend concrete measures (end-to-end encryption, password managers, MFA on the customer portal).
The de facto standard is defined by ENISA (Guideline on Security Measures under the EECC) and BEREC. The ILR explicitly relies on these references during inspections.
How Luxgap automates this risk
Our Luxgap Subscriber Threat Broadcaster turns the subscriber information obligation into an automated, measurable channel enforceable before the ILR. The tool correlates in real time CERT.LU, ENISA, CISA KEV, HaveIBeenPwned feeds and your SOC logs (Sentinel, Wazuh, Splunk) to detect threats specifically affecting your subscriber base and CPE fleet, then triggers targeted communication without requiring the CISO to draft an email for every incident.
- Automatically detects critical CVEs affecting router/ONT models present in your fleet, by cross-referencing CPE inventory with CERT.LU and NVD bulletins.
- Identifies exposed subscribers (by segment, model, firmware version) and generates the targeted distribution list, with no unnecessary broadcast to the rest of the fleet.
- Automatically drafts the multilingual alert message (FR/EN/DE/LU) with concrete recommended measures, validated by an LLM agent specialized in ENISA compliance.
- Publishes the alert across multichannel paths (SMS, customer portal, mobile app, postal mail for vulnerable subscribers) and traces every delivery with acknowledgment.
- Continuously scans security by default compliance on provisioned CPEs (residual default passwords, outdated firmware, open management ports) via SNMP/TR-069 probes.
- Produces a quarterly timestamped, cryptographically sealed report, enforceable before the ILR, demonstrating execution of the information and security by design obligations.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalized quote and our teams will prepare a demonstration on your real CPE fleet, with a free white audit within 48h to measure your exposure before any commitment.