Recital 105

Recital 105

Directive on the security of network and information systems · UE 2022/2555

(105)

A proactive approach to cyber threats is a vital component of cybersecurity risk management that should enable the competent authorities to effectively prevent cyber threats from materialising into incidents that may cause considerable material or non-material damage. For that purpose, the notification of cyber threats is of key importance. To that end, entities are encouraged to report on a voluntary basis cyber threats.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes the voluntary cyber threat notification mechanism. The ILR and the national CSIRT (GOVCERT.LU for the public sector, CIRCL for the non-governmental private sector) are the contact points for these voluntary reports, which cannot result in any additional obligation or sanction solely because of the notification.

Luxgap practice: submit voluntary notifications through the MISP-LU platform operated by CIRCL, which enables automated and anonymisable IOC sharing with Luxembourg sectoral peers.