Recital 119

Recital 119

Directive on the security of network and information systems · UE 2022/2555

(119)

With cyber threats becoming more complex and sophisticated, good detection of such threats and their prevention measures depend to a large extent on regular threat and vulnerability intelligence sharing between entities. Information sharing contributes to an increased awareness of cyber threats, which, in turn, enhances entities’ capacity to prevent such threats from materialising into incidents and enables entities to better contain the effects of incidents and recover more efficiently. In the absence of guidance at Union level, various factors seem to have inhibited such intelligence sharing, in particular uncertainty over the compatibility with competition and liability rules.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the national CSIRT designated by the ILR is the entry point for the voluntary information sharing referred to in recital 119 and article 29 NIS 2. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, entrusts the ILR with coordinating sharing arrangements between Luxembourg essential and important operators, in liaison with GOVCERT.LU and CIRCL for the private sector.

Luxgap practice: connect your SIEM to CIRCL's MISP feeds and the ILR CSIRT within the first month of the mandate, and formalise a Luxgap-templated information sharing agreement signed with at least two sector peers before the first ILR inspection.