Recital 120

Recital 120

Directive on the security of network and information systems · UE 2022/2555

(120)

Entities should be encouraged and assisted by Member States to collectively leverage their individual knowledge and practical experience at strategic, tactical and operational levels with a view to enhancing their capabilities to adequately prevent, detect, respond to or recover from incidents or to mitigate their impact. It is thus necessary to enable the emergence at Union level of voluntary cybersecurity information-sharing arrangements. To that end, Member States should actively assist and encourage entities, such as those providing cybersecurity services and research, as well as relevant entities not falling within the scope of this Directive, to participate in such cybersecurity information-sharing arrangements. Those arrangements should be established in accordance with the Union competition rules and Union data protection law.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, CIRCL (Computer Incident Response Center Luxembourg), operated by SECURITYMADEIN.LU, is the national anchor point for cyber information sharing and hosts the reference MISP instance used at European level. The ILR explicitly encourages essential and important entities designated under the law of 28 July 2023 on cybersecurity to join CIRCL MISP and contribute actively, in addition to incident notification obligations to the ILR.

Luxgap practice: we set up the technical connection to CIRCL MISP, register your organisation with SECURITYMADEIN.LU and calibrate TLP rules so your contributions are accepted seamlessly by the Luxembourg community.