Recital 3
Directive on the security of network and information systems · UE 2022/2555
| (3) | Network and information systems have developed into a central feature of everyday life with the speedy digital transformation and interconnectedness of society, including in cross-border exchanges. That development has led to an expansion of the cyber threat landscape, bringing about new challenges, which require adapted, coordinated and innovative responses in all Member States. The number, magnitude, sophistication, frequency and impact of incidents are increasing, and present a major threat to the functioning of network and information systems. As a result, incidents can impede the pursuit of economic activities in the internal market, generate financial loss, undermine user confidence and cause major damage to the Union’s economy and society. Cybersecurity preparedness and effectiveness are therefore now more essential than ever to the proper functioning of the internal market. Moreover, cybersecurity is a key enabler for many critical sectors to successfully embrace the digital transformation and to fully grasp the economic, social and sustainable benefits of digitalisation. |
In Luxembourg, the ILR is the competent NIS 2 authority and relies on the national ecosystem (CIRCL.lu, GOVCERT, HCPN) to calibrate its expectations on cyber posture. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes NIS 2 and gives the ILR the power to designate essential and important operators, receive incident notifications, and conduct inspections and sanctions.
Luxgap practice: connecting your threat watch to CIRCL.lu MISP feeds from day one demonstrates alignment with the national ecosystem, a criterion valued during ILR inspections.