The classic trap
Essential and important entities believe they master their cloud perimeter because they have mapped AWS, Azure or GCP. But edge computing shifts processing to micro points of presence (5G POPs, industrial IoT gateways, regional CDNs, Cloudflare Workers nodes, Akamai EdgeWorkers) that escape classic audit scope. During a NIS 2 inspection, the ILR demands a complete map of the processing chain, including these peripheral nodes. A hospital processing medical sensor data on a local 5G gateway, a factory driving its PLCs through an OVHcloud edge node, a bank serving clients via Cloudflare Workers: all these flows must be documented, secured and notified in case of incident, just like central servers.
Edge computing blind spots that the ILR controls
- Peripheral compute nodes hosted at third-party providers not listed in the subcontractor register (Cloudflare, Fastly, Akamai, StackPath).
- Industrial IoT gateways running business code without formalized patch management.
- Data processed locally on private 5G terminals without documented at-rest encryption.
- Logs scattered across dozens of POPs with no central SIEM aggregation, preventing incident detection within 24h.
- Cascaded subcontractors: your CDN subcontracts to a regional operator who subcontracts to a local datacenter, blurring the NIS 2 article 21 responsibility chain.
How Luxgap automates this risk
Our Luxgap Edge Topology Mapper makes the invisible visible: it rebuilds in real time the complete topology of your distributed processing, from the central datacenter down to the last edge node, and turns this map into evidence opposable to the ILR. The tool continuously queries your cloud APIs (AWS Wavelength, Azure Edge Zones, GCP Distributed Cloud, Cloudflare Workers, Fastly Compute@Edge, OVHcloud Edge), your MDM consoles (Intune, Jamf) and your SD-WAN controllers to reveal every active processing point, without asking the CISO to fill in a form.
- Automatically detects every new edge node activated in your environment via the APIs of major hyperscalers and CDNs, within 5 minutes of provisioning.
- Classifies each node according to its NIS 2 criticality level (sensitive data processed, business dependency, network exposure) and computes a risk score per node.
- Continuously verifies the presence of at-rest encryption, up-to-date OS patches and logs centralized to your SIEM (Sentinel, Splunk, Wazuh).
- Instantly alerts via Teams or email when an edge node falls out of compliance (missing patch, expired certificate, log silent for more than 24h).
- Generates an exportable distributed architecture diagram, updated daily, opposable during an ILR audit to demonstrate mastery of the processing chain.
- Produces a pre-filled edge subcontractor register, with explicit cascade subcontracting depth, compliant with NIS 2 article 21(2)(d) requirements.
Available as a complement to a Luxgap CISO mandate or as a standalone SaaS module depending on your perimeter. Request a demonstration and our teams run a free 48h scan of your real edge topology to materialize your exposure before any engagement.