Recital 37
Directive on the security of network and information systems · UE 2022/2555
| (37) | The growing interdependencies are the result of an increasingly cross-border and interdependent network of service provision using key infrastructures across the Union in sectors such as energy, transport, digital infrastructure, drinking water and waste water, health, certain aspects of public administration, as well as space in so far as the provision of certain services depending on ground-based infrastructures that are owned, managed and operated either by Member States or by private parties is concerned, therefore not covering infrastructures owned, managed or operated by or on behalf of the Union as part of its space programme. Those interdependencies mean that any disruption, even one initially confined to one entity or one sector, can have cascading effects more broadly, potentially resulting in far-reaching and long-lasting negative impacts in the delivery of services across the internal market. The intensified cyberattacks during the COVID-19 pandemic have shown the vulnerability of increasingly interdependent societies in the face of low-probability risks. |
In Luxembourg, the ILR is the competent authority to receive NIS 2 incident notifications and conduct inspections on interdependencies. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes NIS 2 and empowers the ILR to designate essential and important operators and to require the mapping of cross-border dependencies, particularly sensitive for the Luxembourg market given the concentration of datacenters (LuxConnect, eBRC) hosting essential services for the entire EU.
Luxgap practice: for Luxembourg entities, we integrate by default into the Cascade Risk Mapper the local datacenter operators (LuxConnect, eBRC, POST Telecom) and cross-border interconnections (BE, DE, FR) to produce a map immediately enforceable before the ILR.