Recital 49

Recital 49

Directive on the security of network and information systems · UE 2022/2555

(49)

Cyber hygiene policies provide the foundations for protecting network and information system infrastructures, hardware, software and online application security, and business or end-user data upon which entities rely. Cyber hygiene policies comprising a common baseline set of practices, including software and hardware updates, password changes, the management of new installs, the limitation of administrator-level access accounts, and the backing-up of data, enable a proactive framework of preparedness and overall safety and security in the event of incidents or cyber threats. ENISA should monitor and analyse Member States’ cyber hygiene policies.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority to supervise cyber hygiene of essential and important operators designated under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). ILR explicitly relies on ENISA guides and ANSSI frameworks to assess the baseline during inspections, and can impose administrative fines up to 10 million euros or 2% of worldwide turnover for essential entities.

Luxgap practice: we calibrate the Hygiene Sentinel baseline on the ENISA cyber hygiene framework and cross-check it with ILR documented expectations for Luxembourg regulated sectors (energy, health, finance, digital infrastructure).