The classic trap
Recital 50 informs Article 21(2)(g) of NIS 2 which mandates cyber hygiene practices and training. In practice, the ILR sanctions essential and important entities that present a purely declarative awareness policy: an annual e-learning, a charter signed at onboarding, but no measurement of actual cyber culture and no consideration of connected devices (industrial IoT, sensors, cameras, badges, printers). The trap: your ISMS policy talks about awareness, but your 2,000 connected devices remain invisible and your executives don't know they are the primary attack vector.
What this recital concretely changes
Recital 50 extends cyber hygiene beyond employees: it targets all connected devices, which includes shadow IoT (smart TVs in meeting rooms, HVAC sensors, industrial robots, connected medical devices). Operationally, this means:
- Continuously mapping connected devices on the network, not just classic workstations.
- Measuring cyber maturity per population (executives, IT, OT, field) rather than a smoothed global score.
- Documenting a differentiated awareness approach with indicators that can be presented to the ILR.
- Aligning with ENISA references (Cybersecurity Skills Framework, cyber hygiene guides) which the ILR uses as inspection grids.
How Luxgap automates this risk
Our Luxgap Cyber Hygiene Radar turns declarative awareness into measurable, defensible cyber culture evidence. The tool plugs a passive sensor into your switches and Wi-Fi access points (Cisco Meraki, Aruba, Fortinet, Ubiquiti) to inventory every connected device in real time, then cross-references this inventory with your Microsoft 365, KnowBe4 or Hoxhunt awareness campaigns to calculate a cyber hygiene score per population and per site.
- Automatically detects every new connected device (IoT, OT, BYOD, shadow IT) through passive fingerprinting and raises a Teams alert if firmware is vulnerable per the ENISA CSIRT feed.
- Classifies each device by business criticality and identifies those falling outside your awareness policy scope.
- Generates differentiated awareness journeys by population (executives, IT, OT, field, contractors) with targeted simulated phishing and real click-rate measurement.
- Computes a cyber maturity index aligned with the ENISA framework, refreshed monthly, with a 24-month evolution curve.
- Produces a time-stamped, cryptographically sealed PDF report, defensible before the ILR during inspection, demonstrating Article 21(2)(g) compliance on both devices and humans.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual network, with a free 48-hour scan to reveal your invisible connected devices before any engagement.