Recital 50

Recital 50

Directive on the security of network and information systems · UE 2022/2555

(50)

Cybersecurity awareness and cyber hygiene are essential to enhance the level of cybersecurity within the Union, in particular in light of the growing number of connected devices that are increasingly used in cyberattacks. Efforts should be made to enhance the overall awareness of risks related to such devices, while assessments at Union level could help ensure a common understanding of such risks within the internal market.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite

In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to oversee cyber hygiene and awareness measures of essential and important entities. The ILR explicitly relies on ENISA guides and may require demonstration of a differentiated awareness policy during inspections, with fines reaching 10 million EUR or 2% of global turnover for essential entities.

Luxgap practice: prepare a cyber hygiene evidence pack including the IoT inventory, completion rates of awareness journeys per population and traces of simulated phishing campaigns, ready to be handed to the ILR within 72 hours of a formal request.