Recital 54

Recital 54

Directive on the security of network and information systems · UE 2022/2555

(54)

In recent years, the Union has faced an exponential increase in ransomware attacks, in which malware encrypts data and systems and demands a ransom payment for release. The increasing frequency and severity of ransomware attacks can be driven by several factors, such as different attack patterns, criminal business models around ‘ransomware as a service’ and cryptocurrencies, ransom demands, and the rise of supply chain attacks. Member States should develop a policy addressing the rise of ransomware attacks as part of their national cybersecurity strategy.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative à la cybersécurité, modifiée par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended on 28 July 2025) designates ILR as the incident notification authority and entrusts HCPN (High Commission for National Protection) with steering the national cybersecurity strategy, which has explicitly included an anti-ransomware component since 2021. Essential entities must notify a significant ransomware incident to ILR within 24h (early warning) then 72h (full notification), via the MISP-Lux platform operated by CIRCL.

Luxgap practice: we preconfigure the MISP-Lux connectors and the ILR notification channel inside the Ransomware Readiness Engine, so that the 24h/72h declaration is dispatched automatically with IoCs already formatted to the CIRCL standard the moment encryption is detected.