Recital 55

Recital 55

Directive on the security of network and information systems · UE 2022/2555

(55)

Public-private partnerships (PPPs) in the field of cybersecurity can provide an appropriate framework for knowledge exchange, the sharing of best practices and the establishment of a common level of understanding among stakeholders. Member States should promote policies underpinning the establishment of cybersecurity-specific PPPs. Those policies should clarify, inter alia, the scope and stakeholders involved, the governance model, the available funding options and the interaction among participating stakeholders with regard to PPPs. PPPs can leverage the expertise of private-sector entities to assist the competent authorities in developing state-of-the-art services and processes including information exchange, early warnings, cyber threat and incident exercises, crisis management and resilience planning.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite

In Luxembourg, the reference cybersecurity PPP is CIRCL (Computer Incident Response Center Luxembourg), operated by securitymadein.lu, which maintains the national MISP instance. The law of 28 July 2023 on cybersecurity implicitly recognizes information sharing through CIRCL and GOVCERT.LU as part of the due diligence expected by ILR under the transposed Article 21.

Luxgap practice: we systematically connect our clients' SIEM to CIRCL MISP and GOVCERT.LU within the first month of the CISO mandate, and we document exchanges in a register opposable during an ILR audit.