Recital 66

Recital 66

Directive on the security of network and information systems · UE 2022/2555

(66)

The Cooperation Group should remain a flexible forum and be able to react to changing and new policy priorities and challenges while taking into account the availability of resources. It could organise regular joint meetings with relevant private stakeholders from across the Union to discuss activities carried out by the Cooperation Group and gather data and input on emerging policy challenges. Additionally, the Cooperation Group should carry out a regular assessment of the state of play of cyber threats or incidents, such as ransomware. In order to enhance cooperation at Union level, the Cooperation Group should consider inviting relevant Union institutions, bodies, offices and agencies involved in cybersecurity policy, such as the European Parliament, Europol, the European Data Protection Board, the European Union Aviation Safety Agency, established by Regulation (EU) 2018/1139, and the European Union Agency for Space Programme, established by Regulation (EU) 2021/696 of the European Parliament and the Council (14), to participate in its work.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR represents the country within the NIS 2 Cooperation Group and relays its priorities via circulars and its official website. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, entrusts the ILR with designating essential and important operators, and its inspections mechanically reflect themes raised by the Cooperation Group (notably ransomware and supply chain).

Luxgap practice: subscribe your CISO to the ILR RSS feed and integrate ILR circulars as a mandatory input of your quarterly risk committee to anticipate inspections.