Recital 69
Directive on the security of network and information systems · UE 2022/2555
| (69) | In accordance with the Annex to Recommendation (EU) 2017/1584, a large-scale cybersecurity incident should mean an incident which causes a level of disruption that exceeds a Member State’s capacity to respond to it or which has a significant impact on at least two Member States. Depending on their cause and impact, large-scale cybersecurity incidents may escalate and turn into fully-fledged crises not allowing the proper functioning of the internal market or posing serious public security and safety risks for entities or citizens in several Member States or the Union as a whole. Given the wide-ranging scope and, in most cases, the cross-border nature of such incidents, Member States and the relevant Union institutions, bodies, offices and agencies should cooperate at technical, operational and political level to properly coordinate the response across the Union. |
In Luxembourg, the ILR is the single point of contact for large-scale cybersecurity incident notifications and the interface with EU-CyCLONe and the CSIRTs network. The Law of 28 July 2023 on cybersecurity, as amended by the Law of 28 July 2025, confirms that any large-scale incident notification goes through the ILR, which escalates to European authorities and cooperates with the national CSIRT (GOVCERT.LU and CIRCL depending on the sector).
Luxgap practice: configure your incident procedures to prioritise ILR notification with a justified cross-border qualification from the 24-hour early warning phase, to trigger as early as possible the coordination with the CSIRTs of the affected Member States.