The classic trap
This recital lays down a founding principle of NIS 2: security is not an obligation of means that can be delegated to the IT provider, it is a primary responsibility of the essential or important entity. In practice, the ILR heavily sanctions organisations that present a written security policy but are unable to demonstrate a living, dated, reviewed risk analysis connected to the technical measures actually deployed. The trap is not the absence of a policy, it is the absence of a culture of risk management: a 2021 Word document is no longer enough.
What this recital concretely changes for article 21
Article 21 of NIS 2 is read in light of recital 77. Concretely, during an ILR inspection, the auditor will look for evidence of:
- A risk analysis dated less than 12 months ago, signed by management (not by IT alone).
- A critical asset map automatically updated, not a frozen Excel.
- A risk matrix with scoring (probability x impact) connected to traceable mitigation measures.
- Evidence that measures are proportionate to identified risks: no generic ISO 27001 layer copy-pasted.
- Periodic reviews after incidents, after major SI changes, or after threat evolution (e.g. new sectoral ransomware).
- Documented involvement of the management body (article 20), including training.
Recital 77 turns a declarative obligation into a demonstrable and cultural one. This shift is what traps organisations used to paper compliance.
How Luxgap automates this risk
Our Luxgap Risk Culture Engine transforms your static risk analysis into a living organism that re-evaluates itself automatically with every change detected in your SI. The tool connects a specialised LLM agent to your operational sources (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, Active Directory, Odoo, ITSM) and continuously recomputes the NIS 2 risk matrix without ever asking the CISO to fill a single spreadsheet.
- Detects in real time every new critical asset appearing in your SI (new server, new SaaS application, new data flow) and integrates it automatically into the map.
- Recomputes the risk score every 24h by cross-referencing published CVEs, ENISA sectoral alerts and actual exposure measured by your connected EDRs.
- Generates a timestamped, cryptographically sealed risk analysis PDF, enforceable before the ILR during an inspection, with electronic signature of management.
- Alerts management on Teams or Slack as soon as a risk changes criticality, with a quantified mitigation proposal (cost / lead time / expected risk reduction).
- Produces the quarterly risk committee minutes pre-filled, proving the management body involvement required by article 20.
- Traces every accepted risk decision with timestamp and signatory, materialising the risk management culture intended by recital 77.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS brick depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real perimeter, with a free 48h white audit to measure your risk management culture maturity before any engagement.