Recital 77

Recital 77

Directive on the security of network and information systems · UE 2022/2555

(77)

Responsibility for ensuring the security of network and information system lies, to a great extent, with essential and important entities. A culture of risk management, involving risk assessments and the implementation of cybersecurity risk-management measures appropriate to the risks faced, should be promoted and developed.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for controlling the concrete implementation of this risk management culture. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, gives the ILR the power to conduct on-site inspections, require the production of the risk analysis and impose administrative sanctions of up to 10 million euros or 2% of worldwide turnover for essential entities. The ILR expects a formalised, dated risk analysis, signed by management and connected to deployed technical measures.

Luxgap practice: we align the Risk Culture Engine with the ILR framework and deliver a bilingual FR/EN report directly usable in case of inspection, with LuxTrust or Qualified Trust Service electronic signature.