Recital 78

Recital 78

Directive on the security of network and information systems · UE 2022/2555

(78)

Cybersecurity risk-management measures should take into account the degree of dependence of the essential or important entity on network and information systems and include measures to identify any risks of incidents, to prevent, detect, respond to and recover from incidents and to mitigate their impact. The security of network and information systems should include the security of stored, transmitted and processed data. Cybersecurity risk-management measures should provide for systemic analysis, taking into account the human factor, in order to have a complete picture of the security of the network and information system.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR applies recital 78's systemic reading through the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). During inspections, the ILR requires concrete demonstration of coverage of the six NIST phases and consideration of the human factor, with administrative fines up to 10 M EUR or 2% of global turnover for essential entities.

Luxgap practice: prepare an ILR inspection file structured along the six NIST CSF phases, with technical evidence (Defender/Sentinel logs) AND human evidence (training completion rates, phishing simulation results) for each.