The classic trap
Recital 78 informs Article 21 by requiring a systemic reading of cybersecurity: it is not a firewall checklist, it is a complete picture that includes the human factor, data at rest, in transit and in processing, and the full incident lifecycle (identify, prevent, detect, respond, recover, mitigate). The ILR sanctions entities that present a paper ISMS but cannot demonstrate concrete coverage of the six NIST phases nor a mapping of their dependency on information systems. The classic trap: having a modern EDR but no measure on human error (phishing, mishandling, shadow IT), or the reverse.
The six phases your framework must explicitly cover
- Identify: asset mapping, business dependencies and human factor (who has access to what).
- Prevent: technical hardening (MFA, segmentation, encryption) AND continuous staff training.
- Detect: SIEM, EDR, anomalous behavior monitoring, real-time alerts.
- Respond: tested incident response plan, crisis cell, ILR notification within 24h/72h.
- Recover: immutable backups, tested recovery plan, documented RTO/RPO.
- Mitigate: post-incident lessons learned, tracked corrective actions, updated risk register.
The systemic analysis required by recital 78 means each phase must be assessed across its technical, organizational AND human dimensions. A purely technical measure that ignores the end user is non-compliant.
How Luxgap automates this risk
Our Luxgap Systemic Cyber Radar turns recital 78's systemic analysis requirement into a living matrix that covers the six NIST CSF phases, cross-referenced with the three dimensions (technical, organizational, human). The tool connects to Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, your Active Directory and your LMS (KnowBe4, Riot, Phished) to materialize in real time the actual coverage of your framework, without any self-declaration.
- Computes a maturity score per NIST CSF phase (Identify, Protect, Detect, Respond, Recover) cross-referenced with technical, organizational and human controls to reveal blind spots.
- Automatically detects high-risk users (repeated phishing clicks, abnormal external sharing, excessive privileges) by correlating Defender for Office 365, Purview and AD logs.
- Scans data coverage across the three states: encryption at rest (BitLocker, Azure Disk Encryption), in transit (TLS 1.3, certificates), and in processing (Confidential Computing, masking).
- Simulates incident scenarios (ransomware, exfiltration, privileged account compromise) and measures real detection and response time on your connected SI.
- Produces a cryptographically sealed timestamped PDF report, enforceable before the ILR during an inspection, demonstrating the systemic analysis required by recital 78 and Article 21.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real SI, with a free blank audit within 48h to measure your systemic exposure before any engagement.