Recital 86

Recital 86

Directive on the security of network and information systems · UE 2022/2555

(86)

Among service providers, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and, because of their close integration in the operations of entities pose a particular risk. Essential and important entities should therefore exercise increased diligence in selecting a managed security service provider.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for NIS 2 incident notifications and inspections, under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). The Luxembourg MSSP market being highly concentrated around players such as POST Cyberforce, eBRC, Excellium (Thales), Telindus and a few specialised boutiques, ILR is particularly sensitive to concentration risk: a simultaneous failure at a major MSSP would impact a significant share of the national economy. Documenting the choice of a single MSSP without analysing this concentration is a classic gap during inspections.

Luxgap practice: for each essential or important entity, we produce a group-level MSSP concentration map and a technical plan B (pre-qualified second provider, internal switchover capacity) documented in the ILR file, which closes the topic if questioned during an inspection.