The classic trap
Recital 87 opens a door often overlooked: the ILR and its mandated experts may commission audits, penetration tests or incident response exercises as part of their supervision. In practice, an essential or important entity can be subjected to a contradictory pentest run by a provider chosen by the authority, which will uncover everything your internal audits missed. Organisations that never went through a credible external pentest then discover, under regulatory pressure, an embarrassing gap between their ISO 27001 paperwork and the technical reality.
Why this recital shifts your defensive posture
A supervisory audit is not a courtesy audit. The mandated expert hunts real weaknesses: poorly segmented Active Directory, service accounts with passwords expired since 2019, SMBv1-exposed NAS, EDR not deployed on the IT team's own machines. Three reflexes to anticipate:
- Run an annual offensive pentest by an external provider (not your usual integrator), with red team scenarios including phishing and AD compromise.
- Maintain a live inventory of exposed assets (DNS, forgotten subdomains, public staging environments, misconfigured S3 buckets) because that is where the ILR will start.
- Document post-audit remediation plans with closure evidence, because an unremediated finding from a previous audit becomes an aggravating factor.
How Luxgap automates this risk
Our Luxgap Adversary Simulation Engine continuously reproduces the offensive techniques that ILR-mandated auditors will use, so you discover your gaps before they do, not during the inspection. The platform orchestrates automated attack scenarios mapped to MITRE ATT&CK, executed weekly on your real perimeter via lightweight agents connected to Microsoft Defender, Azure Sentinel, CrowdStrike and Wazuh, without disrupting production.
- Continuously scans your external attack surface (subdomains, certificates, exposed ports, HIBP leaks) and instantly alerts on any new asset your inventory missed.
- Runs simulated phishing campaigns targeted at your high-risk populations (executives, finance, IT admins) with click-rate measurement and immediate training for caught users.
- Tests Active Directory monthly against Kerberoasting, AS-REP Roasting, DCSync attacks and detects attack paths to Tier 0 accounts via integrated BloodHound logic.
- Generates a timestamped, cryptographically signed PDF report, defensible before the ILR, proving regular offensive audits aligned with recital 87 and Article 21 NIS 2.
- Produces an evolving defensive maturity score and a prioritised remediation roadmap, with automatic ticketing to Jira or ServiceNow.
Available as a complement to a Luxgap CISO mandate or as a standalone SaaS depending on your perimeter. Request your demonstration and our teams will run a free 48h blank audit on your external attack surface to materialise your real exposure before any engagement.