Recital 88

Recital 88

Directive on the security of network and information systems · UE 2022/2555

(88)

Essential and important entities should also address risks stemming from their interactions and relationships with other stakeholders within a broader ecosystem, including with regard to countering industrial espionage and protecting trade secrets. In particular, those entities should take appropriate measures to ensure that their cooperation with academic and research institutions takes place in line with their cybersecurity policies and follows good practices as regards secure access and dissemination of information in general and the protection of intellectual property in particular. Similarly, given the importance and value of data for the activities of essential and important entities, when relying on data transformation and data analytics services from third parties, those entities should take all appropriate cybersecurity risk-management measures.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite (modifiee par la loi du 28 juillet 2025) et loi du 26 juin 2019 sur la protection des secrets d'affaires

In Luxembourg, the research ecosystem is particularly dense (LIST, LISER, Uni.lu, Luxinnovation, House of Biohealth, House of Startups) and many essential or important entities participate in FNR or Horizon Europe co-funded projects. The ILR, in its supervisory role under the law of 28 July 2023 on cybersecurity as amended by the law of 28 July 2025, expects covered entities to maintain a formal policy framing academic cooperation and the use of analytics providers, including trade secret protection in line with the law of 26 June 2019 on the protection of trade secrets.

Luxgap practice: we systematically embed in our Luxembourg NIS 2 audits a dedicated 'research and innovation ecosystem' module that reviews your FNR agreements, Horizon Europe contracts and CRP partnerships, with remediation of cybersecurity clauses before the next ILR inspection.