Recital 89
Directive on the security of network and information systems · UE 2022/2555
| (89) | Essential and important entities should adopt a wide range of basic cyber hygiene practices, such as zero-trust principles, software updates, device configuration, network segmentation, identity and access management or user awareness, organise training for their staff and raise awareness concerning cyber threats, phishing or social engineering techniques. Furthermore, those entities should evaluate their own cybersecurity capabilities and, where appropriate, pursue the integration of cybersecurity enhancing technologies, such as artificial intelligence or machine-learning systems to enhance their capabilities and the security of network and information systems. |
In Luxembourg, the ILR is the competent authority to supervise cyber hygiene measures of essential and important entities. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, transposes Article 21 of NIS 2 and empowers the ILR to conduct on-site inspections and require dated operational evidence (logs, scan reports, training registers). Essential entities face administrative sanctions up to EUR 10 M or 2% of global turnover for proven failure to apply basic measures.
Luxgap practice: maintain a cyber hygiene file consolidated quarterly (MFA rate, patching KPIs, simulated phishing results, IAM review) ready to be submitted to the ILR within 48h upon request, and align your framework with technical guides published by ENISA and CERT.LU.