What support is NC3 providing in the frame of NIS2?
Municipalities and SMEs that operate essential services are required to quickly comply with the cyber resilience requirements of the NIS2 law. How can Luxembourg's National Cybersecurity Competence Centre (NC3) help them become compliant? Dominique Kogue, its director, explains.
What are NC3’s main attributions or actions within the NIS2 framework?
NC3's role is to raise awareness of best practices and security hygiene, as well as to provide recommendations regarding the NIS2 Act.
For instance, we organise awareness sessions to support municipalities in all aspects of information security governance, and the requirements to be fulfilled under the NIS2 directive, as well as the actions and steps to be taken to comply.
What tools has NC3 implemented to support them?
We have developed different tools to support SMEs and municipalities in improving their security posture and their compliance journey. One of these tools is CyberCheck, a self-assessment solution designed to help organisations evaluate their current level of cybersecurity maturity. CyberCheck consists of a structured set of questions and answers that guide users through the self-assessment process. Upon completion, it generates a report providing an overview of the organisation's current security posture, identifies potential gaps, and offers practical recommendations to help improve cybersecurity and support compliance efforts.
Since the directive also focuses on risk management, we provide training and learning materials on how to use Monarc, our risk management tool, which is also recommended by the regulator.
Our NC3 eLearning platform, currently available exclusively to municipalities, is designed to strengthen cybersecurity awareness among municipal employees. It provides municipalities with tools to create and launch cybersecurity awareness campaigns, as well as conduct phishing simulation campaigns to help employees recognise and respond to phishing attempts. The platform has been available since the beginning of the year, and several awareness campaigns have already been successfully launched. It enables municipalities to foster a stronger cybersecurity culture through continuous training and practical exercises.
Our training offer also includes an “Introduction to information security: Cybersecurity for everyone”, as well as a session dedicated to teaching colleagues on security issues (“Train the Trainer”).
Furthermore, we support the regulator in developing tools. For instance, SERIMA (SEcurity RIsk MAnagement) is a centralised open-source cybersecurity and risk analysis platform. It allows entities to perform standardised risk analyses, and to securely report security incidents and measures to competent authorities such as the Institut Luxembourgeois de Régulation (ILR). Companies and municipalities which operate essential services must use it to report cybersecurity incidents to the competent authority.
A wide range of private actors across the ecosystem is available to support organisations concerned by NIS2. They can be found at cybersecurity.lu.
Does NIS2 concern all municipalities?
It concerns all municipalities that provide essential services, including water, electricity, waste, etc.
The objective of NIS2 is to ensure the resilience of the ecosystem. If this resilience is not in place, a cyber incident can lead to the paralysis of public services and the massive theft of citizen data. This can have long-term impacts on consumers, whose profile can be used by hackers to carry out malicious actions and on the economy of the whole country.
Furthermore, NIS2 provides that CEO of SMEs and city mayors are responsible for ensuring that the implementation is done correctly and that the requirements of the Directive are respected. They are also held penally responsible.
Therefore, if not done yet, they need to tackle the cyber issues of their organisation rapidly. They must be aware of what needs to be put in place. They must also ensure good cybersecurity governance, in order to be compliant with the law.
What are their main demands regarding the implementation of NIS2?
During our awareness campaigns, we receive many demands. The main one so far is about where and how to start. Another one is about the reference standard to use. As a first step, it is important to understand the organization's current cybersecurity posture. This is where our CyberCheck platform can be particularly valuable. Standards such as ISO/IEC 27001, the NIST Cybersecurity Framework, or the CIS Critical Security Controls provide a solid foundation. However, organisations must also ensure they address any NIS2 requirements that are not covered by the chosen framework.
What main recommendation would you share with companies and municipalities?
If you haven’t started yet, you need to start now. You need to know that several actors are there to help. Do not hesitate to seek help. Many tools are available on our website that can help you understand your level and posture and start running tests while keeping an eye on current risks.
