Skip to content
Cyvalent

Ideas, guidance, and perspectives on making cybersecurity more effective.

Explore our latest insights, strategic frameworks, and practical advice for navigating the modern threat landscape. If you want to discuss any of these topics in more detail, contact us.

Latest Insights

If Your Software or Connected Product Enters the EU Market, the Cyber Resilience Act May Apply

The EU Cyber Resilience Act, Regulation (EU) 2024/2847, introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market. It is horizontal: it does not target one sector in the way NIS2 or DORA does. It targets the product and the economic activity around that product: manufacturing, importing, distributing, and making products with digital elements available in the EU.

Read article

What You Should Actually Expect from Cyvalent 360 Cyber Services

Cyvalent 360 Cyber Services provides the practitioner capacity to run an ongoing cybersecurity governance programme—from risk and compliance work to management reporting and incident readiness. It is aimed at organisations that need hands-on delivery, with CISOaaS available where senior security leadership is missing.

Read article

DORA Supplier Risk in Luxembourg: From Messy Supplier Lists to a Register You Can Defend

DORA's ICT third-party risk rules—Articles 28–30 of Regulation (EU) 2022/2554—have applied directly since 17 January 2025. In Luxembourg, the Law of 1 July 2024 gives the CSSF and CAA the powers needed to supervise and sanction DORA compliance and transposes Directive (EU) 2022/2556. CSSF-supervised DORA entities must also follow the local requirements in Circular CSSF 25/882; CAA-supervised entities follow the CAA's DORA instructions.

Read article

The EU's Cybersecurity and Resilience Rulebook, in Plain English

If you run or manage an organisation in Luxembourg, the cyber and resilience rulebook can look crowded: the Luxembourg NIS 2 and critical-entities laws sit alongside directly applicable EU regulations such as DORA, the Cyber Resilience Act and the AI Act. The practical question is not which instrument matters most, but which trigger applies to each legal entity, activity, product or service.

Read article