Showing posts with label Luxembourg. Show all posts
Showing posts with label Luxembourg. Show all posts

Belgium published first, France went deeper. Belgium's CCB released CyFun well before the October 2024 NIS 2 transposition deadline, built on NIST CSF and officially mapped to ISO 27001/27002. France's ANSSI published ReCyF, but as of March 2026 the underlying legislation still has not passed - making it a technically superior but legally unenforceable framework.Bottom line: ISO 27001-certified organisations in Belgium are largely compliant with a manageable gap list. The same organisations in France still have significant work ahead - and no hard deadline yet to do it by.

Table of Contents

  1. Introduction
  2. Belgium - The Head Start (4 Level Architecture, Control Counts, ISO27002 clusters, What are key measure and why do they matter, self-assessment)
  3. France - The Thorough Approach (The objective and means architecture, still waiting for the law, ISO Alignement ANSSIs own assessment
  4. ISO27002 Mapping as a common Anchor
  5. The Divergences
  6. Practical Impliaction

Part I: Introduction - One Directive, Two Answers

When the EU adopted NIS 2 (Directive 2022/2555) in December 2022, it set a clear expectation: member states had until October 17, 2024 to transpose its requirements into national law. What followed, at least across the Franco-Belgian border, is a study in contrasting regulatory cultures, institutional histories, and practical philosophies.

NIS 2 expanded covered sectors from 7 to 18, lowered size thresholds, made supply chain security and multi-factor authentication explicit obligations, and - most significantly - introduced Article 21's detailed list of required risk management measures. What the directive deliberately does not do is specify how each measure should be implemented. That granularity was left to member states, producing genuine policy diversity: two technically credible frameworks that are compatible at the technical level but structurally different in regulatory philosophy, timing, and practical demands.

The timeline below tells the story at a glance. Belgium formalised an existing, mature framework and published its official cross-framework mapping nine months before the deadline. France is still working through its legislative process 18 months after that same deadline.

Figure 1 : NIS2 Transposition timeline. Belgium met the Octobre 2024 deadline, France Transposing law remains a bill of March 2026.


This blog post will be updated periodically as I come across new practical information and experiences. You can subscribe to my blog if you wish to be kept updated.

Updates : 
  • 24.07.2020: Added number of reported data breaches to Statistics
  • 25.07.2020: Added the Role of the DPA as captured within the GDPR and added references
  • 25.07.2020: Added the section "Parliamentary Oversight" capturing parlamentary enquiries
  • 26.07.2020: Corrected the part about getting a copy of your original complaint. In fact, I only have received parts of it and am still waiting to receive the rest.
  • 27.07.2020: Due to popular demand I added a section "Legal Procedure".

I thought it is useful for the general audience to summarise my experience working with the CNPD as a Data Subject. Aligned with many other administrative procedures in Luxembourg: they have a nice appearance at the frontend but are tilted against your interest in the backend.



How to effectively evade the GDPR and the reach of the DPA (PART 1)


This is a post in a series of posts :
  1. How to deal with the DPA of Luxembourg as a Data Subject <-- Interesting in the context of this post.
As my regular readers know I reluctantly trust anything that isn't tested and battle proof. In the last 2 years, I applied the same logic that I apply to vulnerability research to the Data Privacy environments and proceeded to test a broad range of Data Subject Rights. Expect a few disclosures following this one.

In true Information Security Fashion (insiders will understand) have attributed this weakness the ID :
  • CDPWE-0001 - Does not designate a Representative in the European Union

Introduction

When I searched Google for my name an interesting website came up in the results. A company called "Rocket Reach" allowed others to buy access to my personal data. I was intrigued as I have never given any consent for Rocketreach to store (or even sell) my data and I saw no other legal basis for RocketReach processing of my data.

"Rocket Reach" a data broker that describes it's service as :
"Connect directly with the right decision makers, using the world's largest and most accurate database of emails and direct dials. Real-time verified data for 430 million professionals across 17 million companies, worldwide.Trusted by over 5.0 million users — powering sales, recruiting, and marketing at companies large and small.
Prospect, connect and converse with your leads at scale."

Issuing a DSAR

On the 5th of April  2019, I asked Rocketreach access to my personal data (Data Subject Access Request) and asked for the purpose and the legal basis of processing. Instead of giving me access to my data and reply adequately, RocketReach decided to delete/remove all traces of it and informed me that it did so the same day.

While it might be surprising to some, this is actually a common reaction to DSARs when the Data Controller realizes the data they have may have no real legal basis.

Filing a complaint 

On the 05th of April 2019, I filed a complaint with the Luxemburgish Data Protection Agency (CNPD). The reference for this complaint is #3018 (For those that want to request information/documents from the CNPD).

Waiting for roughly a year

"We agree with you but we can't do anything, sorry, move on"

On the 6th of March 2020 (1 year!) the CNPD responded as follows (Original Version on top, the Translated version at the bottom).

Monsieur Zoller,
La Commission nationale pour la protection des données (CNPD) se permet de revenir vers vous concernant votre réclamation du 5 avril 2019 à l’encontre de la société RocketReach.
Dans le cadre de l’instruction de votre réclamation, la société RocketReach nous a communiqué qu’elle considère que ce sont les utilisateurs de ses services, et non elle-même, qui sont les responsables du traitement pour ce qui concerne les données à caractère personnel traitées sur son site internet.
Par ailleurs, il ressort également de cette instruction que la société RocketReach est une société située aux Etats-Unis d’Amérique ne disposant pas d’un représentant dans l’Union au sens de l’article 27 du règlement général sur la protection des données (RGPD).
Au sujet des responsables du traitement établis dans des pays tiers, comme les Etats-Unis d’Amérique, nous souhaitons attirer votre attention sur le considérant (116) du RGPD qui précise que:
« Lorsque des données à caractère personnel franchissent les frontières extérieures de l'Union, cela peut accroître le risque que les personnes physiques ne puissent exercer leurs droits liés à la protection des données, notamment pour se protéger de l'utilisation ou de la divulgation illicite de ces informations. De même, les autorités de contrôle peuvent être confrontées à l'impossibilité d'examiner des réclamations ou de mener des enquêtes sur les activités exercées en dehors de leurs frontières. Leurs efforts pour collaborer dans le contexte transfrontalier peuvent également être freinés par les pouvoirs insuffisants dont elles disposent en matière de prévention ou de recours, par l'hétérogénéité des régimes juridiques et par des obstacles pratiques tels que le manque de ressources. »
Dans le cas de votre réclamation cela signifie que, bien que nous ne partagions pas le point de vue de RocketReach et que nous sommes au contraire d’avis que cette société est bien à considérer comme responsable du traitement pour les traitements de données à caractère personnel effectués sur son site internet, il nous est impossible de poursuivre plus en avant le traitement de votre réclamation. En effet, nous ne disposons pas des pouvoirs de mener des enquêtes et de faire appliquer les décisions que nous serions amenés à prendre sur le territoire des Etats-Unis d’Amérique.
Nous sommes dès lors au regret de vous informer que nous considérons qu’il nous est impossible de poursuivre de façon effective le traitement de votre dossier. 
Veuillez agréer, Monsieur Zoller, l’expression de nos sentiments distingués.

English Translation

Mr. Zoller,
The National Commission for Data Protection (CNPD) would like to get back to you regarding your complaint of 5 April 2019 against the company RocketReach.

Rocket Reach has informed us that it considers that it is the users of its services, and not itself, who are responsible for processing personal data processed on its website. Furthermore, it also emerges from this instruction that RocketReach is a company located in the United States of America that does not have a representative in the Union within the meaning of Article 27 of the General Regulation on Data Protection (RGPD). 

As regards data controllers established in third countries, such as the United States of America, we would like to draw your attention to recital (116) of the GDPR which states that: 'When personal data crosses the external borders of the Union, this may increase the risk that individuals may not be able to exercise their data protection rights, in particular to protect themselves against unlawful use or disclosure of such information.
Similarly, supervisory authorities may be faced with the impossibility to investigate complaints or activities outside their borders. Their efforts to work together in the cross-border context may also be hampered by insufficient preventive or remedial powers, heterogeneous legal regimes and practical obstacles such as lack of resources. » 

In the case of your complaint, this means that, although we do not share RocketReach's view and to the contrary believe that RocketReach is the data controller for the processing of personal data on its website, we are unable to take any further action in relation to your complaint. We do not have the authority to investigate and enforce any decision we would have to take in the United States of America. 

We regret to inform you that we consider it impossible for us to proceed with the processing of your case.

In Summary -  Rocketreach has not met the requirement of the GDPR to name an EU representative (Art27) to account for the processing of European Personal Data, they furthermore process data with no legal basis of millions of European data subjects. In their answer, the CNPD makes it sound like it is optional, it isn't. Instead of pursuing Rocketreach locally on that basis alone, the CNPD just gives up arguing it has no jurisdiction in the US.

In other words, just don't designate a representative in Europe, build your business model around the illegal exploitation of data from millions of European data subjects and you are fine?

I  am fully aware that I could engage in legal procedures.  That's however not in my interest as I don't want to bear the costs and efforts. The overall question you should ask yourself is: Do we need a European Institution that handles extra-territorial investigations and fines? Why should it take the time, money, and energy from an individual when the DPA is supposed to defend the rights of the data subjects?

What the CNPD could have done according to the GDPR [1]
  • to impose a temporary or definitive limitation including a ban on processing;
  • to order the suspension of data flows to a recipient in a third country or to an international organisation.
  • to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case;
  • to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;

[1] https://cnpd.public.lu/en/commission-nationale/pouvoirs.html

Instead, Rocketreach just continues to sell the personal data of millions of European data subjects like nothing ever happened. Including all of the below :


Members of the CNPD

Members of the European Data Protection Board


CNIL










The Luxemburgish Constitution is not for its people?

Updates:
29/04/2020 - Added section entitled "About the non-deterministic nature"

Bold Statement? Let me take a moment and explain why I came to this rather confrontational conclusion. 

Since the measures against the SARS-CoV-2 Pandemic were introduced my interest in our constitutional rights grew, I was curious to understand under which legal frameworks those measures operated. 

I must admit that I had a clearer understanding of the US Constitution that I had about the constitution that applies to me. That may have been ignorance on my part, but as I soon found out, it's not solely ignorance, it's simply because the Luxemburgish constitution doesn't really say much about the rights of its people and in some cases has quite extraordinary gaps.

Also of note is the fact that the government chooses to not directly involve its citizens in the revision of the constitution, which is in itself I find quite remarkable.

Disclaimer: I am not a legal professional but a simple citizen. I would argue that fundamental rights in a constitution of a state is to be written in such a way for the average citizen to know and understand. I expect to be wrong in certain areas. Feedback and critique welcomed. This post is in English for the many inhabitants of Luxembourg that cannot read the constitution that may or may not apply to them.


As a start and for comparision, here is a list of constitutions * :

* I am aware that all of these have distinctly (in some cases completely) different legal systems.

A list of gaps

  • Contrary to for example Germany, the constitution says nothing about Human Dignity and the state's obligation to protect it. That's actually the first article from the German Constitution. "(1) Die Würde des Menschen ist unantastbar. Sie zu achten und zu schützen ist Verpflichtung aller staatlichen Gewalt." 
    In that context, I'd like to point out and emphasize that the luxembourgish  constitution however explicitly guarantees that the state will protect the environment (nature) and the promotion of the well-being of animals. (Art11 bis).
  • The Luxembourgish Constitution makes no reference to guarantee the fundamental rights of defense. All Luxembourg case-law on procedural and defense rights are based on Article 6 ECHR and does not rely on the Constitution, which does not expressly contain such rights.
  • The Luxembourg Constitution has not explicitly provided any constitutional body to protect fundamental rights
  • The Luxemburgish Constitution with regards to fundamental rights (Chap 2) is often arbitrary in the sense that for the most part it refers to laws that should at a later stage determine the details of those rights. Contrary to for example the constitution of Germany, there is a clear lack of directly deterministic language. Not using a deterministic language guarantees flexibility for the government to change adapt these (through law) at the expense of clarity and  rigidity. It also however is in direct contradiction of the right guaranteed in Art. 11.

    Let's expand on that; the constitution acknowledges the  "droit naturel humain" as fundamental right in Art. 11.

    Simply put the "natural human right" are rights that you own because you are human. 
    The "Droit Naturel Humain" seeks to establish a standard that is immune to the fluctuations of history and morals and avoids the arbitrariness of human judgment. 

    However, the section on fundamental rights within the Luxemburgish constitution seemingly contradicts the very intent of this concept by introducing relative statements all across it's section of fundamental rights ("as determined by law").

    Natural law is actually opposed to positive law, which is the law in force, enacted by society or the State, which by definition is changeable, according to places and times.

    Fundamental rights hence should be clearly and deterministically formulated as far as possible, but they often are not and deliberately weak and hollow :

    Examples :L’Etat garantit la protection de la vie privée, sauf les exceptions fixées par la loi La liberté du commerce et de l’industrie, l’exercice de la profession libérale et du travail agricole sont garantis, sauf les restrictions à établir par la loi

    La liberté individuelle est garantie. - Nul ne peut être poursuivi que dans les cas prévus par la loi et dans la forme qu’elle prescrit. - Nul ne peut être arrêté ou placé que dans les cas prévus par la loi et dans la forme qu’elle prescrit.

Are they really gaps?

In Luxemburg fundamental rights are not limited to the Consitution only, they include the UN Charta of Human Rights and the European Declaration of Human Rights and the Luxemburgish courts have given precedence of these obligations over national law.

It is true that Luxembourg is subject to the EDHR/UN Charta and implicitly is bound by these. It is also true that Luxembourg operates on a model where the courts do verify cases in alignment to treaties and fundamental rights. 

That said, I have to say two things for those arguing that this situation is fine:
  • If it's the case that these take precedence, then I see no reason to not just simply add them to the revision of the constitution, making it both more accessible and understandable for an average citizen (.i.e. me).
  • Personally I find it quite frightening that an average citizen is supposed to read, understand and cross-reference existing jurisprudence (or nonexisting for that matter - we have many articles with zero existing case law..) , international treaties, chartas for them to understand their fundamental rights as a citizen of Luxembourg. A constitution and a list of fundamental rights shall be easy to understand and easy to comprehend by it's people.
It is therefore that I come to the conclusion that Luxemburgs' constitution, in it's current (and planned) form is simply not meant for its people, and that's something I'd like to see challenged.


About the non deterministic nature 

To make this clearer, let's take a few examples.

Luxemburgs current understanding of describing a fundamental human right in a constitution is best demonstrated by Art 25 :
«Art. 25. La Constitution garantit le droit de s’assembler paisiblement et sans armes, dans le respect des lois qui règlent l’exercice de ce droit, sans pouvoir le soumettre à une autorisation préalable. - Cette disposition ne s’applique pas aux rassemblements en plein air, politiques, religieux ou autres; ces rassemblements restent entièrement soumis aux lois et règlements de police
Translation :
"ART. 25. The Constitution guarantees the right to assemble peacefully and unarmed, in accordance with the laws regulating the exercise of this right, without being able to subject it to prior authorization. - This provision does not apply to open-air, political, religious or other gatherings; such gatherings remain entirely subject to the laws and police regulations."
That's not a description of a fundamental right, and in my opinion has no place in a constitution. That is basically saying, you have a right, and we restrict that right. Then after finishing that very sentence and for good measure, we continue to restrict your "fundamental right" even further by excluding open-air, political, religious or "other gatherings" and pointing to laws and police regulations that are not futher described. This is both ambigious and deliberate. In my opinion, that's plain nonsense and a travesty and has no place in a section on fundamental rights in a constitution.

Let's take a look at Art 8 of the German Constitution describing what is basically the same fundamental right.
Art. 8 GG : "(1) Alle Deutschen haben das Recht, sich ohne Anmeldung oder Erlaubnis friedlich und ohne Waffen zu versammeln. (2) Für Versammlungen unter freiem Himmel kann dieses Recht durch Gesetz oder auf Grund eines Gesetzes beschränkt werden.
Translation :
(1) All Germans have the right to assemble peacefully and without weapons without registration or permission.(2) For assemblies in the open air, this right may be restricted by law or by virtue of a statute.
Apart from being short and to the point; the German constitution allows for restrictions by law without stating that the constitution effectively already restricts them, Germany has not included  restrictions in the constitution even what they are. 


Changes I'd like to see

  • Take Chapter 2 (Fundamental Rights) and transform it into deterministic statements actually applying Art11 ("Natural Human Law") as much as possible. i.e "Your right is XYZ", instead of: "Your right on topic X will be determined within a law and is not ..". Those articles in essence just state that there must be a law, not the intent or limits such laws would have. If I was able to convey my logic to my reader you will understand that all I am really asking for is applying Art.11 of the constitution "Droit naturel Humain".
  • Fundamental rights also serve the purpose to protect from arbritary decisions by governments. we should stay away from mechanisms allowing governments to change the fundamental rights the constitution by way of backdooring it with "will be determined within the law".

    Granted, yes there are other procedures with checks and balances within the legislative process and yes sometimes it is necessary to say that, but that's should be the exception not the norm. That said, a fundamental right is fundamental and only allowed to be circumsized within limits. These limits could be described. 
  • Involve citizens more into the revision process 

If you master German I recommend to read "Grundrechte im Großherzogtum Luxemburg"

Final Word

I leave you with the following - which I think is relevant and applicable to the current situation  :









This blog has been my home for over 20 years, I grew up in Luxembourg and have spent 25+ years building, breaking and safeguarding technology - across security engineering, vulnerability research and red teaming, software development, product management, governance, risk management and internal control, and leadership.

Along the way, I’ve held senior roles at Amazon, J.P. Morgan, HSBC, Julius Baer, Verizon Enterprise and Proximus - and supported many Fortune 100 organisations as a trusted advisor.

The last decade has been second-line overseeing non financial risk overseeing technology and ICT risk oversight across regulated financial institutions

My previous roles span the full breadth of security leadership: Head of Technology Risk Control (CISO) @ Julius Baer Europe, Head of Technology Risk and Compliance (CISO) at J.P. Morgan Mobility Payment Solutions, CISO at Amazon Payments, EMEA Head of Security Risk & Compliance at Amazon, Head of Country Risk for HSBC Luxembourg, and EMEA Threat & Vulnerability Management Practice Lead at Verizon Enterprise. Before that, I worked as a Director of Product Security and Services and Senior Offensive Security Engineer at n.runs, a Security Engineer at Telindus/Proximus.

I’m a proud founding father and distinguished subject matter expert for the ISC2 CSSLP Certification, a (former) board member at OWASP Benelux, and a standing Advisory Board Member for the C|ASE programme at EC-Council (Certified Application Security Engineer).  I also enjoyed mentoring at the Luxembourg School of Business and Women4Cyber and served as an external Master Thesis advisor at KU Leuven.

I've always believed that openly sharing knowledge is one of the best ways to raise our collective security baseline, make the field more accessible, and encourage people just starting out. Throughout my career I've volunteered with several organisations and published research - sometimes privately, sometimes professionally, always to give something back.

So it follows naturally that over the years I've published a body of security research and presented at conferences around the world


Academic References & Citations

Some of my work has been cited in academic journals, papers, PhD theses and conference presentations. Below is a list of peer-reviewed journal articles, conference proceedings, PhD dissertations, that reference my publications:

 ► 
Academic References & Citations


Advisories / Tools / Talks

A selection of my vulnerability disclosures, tools and talks :

 ► Vulnerability Disclosures



Get in touch
If you want to connect, I’m active on X and LinkedIn — and there’s also an online form if you prefer reaching out directly.

How I started in the field of Information Security

As a teenager I was captivated by technology. My self-taught journey began with dabbling in BASIC development on the Atari 1024ST— yes, the one with cassette decks! The thrill of watching a machine come alive with my commands and logic was nothing short of magical.

I'm grateful to my parents for nurturing my tech inclinations and later transitioned to the iconic IBM x68 architecture. This shift allowed me to delve into the world of 3D modeling and animations with 3D Studio, which later evolved into 3DS Max. I also happen to explore  the realm of music production using "Fast Tracker II", a music tracker with roots in the Demo Scene (Example).

The advent of the Internet was a game-changer for me. It opened doors to a universe of free knowledge, introducing me to the intricacies of networks, protocols, and the intriguing world of cyberattacks.

My deep dive into the Infosec realm began when I stumbled upon an article about a Remote Access Tool named BO (cDC) in the German magazine "ct". At 15, my curiosity was piqued. I was eager to understand its mechanics and the technology that facilitated remote access. This led me to explore the intricacies of IP, TCP, UDP, and the inner workings of operating systems. I dedicated years to building a solid foundational understanding.

By the late 90s, I had analyzed and reverse-engineered a vast number of malicious codes. Back then, the tools for analysis were rudimentary compared to today's standards. To the best of my recollection, there weren't any publicly accessible ones. I took it upon myself to curate what might have been the world's most extensive repository of malware analysis, possibly pioneering the first centrally maintained list of indicators of compromise.

My work gained recognition, with mentions by the SANS Institute, citations in various books, and integration into both commercial and non-commercial IDS rules, as well as AV vendors. Reflecting on it now, I'm struck by the realization that some IDS systems still carry my original signatures.

Much of my personal time was dedicated to learning, reading, and hands-on practice. As I delved into multiple programming languages, explored both binary and dynamic reverse engineering, and immersed myself in an information security environment, significant breakthroughs began to emerge.

During this period, my passion for Information Security truly crystallized. After parting ways with n.runs in mid-2009, I established G-SEC. My vision was to create a local non-profit organization aimed at fostering interest and awareness, especially for those still contemplating their career paths.

My research led me to uncover hundreds of vulnerabilities, including critical defects in key tech components. I pioneered the first Bluetooth cryptographic attack and made the code open-source. I take particular pride in identifying high-profile vulnerabilities in software from giants like Microsoft, Oracle, Google, and Apple. This body of work culminated in IBM X-Force recognizing me as one of the Global Top Vulnerability Discoverers of 2009.