· What is your view on the topic we are discussing today?
Muriel Morbé: I prefer to talk about cyber-resilience rather than cybersecurity. The term seems more accurate to me. Our approach is not intended to be alarmist; above all, it aims to help organisations anticipate, prepare for, and respond to cyber threats.
A cyber-resilient organisation is not simply one that protects itself. It is an organisation that can keep its operations running and bounce back when an incident occurs.
Technical tools are, of course, essential. But they are not enough. Resilience is not solely the responsibility of IT teams. It also relies on skills, shared reflexes, and clearly defined responsibilities within a clear governance framework.
· What are the challenges for the economy and businesses?
MM: There are many, including operational, financial, regulatory and reputational challenges. In Luxembourg, this is a strategic issue, particularly for the finance sector, industry, critical infrastructure and data-driven activities.
Regulations such as DORA, NIS2, MiCA and the Cyber Resilience Act can act as catalysts. They encourage organisations to ask the right questions about their governance, risk management, business continuity and internal responsibilities.
However, it would be simplistic to adopt only a compliance-based approach. These frameworks must be a catalyst for progress, helping to structure capabilities and integrate cybersecurity into companies’ overall strategies. In other words, cyber resilience must be treated as a business issue, not just a technical one.
This is where continuing vocational training plays a vital role, enabling the transition from awareness to the ability to take action.
Continuing vocational training plays a vital role, enabling this transition.
· So, is cyber resilience everyone’s business within the company?
MM: Yes, definitely. But that doesn’t mean everyone has to become an expert. Everyone must be trained according to their level of responsibility.
Executives must take the issue to a strategic level, setting the framework and ensuring governance. Employees adopt the right habits in their day-to-day work. Technical teams secure, monitor and organise the response. The risk, compliance, legal, HR and business functions also have a role to play.
It is easy to forget, but many incidents have a human element, such as a hasty click, a weak password, a misunderstood procedure or a tool being used incorrectly. According to Verizon’s annual study, almost 60% of data breaches involve human error.
This shows that awareness-raising must be regular, practical and tailored to the workplace.
· In 2026, what training courses will House of Training be offering on this subject?
MM: In 2026, we will be offering a range of cyber resilience courses. 33 training courses, including 22 new ones, 8 certification pathways and 2 academic programmes. These courses are based on three pillars: governance, to integrate cyber resilience into strategy and risk management; awareness, to install the right reflexes; and resilience, to prepare for crisis management, business continuity and recovery.
The idea is not to train everyone in the same way. Managers, employees, IT experts, lawyers and risk managers have different needs. However, everyone must have the right level of understanding and the ability to take action.
· And what does the future hold? What message would you like to convey to our readers?
MM: Risks will continue to evolve, as will the required skills. Artificial intelligence, the cloud, collaborative tools, quantum computing, and new regulatory obligations will transform practices.
The main message is simple: preparedness is built over time. This requires regular skills updates, ongoing awareness-raising, and the involvement of the entire organisation.
Training teams enables organisations to stay ready in a rapidly changing environment. A better-trained organisation is a better-prepared organisation.
Find out how the House of Training can support your business and staff on their journey to cyber resilience.
