With 59% of the national fixed internet market and 49% of mobile internet, Post is not an operator like the others: it cannot be “down.” Its strategic role alongside its reference shareholder--the state--in the development of the country's technological ecosystem in virtually all areas, means that the company must always deliver what is expected of it.
Whether this is good or bad is always open to discussion, but if a large part of the country is deprived of internet or communication because of a “common” bug in a routing control software, as Post’s CEO Claude Strasser explained this Thursday morning, live from the boardroom--that should not happen. But what can be done to avoid this at all costs?
Weary after a short night trying to understand what had happened, the pressure from the government and that of all his customers, Strasser explained that nothing had happened. He explained that there was no evidence so far of malicious external intervention, although this could not be ruled out at this stage, that it was a bug in external software and that there was no reason to suppose that the problem was caused by a Post Group employee.
With four hours of blackout, the company is more or less safe from a contractual point of view, since its contracts must provide for 99% availability. Over the course of a year, a second blackout of this type could happen without costing anything other than bad publicity, which is already a lot both for Post and for Luxembourg.
An objective analysis must be carried out in the coming weeks to improve what has been observed, This is a necessary step after every event of this type"
In addition to the deputy managing director of Post and director of Post Telecom Cliff Konsbruck, Strasser had invited Pierre Scholtes, head of the Telecom Networks department at Post Technologies, to describe a redundant (IT) architecture, “sometimes doubled, sometimes even tripled”... but not resilient, since the software brought down all the grand duchy’s communications.
This question is central when we look both at the group’s evolution from a postal and telecoms incumbent to a technology company--which the Deep brand was launched for--and the government’s three-pronged strategy around data, artificial intelligence and quantum, a strategy largely backed by the relevance of its technological communications and data centre infrastructure.
This question was also asked by the prime minister on Thursday at the last press conference of the season on the government’s activities. Luc Frieden (CSV) expressed his deep concern about yesterday’s incident, during which the security and rescue services could not be reached. He stressed that this event must be analysed to prevent it happening again in the future. This is part of the resilience strategy aimed at protecting the population against external attacks that could render systems vulnerable. These attacks can be of a hybrid type, including natural disasters or cyberattacks.
Is there a problem of dependence on a single operator for telephone rescue services, and is it easy for citizens and the state to change operators? Frieden said he didn’t know the answer at this stage and mentioned that the warning messages people receive may not be understandable to everyone. “An objective analysis must be carried out in the coming weeks to improve what has been observed, a necessary step after every event of this type.”
Post’s managing director, of course, would not say who supplied the company with the notorious software, stressing that discussions were underway to resolve the problem, but the Luxembourg operator works on these subjects with Nokia as well as Ericsson or Juniper. There are three possible scenarios: the software goes off the rails unexpectedly when it has been fully tested and released on the market, bearing in mind that the slightest problem can have major reputational consequences; it has been the subject of a recent update and side effects can appear in a particular ecosystem; or a hacker has managed to inject a piece of malicious code without anyone noticing, which is not uncommon--just ask the social networking star who entrusted everything to his new AI agent, which erased his clients, contracts and databases all at once and without warning in the middle of the night…
In any case, the trio assured us, the bug “did not allow anyone to get their hands on any data.” Hackers have only two motivations: to bring the internet down in order to block a country and its economic activity; or to collect data in order to sell it at a premium to all sorts of more or less reputable players.
The All-IP, a key moment for rethinking resilience
Does Post intend to audit its entire technology stack? No. But it will ask its risk management committee to include this situation in its risk analysis, and, in other words, follow any recommendations it might make in the light of the analysis of this problem, as provided for in the first technical guidance published by the European Union Agency for Cybersecurity (Enisa) in June when moving to “All-IP.”
The issue of resilience is particularly important now. Post will have finished converting all its technologies to All-IP (the transition from traditional telecoms networks (fixed and mobile telephony, television, etc.) to an infrastructure based entirely on the Internet Protocol (rules that govern data transmission) as early as this year, which will further concentrate traffic.
But it will also be doing so because, in the midst of its heavy investments--totalling one billion euros--are the next generations of management systems boosted by artificial intelligence. Like SES with its new O3B Mpower satellites, the technology is capable of deciding for itself how to allocate bandwidth to optimise infrastructures (and therefore attract more customers). It’s a bit like Waze, which dispatches those who want to get from the same point A to the same point B on different routes to avoid saturation of the main route.
As for those wondering why there is no national roaming in Luxembourg, they have forgotten the basics: Post would have been obliged to invest hundreds of millions of euros, with all the difficulties of making its investments profitable by leasing its infrastructure to other operators. This is complicated at a time of pressure on prices, according to the Luxembourg Regulatory Institute (ILR), the telecoms regulator. And in this situation, too, it would have had to bear the cost of interrupting services.
Perhaps Luxembourg will end up devising a minimum service in the event of failure, with all that that entails in terms of debate and regulations. It’s another form of resilience. We don’t yet know whether the inability to reach emergency services--even if the 2G network worked for a while before becoming saturated--will have cost any lives.
This article was originally published in French.




