For several years, the concept of resilience has been at the core of priorities highlighted by IT security professionals. “It’s important to protect digital assets—and, through them, the company’s activities—against threats. It’s also essential to realize that, by definition, we cannot predict the unpredictable. However, anticipating the unlikely is crucial, as any organization can, at any moment, be the victim of a unique incident. The key is being able to respond and recover as quickly as possible, while limiting impacts,” comments Mohamed Ourdane, Head of Cybersecurity at POST.
Preparing for the Unpredictable
Resilience is broader than cybersecurity alone. “By incident, we obviously mean external attacks, but also other events like equipment failures, software issues, or internal sabotage,” specifies Mohamed Ourdane. Strengthening resilience thus involves clearly identifying risks to which one is exposed or may be exposed. “A risk is the probability of an incident occurring multiplied by its impact,” he explains. In today’s world, with the increasing complexity of information systems, their rapid evolution, and the rise of sophisticated, multifaceted attacks, it is paradoxically necessary to anticipate random events and, above all, demonstrate great agility to face the unknown.
By incident, we obviously mean external attacks, but also other events like equipment failures, software issues, or internal sabotage.
Continuous and Collective Preparation
POST’s cybersecurity teams prepare daily: they exchange threat information within specialized networks, participate in international attack simulation exercises, and continuously develop new scenarios. But beyond exercises, there’s real-world experience.
“Every day, we face real attacks and manage incidents. For months, due to the evolving geopolitical situation, we’ve observed a significant intensification of attacks. In most cases, their effects are not visible because they are contained by our teams, who are trained to handle incidents,” explains Pierre Zimmer, Deputy General Manager of the POST group.
An unprecedented incident
Sometimes, however, certain events can cause noticeable disruptions externally. That was the case with the attack the group suffered on July 23rd. “The incident we faced was previously unknown to everyone,” continues Pierre Zimmer. “In the face of what could not be anticipated, the challenge is to be prepared to minimize the impact and reduce as much as possible the time needed to restore the service.”
To illustrate this resilience, Mohamed Ourdane refers to the fable of the oak and the reed. When facing the unknown, protection mechanisms alone are not enough.
“We must be able to absorb shocks, bend to better recover,” he comments. This is an ongoing effort for POST teams: “It involves identifying our weaknesses, strengthening measures to limit impacts—redundancy, encryption, compartmentalization, etc. We also anticipate future challenges by investing in innovation to ensure the greatest possible control ahead of time.”
Learning lessons every day
On July 23rd, attackers exploited a still-unknown vulnerability to cut the operator—and its customers—off from the public Internet. All services relying on POST's infrastructure—its fiber network and cloud solutions—were not affected. The emergency services switchboard (112), managed by POST, remained technically operational and accessible, although some customers experienced difficulties in making calls during this period, including to emergency numbers. After identifying the issue, POST's teams fixed the problem within about twenty minutes. However, due to side effects, it took slightly longer to restart all the systems disconnected from the public network, causing disruptions on both fixed and mobile networks.
POST did not miss the opportunity to learn from this incident.
“This situation allowed us to assess our level of preparedness. We found that many of our measures worked well and enabled us to restore systems quickly. We also communicated promptly about the incident—both to authorities and across dedicated networks—to warn others of the risks associated with this previously unknown vulnerability,” comments Pierre Zimmer.
Questioning our dependencies
POST also sought to determine whether such an incident could have been better anticipated.
“We exercised this scenario. We concluded that it remains difficult to fully prepare for such incidents except by regularly undergoing similar scenarios—deliberately and controllably disconnecting from the public Internet to evaluate effects,” continues Pierre Zimmer. While not excluded, such exercises do have an impact on the services offered to Luxembourg society, as the solutions we all use depend on resources accessible via the Internet.
When discussing resilience and impact, careful preparation involves properly assessing our dependencies on various resources, aware that these are constantly evolving.
“When discussing resilience and impact, careful preparation involves properly assessing our dependencies on various resources, aware that these are constantly evolving,” comments Pierre Zimmer. “For organizations, it’s also an invitation to reflect on the solutions we use. Proximity can also ensure continuity, notably through multi-cloud approaches, including local or sovereign infrastructures.

