Phishing, ransomware, credential compromise — these are terms you've likely heard in the media, at work, or elsewhere. The rise of digital technologies over the past 30 years has inevitably led to exponential growth in cybercrime. SMEs are no exception to this trend. Olivier Antoine, Director of Cybersecurity Services at Luxcontrol, explains: “Today, SMEs have become a prime target for cybercriminals because they often act as suppliers to larger companies. Compromising them often provides access to their clients' systems.” Recent statistics show that about one in two SMEs does not survive more than six months after a cyberattack. Yet, many remain unaware of the risks. “Many SME owners tell us: ‘I have no idea where I stand in terms of cybersecurity, I know nothing about it, I’ve outsourced everything to a provider.’ As long as they haven’t been attacked, they fail to grasp the importance of protecting their systems.” In this context, Luxcontrol’s teams have developed a method to quickly assess a company’s cybersecurity level: the Cyberscore. The focus is primarily on prevention.
Today, SMEs have become a prime target for cybercriminals because they often act as suppliers to larger companies. Compromising them often provides access to their clients' systems.
Prevention is better than cure
The Cyberscore is presented as a scale from A to E, evaluated by Luxcontrol’s experts. “In less than five days, a company can gain a clear understanding of its security posture and receive a pragmatic action plan.” How does it work in practice? “A preliminary meeting with the client takes place before starting the on-site analysis. Our experts, certified in standards such as ISO/IEC 27001, then conduct an assessment with designated participants. They usually spend one to two days on-site before drafting a report compiling their observations and a corresponding action plan. The process concludes with a presentation to the client and the disclosure of the score.” The Technical Director adds: “This is not an audit aimed at pointing out failures, but rather a pragmatic and educational approach designed to help leaders understand their priorities and prepare for common threats.”
The assessment is based on 92 criteria, including 18 ‘critical’ ones — similar to a vehicle inspection distinguishing between major and minor faults. If a key criterion is missing, it will directly affect the final evaluation. Sébastien Weiland, Director of Information Systems at Luxcontrol, highlights several key areas of vigilance: “We emphasize the importance of backups, for example. A company must be able to quickly access verified backup files that are regularly tested. This also includes strong authentication, secure email infrastructure (both incoming and outgoing), and comprehensive device protection.
We emphasize the importance of backups, for example. A company must be able to quickly access verified backup files that are regularly tested.
This last point underlines a consistent factor in cyber incidents: humans. “In the majority of cases, human error plays a role in cyberattacks — 85% of them begin with an employee’s mistake. Luxcontrol’s Cyberscore helps prevent potentially significant losses with a contained budget. “The assessment starts at €5,000, depending on the complexity of the information systems,” explains Olivier Antoine. This cost-conscious approach continues into implementation: “Following the assessment, we often recommend suitable tools — including open-source solutions — to align with the budget constraints of smaller organizations.”
Anticipating Standards
Cybersecurity is no longer an isolated matter: strengthening your own systems also helps protect the entire value chain. The European Directive NIS 2 (Network and Information Security), coming into effect in Luxembourg at the end of 2025, significantly expands the scope of NIS 1. It applies to all companies operating within the European Union — including those based abroad if they provide services to European citizens. The size criteria are now clearly defined:
Large companies (more than 250 employees or over €50 million in revenue) Medium-sized companies (50 to 250 employees and revenue between €10 million and €50 million) Small companies (fewer than 50 employees and less than €10 million in revenue) “NIS 2 is the continuation of NIS 1, but with a much broader scope,” emphasizes Olivier Antoine, Director of Cybersecurity Services at Luxcontrol. “One of the key aspects of this directive is supplier oversight. In simple terms, clients will be able to hold their suppliers — including SMEs — accountable for their cybersecurity maturity. That’s where the Cyberscore becomes particularly valuable.”
Cybersecurity is no longer a luxury but a necessity. With the arrival of NIS 2, all companies, including SMEs, will need to demonstrate their digital maturity. The Cyberscore provides a concrete first step: assess your level, address vulnerabilities, and demonstrate your progress. More than just a diagnostic tool, it represents an educational and progressive approach that fosters a genuine culture of resilience and trust.

