Luxembourg is celebrating 10 years of participation in the InCyber Forum (FIC) this year, further strengthening its expertise in cybersecurity under the aegis of the Luxembourg House of Cybersecurity (LHC).
In this series of interviews, we highlight the companies and institutions representing Luxembourg at the event in early April. Here, Claudio Orlando Miele, Manager Cybersecurity & Data Protection – DPO of the Year 2024 – at Forvis Mazars, shares his insights on the evolving cybersecurity landscape, key challenges for 2025, and how Luxembourg is reinforcing its commitment to data protection and innovation.
What are your company’s main news and innovations in cybersecurity for 2025?
As we navigate the Fourth Industrial Revolution, the rapid pace of technological innovation is unlocking new possibilities while presenting unprecedented challenges. As an advisory and audit firm, we are observing renewed attention from clients on cybersecurity and data protection compliance, driven by the rapid pace of digital transformation and the growing complexity of the interconnected regulatory landscape.
In response, at Forvis Mazars Luxembourg, we are helping clients navigate the intricate relationships between key regulatory frameworks such as DORA, AI Act, NIS2, GDPR, ePrivacy, and the broader EU digital regulations package (including the Data Act, Data Governance Act, Digital Market Act, and Digital Service Act). Our primary focus is on developing an integrated approach that identifies and leverages the points of convergence across these frameworks.
Our goal is to guide organizations in adopting a unified strategy that streamlines processes, reduces risk and operational complexity, simplifies compliance, and builds resilience. This comprehensive approach not only strengthens both cybersecurity and data privacy capabilities but also fosters trust in an increasingly data-driven world.
What do you think are the major cybersecurity challenges in 2025, and how is your company responding to them?
Technology transformation is a top priority for business leaders, but expanding digital supply chains and global operations heighten cyber risks. Regulation further complicates the matter; as requirements vary from country to country, they can also exacerbate the tendency to take a compliance-based approach as opposed to a true risk-based approach.
So, how can ambitious businesses balance digital transformation with cyber security and data protection?
It may seem easiest to start by assessing the current tech surface, but with digital supply chains changing daily, a point-in-time security and data protection review quickly becomes outdated. Instead, we recommend adopting a risk-based approach:
- Map Core Business Functions: Identify critical business processes without focusing on suppliers. This highlights where sensitive data and key operations reside.
- Assess Risk and Impact: Pinpoint your “crown jewels”, you can start to quantify the impact of any of them being compromised to varying degrees.
- Know your cyber landscape and cyber threats: Go beyond compliance checklist by embedding cyber risk management into business decisions, leveraging global and local cyber expertise.
- Define Cyber Security Requirements: Use insights from the previous steps to create tailored policies that prioritize the protection of high-value assets.
This risk-based approach to cyber security means policies and requirements will be a true reflection of the business’s value and priorities, instead of trying to validate technologies according to an externally defined (and therefore somewhat arbitrary) standard.
Why did you choose to participate in FIC 2025, and what are your objectives for this event?
FIC 2025 presents a unique opportunity to exchange ideas on the latest trends, challenges, and solutions in cybersecurity and data protection with industry leaders, policymakers, and experts in the field. The event offers a platform to shape the future of the industry.
Our primary objective is to make a meaningful impact on society by contributing to a more informed and resilient digital ecosystem. By participating in FIC 2025, we aim to better understand market dynamics, and fully connect with emerging trends and needs. This will ensure that we provide actionable insights and deliver a truly meaningful impact to clients and society at large.
What does Luxembourg’s presence with a national pavilion at FIC 2025 represent, and how does this enhance the Luxembourg cyber ecosystem?
Luxembourg’s presence at FIC 2025 underscores the country’s commitment to being a leading force in the global cybersecurity and data protection landscape. It highlights Luxembourg’s growing role as a hub for innovation, supported by a dynamic regulatory environment, a skilled workforce, and the presence of top-tier cybersecurity and data protection firms.
This reinforces the country’s strategic importance within Europe’s digital economy, attracts further investment and talent into Luxembourg’s cybersecurity sector, and promotes collaboration among private enterprises, government bodies, and academic institutions.
This collaborative approach is essential for ensuring Luxembourg remains at the forefront of digital innovation, fostering trust among international clients, and reinforcing its reputation as a key player in global digital security.
What key advice would you give to companies, startups, and individuals to strengthen their cybersecurity in 2025?
In 2025, companies must embed cybersecurity and data protection into digital products and services from the outset—shifting from reactive compliance to proactive security by design. This strategic approach integrates security and privacy as core components of business operations, fostering a culture of data governance and accountability at all levels of the organization.
Data governance serves as the foundation of all cybersecurity and privacy practices, requiring organizations to establish clear policies, processes, and frameworks to manage, protect, and oversee data throughout its entire lifecycle. In an increasingly interconnected world—where data is both a critical asset and a potential liability—maintaining end-to-end control over this valuable resource has never been more essential.
Beyond mitigating risks, adopting a data governance by design helps secure long-term business sustainability in a landscape where data protection and cybersecurity are key to maintaining competitive edge and stakeholder confidence.