Best Open-Source Cybersecurity Tools for 2026: What We Use
A practical 2026 guide to Wazuh, MISP, MONARC, Arkime, Suricata and Greenbone/OpenVAS: where each tool fits, what it does not replace and what operating it really requires.
When businesses first migrated workloads to the cloud, the dominant questions were technical: performance, availability, cost, and integration. Compliance was a secondary concern, addressed after the architecture was chosen. That era is over.
In 2026, a business decision to store data with a particular cloud provider is simultaneously a technology decision, a legal decision, a regulatory compliance decision, and — for larger organisations — potentially a strategic geopolitical decision. The European Union has spent the past four years constructing a regulatory framework that governs not just how data is protected, but where it sits, who can access it, under whose jurisdiction it falls, and what happens when a government — any government — demands it.
For Luxembourg businesses, this shift is not abstract. Two of the four winning consortia in the European Commission's €180 million sovereign cloud contract (awarded April 2026) include Luxembourg-based provider participation. The CNPD continues to enforce GDPR against businesses that treat data transfers as purely technical matters. And the financial sector — disproportionately represented in Luxembourg's economy — faces DORA requirements that treat cloud vendors as critical ICT third parties subject to structured governance.
The question is no longer "which cloud is cheapest and fastest?" It is "which cloud is legal, secure, and defensible under the regulatory frameworks that govern my business?"
The EU Data Act entered into force in January 2024, but its core provisions became applicable on 12 September 2025. If your organisation uses cloud services — and Eurostat data shows that 52.74% of EU enterprises with ten or more employees now do, up from 45% in 2023 — these rules apply to you.
The Data Act's most immediate impact on cloud users is the set of obligations it places on cloud service providers around switching and interoperability. Providers are now legally required to remove commercial, technical, contractual, and organisational obstacles that prevent customers from switching to an alternative provider.
The practical consequences are significant. Cloud providers must allow customers to migrate their data and workloads to a competing provider within 30 calendar days — extendable to a maximum of seven months only where technically justified. Switching charges were permitted at direct-cost-only levels until January 2027, after which switching must be free of charge. Providers must maintain an online register documenting data structures, formats, standards, and interoperability specifications.
For SaaS and PaaS providers, the obligations go further: interfaces must be opened free of charge to both the customer and to incoming providers, enabling seamless functional transitions. The concept of "functional equivalence" now governs what a reasonable cloud migration should look like, replacing the era of deliberate lock-in as a business model.
The Data Act creates a right to exit that many existing cloud contracts were explicitly designed to obstruct. If your current cloud agreements were signed before September 2025, they may contain clauses that are now unenforceable — or that your provider is now legally required to waive. This is an active reason to review existing contracts with legal counsel familiar with the Data Act.
It is also a reason to be more careful about new cloud commitments. Agreements that include egress charges above direct cost, proprietary data format lock-in, or switching barriers inconsistent with Data Act requirements may now be challengeable. Understanding these rights before you sign is considerably cheaper than asserting them after the fact.
The cumulative total of GDPR fines issued since May 2018 has crossed €7.1 billion. In 2025 alone, regulators issued €1.2 billion in fines — and between January 2023 and March 2026, more fines were issued than in the preceding five years combined. This is not a trickle of enforcement against edge cases; it is systematic, accelerating, and reaching into every sector.
The landmark enforcement actions of the past eighteen months illustrate both the scale and the specific patterns of risk:
The Ireland-based enforcement totals are worth noting: the Irish DPC has issued €4.04 billion in cumulative fines, reflecting its role as lead supervisory authority for the EU operations of most major technology companies. France's CNIL, now the second-largest enforcer with over €1 billion in cumulative fines, has focused on cookie consent and advertising technology. Both trajectories are relevant to Luxembourg businesses that use or operate European digital services.
The largest fines consistently involve Article 46 GDPR violations: transfers of personal data outside the EU without adequate safeguards. The TikTok (€530M) and Uber (€290M, August 2024) cases are representative of a pattern where organisations transfer data to non-EU jurisdictions under legal mechanisms that have subsequently been found inadequate or improperly implemented.
For Luxembourg businesses using US cloud providers, this pattern is directly relevant. The legal mechanisms currently available for EU-US data transfers are more robust than they were under Privacy Shield — but they are not permanent, and they are under active legal challenge.
The EU-US Data Privacy Framework (DPF) was adopted in 2023 as the successor to Privacy Shield, which was invalidated by the CJEU in the Schrems II ruling of 2020. The DPF introduced a Data Protection Review Court (DPRC) as the mechanism for European individuals to seek redress for US intelligence collection affecting their data.
On 3 September 2025, the EU General Court dismissed the first challenge to the DPF — a case brought by French MP Philippe Latombe — finding that the DPRC meets independence standards and that its decisions are binding and final. This ruling maintained the DPF's legal basis and, for now, the legal channels for EU-US data transfers it enables.
However, the word "now" carries significant weight. Three developments create ongoing uncertainty:
For any Luxembourg business whose cloud architecture depends on transfers of personal data to US-based infrastructure — whether directly or through US-headquartered cloud providers serving from European data centres — the DPF situation warrants monitoring and contingency planning, not comfortable assumption of stability.
In October 2025, the European Commission published a Cloud Sovereignty Framework that established a structured system for assessing the sovereignty of cloud services used in public procurement. This framework — while designed primarily for public sector procurement — is increasingly used by regulated private sector organisations as a reference model for their own cloud governance decisions.
The framework defines five Sovereignty Effectiveness Assurance Levels (SEAL):
| SEAL Level | Description | Key Characteristic |
|---|---|---|
| SEAL-0 | No Sovereignty | Entirely under non-EU legal jurisdiction; automatically excluded from EU tender eligibility |
| SEAL-1 | Jurisdictional Sovereignty | EU law formally applies but limited enforceability; operational control remains with non-EU parties |
| SEAL-2 | Data Sovereignty | EU law applicable and enforceable; minimum threshold for EU Commission procurement |
| SEAL-3 | Operational Sovereignty | Full EU operational control with supply chain transparency |
| SEAL-4 | Complete Sovereignty | Full EU supply chain from hardware to software; no non-EU dependencies |
The practical significance for private sector organisations is this: if your organisation works with EU public sector clients, handles data subject to public procurement conditions, or operates in a regulated sector where supervisory authorities reference the SEAL framework in their guidance, understanding where your cloud infrastructure sits on this scale is becoming a compliance expectation rather than an optional analysis.
In April 2026, the European Commission awarded a €180 million, six-year sovereign cloud framework contract to four European provider consortia. The winners — OVHcloud/CleverCloud (led by Post Telecom Luxembourg), StackIT, Scaleway, and a Proximus-led consortium — were selected specifically because they meet sovereignty requirements that US hyperscalers cannot satisfy as primary operators under the framework's criteria.
US hyperscalers are not categorically excluded from all EU cloud use. However, they cannot qualify as primary operators in the highest sovereignty tiers: their infrastructure can be incorporated if a European entity controls the operational layer, but the control structure must be demonstrably European. AWS's €7.8 billion European Sovereign Cloud announcement (targeting Germany in late 2025) and Microsoft's Sovereign Private Cloud deployments in France and Germany represent the industry's response — but these remain works in progress, and their compliance with the highest SEAL levels remains unresolved.
For Luxembourg businesses, the participation of Post Telecom Luxembourg in the winning consortium is directly relevant: it demonstrates that sovereign cloud capability meeting EU Commission requirements is available within Luxembourg's own provider ecosystem.
The convergence of the EU Data Act, GDPR enforcement trends, DPF instability, and the Cloud Sovereignty Framework creates a clear direction for cloud strategy — even if the specific compliance requirements vary by sector, data type, and business model. The common thread is that cloud architecture decisions now have regulatory consequences that must be assessed before deployment, not discovered after an enforcement action.
Regardless of sector or size, every Luxembourg business using cloud services should complete the following:
Organisations subject to DORA — banks, investment firms, insurance companies, payment institutions, and other financial entities regulated by the CSSF — face an additional dimension. DORA classifies cloud providers as ICT third-party service providers and requires that:
The CSSF has been clear in its supervisory expectations: existing cloud contracts that predate DORA must be brought into compliance. Organisations that have not completed this remediation are operating with regulatory risk that is readily identifiable in a supervisory review.
Beyond compliance minimum requirements, the strategic question many Luxembourg organisations are now facing is whether to repatriate sensitive workloads to EU-sovereign infrastructure — and if so, which. This is not a simple question. Sovereign cloud providers typically offer a narrower service catalogue, higher unit costs, and less mature developer tooling than the major US hyperscalers. These are real trade-offs that must be weighed against the compliance and geopolitical risk reduction that sovereignty provides.
The emerging pattern among more mature organisations is a workload-segmented approach:
This hybrid architecture reflects the reality that full data sovereignty at SEAL-4 is not a practical or cost-justified outcome for most private sector organisations — but that leaving sensitive and regulated data in infrastructure that cannot satisfy SEAL-2 requirements is increasingly difficult to defend.
Operating in Luxembourg creates specific context that shapes the cloud sovereignty question in ways that generic European guidance does not fully capture.
CNPD oversight and enforcement trajectory. The CNPD — Luxembourg's data protection authority — operates within the framework of the Amazon €746 million case now under reassessment, which has required the regulator to re-examine its enforcement methodology. Luxembourg's position as a hub for EU operations of major technology companies means the CNPD will continue to be a significant enforcement actor, and businesses registered in Luxembourg are subject to its direct supervision regardless of where their data processing occurs.
Financial sector concentration. Luxembourg hosts a disproportionate share of European fund administration, banking infrastructure, and payment processing. The CSSF's supervisory expectations for cloud use by regulated entities reflect the systemic importance of these functions: they are more stringent than what NIS2 requires of general commercial entities, and they are actively enforced through supervisory review cycles.
ILR oversight and communication infrastructure. Telecommunications and communication services providers operating in Luxembourg are subject to ILR oversight. Cloud infrastructure that integrates with regulated communication services carries additional compliance dimensions that are sector-specific to Luxembourg's regulatory landscape.
Luxembourg as a Sovereign Cloud Hub. The Post Telecom Luxembourg participation in the April 2026 EU Commission sovereign cloud contract is a signal about Luxembourg's emerging position. As the EU continues to invest in sovereign cloud infrastructure for sensitive public sector use, Luxembourg's established data centre industry, regulatory environment, and geographic position within the EU make it a natural host for sovereign cloud capacity serving European institutions.
The EU's Gaia-X initiative — which aims to create a federated European data infrastructure based on common standards and trust frameworks — released its Trust Framework 3.0 in November 2025. Gaia-X is not a cloud provider; it is a standards and governance framework within which compliant providers and data spaces can be certified.
The most mature Gaia-X implementation to date is Catena-X in the automotive supply chain, with additional active implementations in construction (iECO), education (MERLOT), and mobility (Gaia-X4KI). For Luxembourg logistics companies — a significant sector in the national economy — Gaia-X-aligned data space participation is becoming a topic of active discussion as customers in automotive and transport ask their logistics partners about data sovereignty and interoperability compliance.
Gaia-X is not yet a mature, ubiquitous standard. But it is the direction in which EU-regulated data sharing is moving, and organisations in industries where Gaia-X data spaces are developing should understand what participation means and what it requires from their IT architecture.
Cloud data sovereignty is a complex topic, but the immediate priorities for most Luxembourg businesses are straightforward:
Cloud data sovereignty spans technology architecture, legal compliance, regulatory affairs, and strategic planning — four disciplines that rarely sit in a single team. The organisations navigating it most effectively are those that treat it as an integrated programme rather than dividing it between IT (who manages the infrastructure), legal (who reviews the contracts), and compliance (who tracks the regulations), with each silo working from incomplete information.
At ObsidianCorps, we work with Luxembourg and Greater Region businesses to make sense of exactly this intersection: helping organisations understand their current cloud exposure, map it against applicable regulatory requirements, evaluate sovereign cloud options appropriate to their sector and risk profile, and build the governance frameworks that make their cloud strategy defensible under CSSF, CNPD, and European Commission scrutiny.
If you are navigating a cloud architecture review, a DORA ICT third-party risk assessment, or a sovereign cloud evaluation — or if you simply want to understand whether your current cloud setup is compliant with the rules that came into force in September 2025 — we would welcome the conversation.
Technology Lead at ObsidianCorps
A practical 2026 guide to Wazuh, MISP, MONARC, Arkime, Suricata and Greenbone/OpenVAS: where each tool fits, what it does not replace and what operating it really requires.
Updated for Luxembourg’s May 2026 NIS 2 Act: understand scope, the ILR registration requirement, incident timelines, the four new evidence templates and practical implementation priorities.
Luxembourg organisations face NIS2 implementation, active DORA supervision and the EU AI Act’s staged 2026–2028 timeline at once. Here is how to prioritise the overlapping controls without duplicating work.
At Obsidiancorps, we fuse innovative technology with trusted security practices to create tailored solutions that protect and elevate your business. Reach out and let's secure a brighter future together.
Differdange, Luxembourg
We typically respond within 24 hours
We'd love to hear from you! Fill out the form below and our team will get back to you as soon as possible.