Thought leadership
The rapid proliferation of unmanned aerial systems (UAS) is introducing a new dimension to the security challenges faced by critical infrastructure operators. As drones become increasingly accessible, cost-effective and sophisticated, they can create vulnerabilities that conventional physical and cybersecurity measures may not fully address. Organisations therefore need to consider the airspace surrounding their assets as an additional layer of their security perimeter and evaluate how drone-related threats could affect operations, physical security and business continuity.
Managing these emerging risks requires more than deploying technologies designed to detect or counter drones. Organisations should adopt a comprehensive, risk-based approach that brings together threat and vulnerability assessments, protection of critical assets, surveillance and detection capabilities, as well as clearly defined response procedures. Resilience depends on being able to detect, analyse and assess potentially unauthorised drone activity quickly, while ensuring effective coordination with the relevant authorities and stakeholders when an incident occurs.
The regulatory environment also adds another layer of complexity. European frameworks, including the CER and NIS2 directives, are increasing expectations around resilience, risk management, preparedness and organisational accountability. At the same time, infrastructure operators may face uncertainty over the measures they can lawfully implement in response to a drone incident. Understanding the interaction between regulatory obligations, operational requirements, and available security capabilities is therefore becoming increasingly important.
As drone adoption continues to expand, stronger cooperation between public authorities and private-sector operators, clearly allocated responsibilities and greater regulatory alignment will become increasingly important. Organisations that assess their exposure to drone-related risks today and integrate C-UAS considerations into their broader resilience strategies will be better positioned to protect critical assets, maintain operations and safeguard the continuity of essential services.
Drone incidents are no longer confined to conflict zones. 2026 turned drone risk from a policy discussion into an operational question for organisations in Luxembourg.
The exposure is concentrated: an international airport and cargo hub, energy and transport networks, data centres and telecoms, EU institutions, financial market infrastructure and high-profile public events, all within a small, cross-border territory.
For a critical entity designated under the new CER law, drone scenarios belong in its resilience risk assessment from the start, not in a later update.
Key considerations for critical infrastructure operators include:
We connect four dimensions that are often handled separately: risk, regulation, operations and technology. Our Luxembourg regulatory and public sector teams work with PwC's European counter-drone and drone technology specialists.
The aim is not more technology. It is a proportionate capability that works in your operating environment and within Luxembourg's institutional set-up.
Philippe Pierre
Advisory Partner, Government & Public Services Leader, PwC Luxembourg
Tel: +352 49 48 48 4313
Daniela Cedola
Advisory Partner, Government & Public Services, EU institutions Leader, PwC Luxembourg
Tel: +352 62133 60 97
Andrea Lucchini
Advisory Director, Government & Public Services, PwC Luxembourg
Tel: +352 621 334 317
Thomas Wittische
Audit Managing Director, Risk Assurance, PwC Luxembourg
Tel: +352 621 334 181