Table of contents
About EBRC
European Business Reliance Centre
Founded in 2000, EBRC is a European Centre of Excellence and Trust in the management and protection of sensitive information.
EBRC has developed a unique value proposition for its clients and partners, focused on Trust and CyberResilience: EBRC-Trusted Services Europe.
To provide the highest security and quality of service, EBRC has certified its services end-to-end: ISO 27001 (information security), ISO 22301 (business continuity), ISO 20000 (IT service management), ISO 9001 (quality), PCI DSS level 1 (payment security). EBRC is compliant with financial sector regulations and holds “Professional of the Financial Sector” (PFS) accreditation.
From its three Tier IV certified Data Centres, EBRC operates its own sovereign European cloud EBRC Trusted Cloud Europe offering public, private and hybrid deployment models connected to 100 international destinations. EBRC provides the full range of ICT Managed Services via EBRC -Trusted Managed Services. In addition, EBRC has its EBRC-Trusted Advisory Services offering, which features advice in Risk Management, Cyber-Resilience, Cyber-Security, Certifications & Compliance to IT Transformation & Move to the Cloud.
EBRC and its subsidiary Digora employ over 340 experts and consultants based in Luxembourg, France, Belgium and Morocco.
With a strong historical presence in the international banking and financial sectors, as well as in the healthcare and international institutions markets, EBRC advises and serves clients in sensitive and critical areas such as e-commerce, manufacturing, pharma & biotech, the public sector, defence, space, energy, critical operators, large law firms, FinTechs & RegTechs, and start-ups.
TRUSTED ADVISORY SERVICES
Risk Management, Cyber-Resilience, Business Continuity, Cyber-Security, Crisis Management, Data Centre Advisory, IT Transformation, Cloud Readiness Assessments, Move to the Cloud, ISO certification support, GDPR, Compliance with regulations…
TRUSTED MANAGED SERVICES
24/7 Agile ICT Outsourcing Services, based on ITIL and international standards and best practices.
TRUSTED CLOUD EUROPE
Fully certified European sovereign Cloud Services, offering 3 deployment models: public, private or hybrid cloud, all operated from EBRC secured Tier IV-certified data centres, connected to 100 international destinations. EBRC is also a “Day-One member” of the Gaia-X initiative.
TRUSTED SECURITY EUROPE
Security Operations Services (SOC)
Computer Emergency Response Team (CERT) Ethical Hacking.
TRUSTED RESILIENCE SERVICES
Business Continuity & Recovery Services, Work Area Recovery (800 workstations on 2 distant interconnected Recovery Sites), Trading Rooms, Disaster Recovery as a Service (DRaaS), Trusted Backup & Recovery Services (TBRS), Cloud Recovery, Crisis Management.
TRUSTED DATA CENTRE SERVICES
High-availability Data Centre Services (3 Tier IV-certified Data Centres – 15,000 sqm of IT server space)
100% Green Energy – ESR Commitment - ISO 14001 & ISO 50001 Certifications
Largest neutral carrier hotel in Luxembourg offering large international connectivity European broadband connectivity (low latency rates to major European hubs)
Cyber-Resilience
Go beyond Cyber-Security with holistic approaches and solutions designed for each business
About our strategy
Since our creation in 2000, EBRC has given businesses the confidence to grow. We improve their performance in the digital world while guaranteeing the security and resilience of their data and activities.
Because EBRC supports and manages clients with sensitive needs, Cyber-Resilience has become vital and mandatory.
To achieve this goal, EBRC has adopted a range of best practices in terms of standards for our own infrastructure and IT services. This includes security of information (ISO 27001) and business continuity (ISO 22301) standards. It also holds the highest certifications for industries, including PCI DSS for payment. Moreover, since 2004, EBRC has been holding the “Professional of the Financial Sector” status regulated by the Commission de Surveillance du Secteur Financier (CSSF). This status offers highlevel guarantees for clients in terms of financial stability, governance, quality and security.
EBRC offers its clients a full chain of integrated and certified end-to-end services: Trusted Services Europe, from advisory services with its Trusted Advisory Services to operations (Trusted Managed Services). EBRC supports its clients to align them with best practices, both in data protection and in the management of critical operations.
About our approach
We have based our C Cyber-Resilience approach is based on a full lifecycle of continuous improvement:
• PREPARE: Analyse your risks, define your critical functions, analyse your impacts, define your resilience strategy.
• IDENTIFY: Evaluate your vulnerabilities, analyse and test the strengths and weaknesses of your organisation and your infrastructure.
• PROTECT: Mitigate risks, define counter measures. Improve your ITIL processes maturity and security, and opt for high availability architecture with Tier IV certified Data Centres
• DETECT: Identify cyber-threats and breaches, detect cyber-attacks with tailor-made processes and tools (log correlation, real-time alerts). Ensure fast and efficient security management.
• ANALYSE: Analyse threats, prioritise your action and set up operational crisis management.
• RESPOND: Manage crises, and take the required measures to face the threats. Plan optimal crisis communication. Ensure short-term reparation and correction, while establishing your mid-term corrective strategy.
• RECOVER: Manage activity recovery and your return to normal. Gather evidence (forensics), and learn lessons. Strengthen your counter-measures to better face risks. Improve your Cyber-Resilience.
Our added value
Our consultants are experienced and certified in risk management, resilience organisation, information security management, audits, data analysis and forensics investigations, cloud architecture and security, support in ISO 22301 and ISO 27001 certification programmes, etc
Our international certifications, including ISO 27001, ISO 22301, PCI DSS certifications and Tier IV certified Data Centres, are key guarantees for the successful operation of critical infrastructures and applications, as well as for the reduction of the risk exposure, particularly in sensitive sectors.
We deliver our services to over 400 international clients from sectors as diverse as Finance, FinTech & RegTech, Health & Life Sciences, International Institutions, Defence-Space-Security, Online Services and Operators of Essential Services. Relying on our Trusted Services Europe portfolio, and a team of 340 experts based in Luxembourg and France, we provide support throughout the entire data protection value chain with risk management, business continuity, 24/7 management, protection and security of sensitive data, advisory services, compliance, alignment with best practices and international certifications (ISO 22301, ISO 27001, ISO 20000, PCI DSS, Tier IV, etc.).
Tailor-made expertise that meets your
Finance, FinTechs and RegTechs:
• Specialised client experience (more than 60% of the banks in Luxembourg use our services)
• 40+ FinTechs use our services on a daily basis
• Our employees have experience in the financial sector, including working in the local regulatory environment
Health & Life Sciences:
Public sector & International institutions:
• Expertise with projects such as the implementation of the Luxembourgish shared care record system run by Agence eSanté and the Integrated BioBank of Luxembourg (IBBL)
• We have key certifications that facilitate the protection and management of sensitive medical data
• Experience in serving the largest EU institutions / agencies
• NATO certifications which are renewed regularly
• Experience in a large ICT ecosystem (EBRC is 100% owned by a public investor that generates over €860M turnover)
business needs:
business based on:
Security, defence and space:
• Our services and data centres are certified by international standards such as ISO 27001 and ISO 22301 or Tier IV. All our certifications are renewed on a yearly basis.
• NATO accreditation and clearance for our critical staff
• Expertise gained from critical industries (financial and health sectors as well as Operators of Essential Services)
Media & online services:
Operator of Essential Services:
• Expertise in providing high availability
• Zero downtime in the operations and management of our 3 highly available Tier IV Data Centres since 2000
• Building agile cloud computing solutions and services (Hybrid Cloud, DevOps based on Kubernetes and RedHat Openshift)
• Know-how in resilient IT services and infrastructures since 2000
• An entire certified value chain for our services: Advise, Design, Build, Operate, Maintain
• Support of our Advisory team, which helps you achieve ISO 27001 and ISO 22301 certification. EBRC also holds these standards since we practice what we preach
Certifications
The ISO 27001 standard defines the requirements for the design, implementation and continuous improvement of an Information Security Management System (ISMS). The ISMS refers to the systemic approach by which an organization needs to ensure the security of its sensitive information (people, processes, IT systems). It identifies this information, guaranteeing its availability, integrity and confidentiality, but also protects IT systems from intrusion and IT disaster.
ISO 22301 is the international standard for the management of business continuity. It has been designed to protect activities from potential disruptions such as: extreme weather conditions, fires, natural disasters, theft, computer failures or even terrorist attacks. The ISO 22301 management system allows the identification of threats related to the activities of an organization, as well as the functions likely to be affected. It also permits the establishment of crisis management and disaster recovery plans.
ISO 20000 is a Service Management System (SMS) standard targeted at IT services driven by business objectives without being limited only to technological requirements. It lists what must be provided by the service provider to enable them to plan, implement, execute, monitor, review, maintain and improve an SMS: design, delivery and improvement of services.
EBRC carries out a yearly PCI DSS assessment with a Qualified Security Assessor (QSA). The auditor controls EBRC’s environment which includes the validation of the infrastructure, the development, the operations, the management, the support and the services that are within scope. EBRC is certified and meets the standards of the PCI DSS version 3.2.1, Level 1 service provider.
This certification, granted by the Uptime Institute, ensures a Data Centre offers the highest level of guarantee, that is, an availability rate approaching 100%. By auditing the building schemes and drawings, visiting the site and carrying out testing, the impartial third party has guaranteed that EBRC’s Data Centres meet the certification standards and is thus able to face the worst incident scenarios: design, construction, operations, etc. In addition, Tier IV criteria are based on the ability to detect and isolate a failure in the critical systems while maintaining the load, and without impacting the power supply and the cooling process
ISO 14001
Trusted
The confidential data you manage at risk due to the growing threat of cyber-crime.
EBRC’s strategy has twin aims in this increasingly complex, cyber-dependent world: protecting your sensitive information and critical applications, while developing your Cyber-Resilience.
With over two decades experience in managing highly sensitive data for governments and institutions - including defence departments - we have our clients benefit from our know-how of managing critical infrastructures and processes
Our team of experienced consultants is skilled in leading IT Risk Assessments, Business Impact Analysis (BIA), Cloud Readiness Assessments, IT Transformation projects, and more, all aligned with international methodologies enshrined in standards such as ISO 27001 and ISO 22301.
Through EBRC’s Managed Services & Outsourcing offering,
benefit from our advanced expertise in Information System Management, the management of sensitive transactions and highly available IT infrastructures.
24/7 IT
Management is founded on secure, certified components: Tier IV Data Centres, and IT methodologies and processes which are ISO 27001, ISO 20000 and ISO 22301 certified to ensure resilience and business continuity
Trusted Cloud Europe
Cloud computing services meeting the standards of the sovereign Cloud
Trusted Cloud Europe is a service managed and maintained by the IT service provider EBRC. Launched in 2010, EBRC’ s Trusted Cloud Europe has been designed to comply with ISO 27001 certification and PFS regulation. It offers the agility and mobility you need to grow your business. This includes DevOps services based on Kubernetes as a Service, and RedHat OpenShift containerisation technologies.
As a pioneer of the Trusted Cloud, it is only natural that EBRC is a "Day-One Member" of the GAIA-X initiative.
Our secure-by-design Cloud infrastructure relies on a cluster of two fault-tolerant certified Tier IV Data Centres located in Luxembourg. EBRC is certified ISO 20000 for IT service management, and ISO 22301 for business continuity management
With our Trusted Cloud Europe service, you access a regulated and secure Cloud computing solution, and a range of cloud deployment models: public, private and hybrid. It offers secure access to more than 100 Cloud destinations!
Trusted Security Europe
The increasing prevalence and sophistication of threats online have made Cyber-Security a vital concern for your organisation.
Thanks to our expertise built over two decades protecting and managing highly sensitive data for public and private entities, we meet the most stringent requirements.
Our substantial know-how in Cyber-Security for the defence sector resides in our skilled, certified internal team of consultants, and also in the support from Post Group: Cyberforce. This expertise is applied to the entire security process. IT Risk Analysis is about identifying vulnerabilities and preparing appropriately. Then when an attack is underway, Cyber-Incident Response is about protection, detection, analysis, response and recovery, underthe supervision of our Security Operations Centre (SOC).
Trusted Resilience Services
Ensure your Business Continuity with an accredited partner
Since 2000 EBRC has been managing Business Continuity services, delivered through an end-to-end offering of Advisory services, backup capability and recovery solutions. These are supported by three Tier IV certified Data Centres and two recovery sites offering 800 fully equipped workstations, all based in Luxembourg, which allow disaster recovery for your business and your employees in less than two hours.
Thanks to EBRC’s ISO 22301 certfication, we put this expertise in security, resilience and Business Continuity Management at your service Our consultants can support your business in its ISO 22301 certification process and support you in conducting your Business Impact Analysis, Business Continuity Plan and IT Disaster Recovery Plan
Besides, we developed EBRC Cyber-Resilience Portal, which allows the centralization of your Business Continuity Management System by supplying an overview of the whole strategic decisions.
In case of a disaster, we guarantee that your data will be available and that you will have access to our recovery sites in less than two hours. EBRC has dedicated or mutualised workplaces in two different locations and does not apply a “first in, first served” policy.
Trusted Data centre Services
Meet the highest data protection challenges with Tier IV Data centres
Criminal organisations have never been more attuned to the value of data. Data Centres are the first link in the information transmission chain, and EBRC ensures the highest standards.
Since we were founded in 2000, we have worked with international organisations which rely on us to ensure business resilience and data protection.
When using our Tier IV Data Centres and our trusted services with ISO 27001 and ISO 22301 certification, you choose the best IT storage and processing environment in Europe for your critical information.
EBRC has broad know-how of designing tailor-made Data Centre services for our demanding clients. One of our three Tier IV Data Centres is located close to the largest European satellite company. This facilitates access to a range of space-related services: Earth observation, telecommunications, IoT satellite networks, and more
Video: our clients testimonials
IBBL
Dominic Allen, COO of the IBBL (Integrated Biobank of Luxembourg) describes the Biobank’s mission and explains the reasons he selected EBRC for this project ISO 27001 certified, EBRC meets the required security levels needed to manage sensitive information such as medical data.
ln the digital world, our role is to support our clients: on the one hand, we must offer them agility so that they can accelerate and innovate in their core business; on the other hand, we must protect them and reduce uncertainty as well as increasing complexity. Our objective is to support them with confidence in cyberspace, offering them both agility and protection.
Agence e-Santé
Hervé Barge, CEO of the Agence e-Santé, outlines the challenge faced by the Agency in setting up a national health platform with, in particular, the establishment of shared medical files. The hosting and management of highly sensitive health data (as well as the ability to meet the 9month deadline for the implementation of the infrastructure), were key factors in the decision to work with EBRC. Trust, respect for commitments and professionalism are the defining characteristics of the relationship between the two companies.
We asked six of our clients to talk about their collaboration with EBRC. ln this series of short videos, they reflect on the partnership with our teams and the support they received throughout their project.
LuxTrust
Stefano Susca, Director of Information Systems at LuxTrust, shares his experience of working with EBRC for the migration of its data centres and the operation of critical infrastructures requiring a 24/7 availability He explains the reasons why Luxtrust chose EBRC services, which are based on numerous certifications including Tier IV, ISO 27001 and the PFS status. He also provides his assessment of the relationship between Luxtrust and EBRC teams in a project lasting more than 12 months.
Banque de Patrimoines Privés
Carlos F. Rubies, Josep-Arseni Ramoneda and François Clausse of the Banque de Patrimoines Privés discuss the support received from EBRC teams as part of their ISO 22301 certification process. Benefitting from end-to-end support from a market leader, the Banque de Patrimoines Privés appreciated the professionalism of EBRC teams and their willingness to work to understand their needs throughout the partnership.
i-Hub
Abdelha Tayeb, Head of Cyber Security at i-Hub, discusses the substantial requirements involved in operating the technologies of this support PSF delivering AML/KYC services. The criteria taken into account when selecting EBRC were numerous: being able to operate the latest generation technologies and monitor them 24/7, being able to integrate with the i-Hub security operations centre, and delivering advice, particularly in terms of continuity plans, governance and international standards. EBRC expertise in cyber-security was instrumental to ensuring the highest levels of protection throughout the service production chain.
Quintet (formerly KBL)
Eric Mansuy, Group Chief Operating Officer at Quintet discusses the project of migrating the bank’s data centre into EBRC’s infrastructures. This went in parallel with the replacement of the group’s core banking platform. The decision to work with EBRC teams was based on criteria including security, the relationship between the teams and the consistency of the approach. Crucially, the project was completed on schedule.
Flash the QR codes to view the testimonials.
An overview of our Awards
TNT Symposium - Techsense TechForLife Prize 2021
IT One Awards
ICT Outsourcing Services Provider of the Year 2020
ICT Business Partner of the Year 2019 Cloud Innovation Provider of the Year 2019 Managed Services Provider of the Year 2014, 2016, 2017, 2018 Cloud Provider of the Year 2014, 2015, 2016
IS DAYS Award
Best IT Security Partner of the Year 2017
Data Cloud Europe Awards (BroadGroup - Europe)
E Excellence in Regional Cloud Europe Award 2022 Excellence in Data Centre Europe Award 2021 Excellence in Cloud Service Award with local impact 2018 Cloud Service Provider Europe Best Regional Data Centre Europe 2015
EuroCloud Europe Awards
Best Cloud Transformation Methods 2015, 2016 Best Use Case of Cloud Services for the Public Sector, France 2011
European Commission Awards
European Code of Conduct for Data Centres Awards 2011, 2016
Trophées de la Transformation Numérique
Prix e-Santé with B Medical Systems 2022
Prix Open Banking with LUXHUB 2020 Prix éthique with the project We are not Weapons of War 2018 Prix finance with PayBoost by Veolia Eau 2016
Find out more on ebrc.com
Rise to the challenge of Cyber-Resilience
EBRC has been managing and protecting your sensitive information for 20 years, and is now ready to help you meet the Cyber-Resilience challenge with complete peace of mind.