Incident Reporting — operationalised.
From first signal to regulator notification, without the scramble.
Operational frameworks aligned to NIS2 Article 23 and DORA Article 19 — triage, notification and post-incident review.
Incident reporting under European law is no longer a single email to a national CSIRT. Operators face overlapping obligations under NIS2, DORA, GDPR, eIDAS2 and sector-specific regimes — each with its own thresholds, recipients and clocks. Our incident reporting service collapses these obligations into a single, rehearsed workflow so the on-call analyst is never asking 'who do we tell, and by when?' at 3am.
Open Incident Reporting on ENISA- NIS2 Article 23
- 24h early warning · 72h notification · 1-month final
- DORA Article 19
- Initial · intermediate · final reports to competent authority
- GDPR Article 33
- 72h notification of personal data breaches to DPA
- eIDAS Article 19
- Trust service provider breach notification without undue delay
What this framework covers
Significance thresholds
Not every incident triggers a regulator notification. NIS2 deems an incident significant if it has caused or is capable of causing severe operational disruption or financial loss, or has affected other natural or legal persons by causing considerable material or non-material damage. We codify these thresholds into objective severity matrices clients can apply consistently.
The three-step NIS2 cadence
Article 23 introduces a tightly choreographed three-step notification flow that the on-call team must execute under pressure.
- ›T+24h — Early warning: indication of suspected malicious cause and any cross-border impact
- ›T+72h — Incident notification: initial assessment, severity, impact and indicators of compromise
- ›On request — Intermediate status update at any point
- ›T+1 month — Final report: root cause, mitigations applied and cross-border effects
- ›If incident ongoing at 1 month — Progress report, then final report when handled
Multi-regulator deconfliction
A single ransomware event in a hospital can simultaneously trigger NIS2 (essential entity), GDPR (personal data), eIDAS2 (if trust services impacted) and national health-sector notifications. Our playbooks include a deconfliction matrix that fires the right notifications to the right recipients without duplication or omission.
Post-incident review loop
Every notified incident produces lessons learned that flow back into detections, controls and the next tabletop exercise — closing the loop between SOC, GRC and engineering.
Incident reporting service components
- Significance threshold matrix tailored to your sector and entity classification
- Pre-written templates for early warning, incident and final reports
- Multi-regulator deconfliction playbook (NIS2, DORA, GDPR, eIDAS2, sectoral)
- On-call incident commander training and tabletop rehearsals
- Direct lines into our 24/7 SOC for triage and forensic support
- Post-incident review facilitation and lessons-learned tracking