Framework / IR

Incident Reporting — operationalised.

From first signal to regulator notification, without the scramble.

IR

Operational frameworks aligned to NIS2 Article 23 and DORA Article 19 — triage, notification and post-incident review.

Incident reporting under European law is no longer a single email to a national CSIRT. Operators face overlapping obligations under NIS2, DORA, GDPR, eIDAS2 and sector-specific regimes — each with its own thresholds, recipients and clocks. Our incident reporting service collapses these obligations into a single, rehearsed workflow so the on-call analyst is never asking 'who do we tell, and by when?' at 3am.

Open Incident Reporting on ENISA
/ KEY.FACTS
NIS2 Article 23
24h early warning · 72h notification · 1-month final
DORA Article 19
Initial · intermediate · final reports to competent authority
GDPR Article 33
72h notification of personal data breaches to DPA
eIDAS Article 19
Trust service provider breach notification without undue delay
/ GUIDANCE

What this framework covers

§ 01

Significance thresholds

Not every incident triggers a regulator notification. NIS2 deems an incident significant if it has caused or is capable of causing severe operational disruption or financial loss, or has affected other natural or legal persons by causing considerable material or non-material damage. We codify these thresholds into objective severity matrices clients can apply consistently.

§ 02

The three-step NIS2 cadence

Article 23 introduces a tightly choreographed three-step notification flow that the on-call team must execute under pressure.

  • T+24h — Early warning: indication of suspected malicious cause and any cross-border impact
  • T+72h — Incident notification: initial assessment, severity, impact and indicators of compromise
  • On request — Intermediate status update at any point
  • T+1 month — Final report: root cause, mitigations applied and cross-border effects
  • If incident ongoing at 1 month — Progress report, then final report when handled
§ 03

Multi-regulator deconfliction

A single ransomware event in a hospital can simultaneously trigger NIS2 (essential entity), GDPR (personal data), eIDAS2 (if trust services impacted) and national health-sector notifications. Our playbooks include a deconfliction matrix that fires the right notifications to the right recipients without duplication or omission.

§ 04

Post-incident review loop

Every notified incident produces lessons learned that flow back into detections, controls and the next tabletop exercise — closing the loop between SOC, GRC and engineering.

/ THECYBERCO.SERVICE

Incident reporting service components

  • Significance threshold matrix tailored to your sector and entity classification
  • Pre-written templates for early warning, incident and final reports
  • Multi-regulator deconfliction playbook (NIS2, DORA, GDPR, eIDAS2, sectoral)
  • On-call incident commander training and tabletop rehearsals
  • Direct lines into our 24/7 SOC for triage and forensic support
  • Post-incident review facilitation and lessons-learned tracking

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment