The reporting duty rarely tests the knowledge of an organisation. It tests its preparation. Once the alert is confirmed, the question is not whether someone can draft a report, but whether it has already been settled who owns it, what information it has to contain and how the portal is reached. If that is not settled, the first hour goes on sorting out the organisation rather than the incident.
The chapter follows the incident lifecycle through four phases. Preparation, the phase where almost the whole outcome is decided and which therefore gets the most space. Roles, decision paths, contact lists and the basic question of who has the mandate to shut down a system. Detection and analysis, the road from alert to confirmed picture, and the difficult classification question of whether the incident is reportable at all. Containment, investigation and remediation, where the chapter deals with the trade off between stopping the attack quickly and preserving the traces later needed to understand what happened. And lessons learned and improvement, which closes the circle and is the phase most often skipped when everyone is tired. After that comes the multiple reporting duty, the awkward case where the Cybersecurity Act, GDPR and possibly a sector regulation all require a report, with different recipients and different deadlines. One section deals with exercise as the road from plan to capability, and another with how smaller organisations solve this without staff of their own. The ability to detect is covered in chapter 16 on SOC and IRT.
Why now is uncomplicated. The reporting duty has applied since the law entered into force on 15 January 2026, and the deadlines are short enough that the preparation has to be done beforehand. The clock also starts on becoming aware of the incident, not when the investigation is complete, which means the first report is written on incomplete information. That makes preparation the only phase you can shape in peace.
This page shows what the chapter covers and why preparation carries the most weight. The phases in detail, the report content and the exercise design are in chapter 17 of the book.
An incident is not a failure. Not learning from it is.
Key insights
- The preparation phase decides the outcome. What is not settled in advance gets improvised under pressure.
- The clock starts on becoming aware of the incident, not when the investigation is done. Early warning rests on incomplete information.
- One incident can trigger reporting duties under several sets of rules at once, with different recipients and different deadlines.
- The lessons learned phase is the one most often skipped and the one that delivers the most value.
- A plan that has never been exercised is a hypothesis about how the organisation will behave.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Template collection
Report templates for early warning within 24 hours and the full report within 72.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.