Part III · Chapter 17

Incident response and reporting

Incident reporting under the Cybersecurity Act follows a clock that starts running before anyone has grasped what is happening. Early warning within 24 hours, a full report within 72. This chapter works through the four phases of incident response, from preparation to lessons learned, deals with the case where several sets of rules demand a report at once, and shows why exercise is what decides the outcome.

  • CISOs and security leads
  • Boards and leadership teams

Last reviewed

The reporting duty rarely tests the knowledge of an organisation. It tests its preparation. Once the alert is confirmed, the question is not whether someone can draft a report, but whether it has already been settled who owns it, what information it has to contain and how the portal is reached. If that is not settled, the first hour goes on sorting out the organisation rather than the incident.

The chapter follows the incident lifecycle through four phases. Preparation, the phase where almost the whole outcome is decided and which therefore gets the most space. Roles, decision paths, contact lists and the basic question of who has the mandate to shut down a system. Detection and analysis, the road from alert to confirmed picture, and the difficult classification question of whether the incident is reportable at all. Containment, investigation and remediation, where the chapter deals with the trade off between stopping the attack quickly and preserving the traces later needed to understand what happened. And lessons learned and improvement, which closes the circle and is the phase most often skipped when everyone is tired. After that comes the multiple reporting duty, the awkward case where the Cybersecurity Act, GDPR and possibly a sector regulation all require a report, with different recipients and different deadlines. One section deals with exercise as the road from plan to capability, and another with how smaller organisations solve this without staff of their own. The ability to detect is covered in chapter 16 on SOC and IRT.

Why now is uncomplicated. The reporting duty has applied since the law entered into force on 15 January 2026, and the deadlines are short enough that the preparation has to be done beforehand. The clock also starts on becoming aware of the incident, not when the investigation is complete, which means the first report is written on incomplete information. That makes preparation the only phase you can shape in peace.

This page shows what the chapter covers and why preparation carries the most weight. The phases in detail, the report content and the exercise design are in chapter 17 of the book.

An incident is not a failure. Not learning from it is.

Key insights

  • The preparation phase decides the outcome. What is not settled in advance gets improvised under pressure.
  • The clock starts on becoming aware of the incident, not when the investigation is done. Early warning rests on incomplete information.
  • One incident can trigger reporting duties under several sets of rules at once, with different recipients and different deadlines.
  • The lessons learned phase is the one most often skipped and the one that delivers the most value.
  • A plan that has never been exercised is a hypothesis about how the organisation will behave.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

  • Template collection

    Report templates for early warning within 24 hours and the full report within 72.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.