Compliance
Reporting an incident under NIS2 within 24 hours: the playbook
September 2, 2026· 6 min
In short
A NIS2 early warning must be sent within 24 hours of becoming aware of the incident: suspected nature, affected scope, possible cross-border impact. The detailed report follows within 72 hours. A signed, timestamped incident file produced at detection time covers both deadlines.
Hour zero to four: qualify, do not notify yet
Isolate affected machines, freeze logs and identify the entry point. The console builds the timeline automatically: initial process, lineage, actions performed. Do not shut the whole fleet down by reflex — you would destroy useful evidence.
Four to 24 hours: the early warning
The early warning is short: what you know, what you still do not, and whether cross-border impact is possible. Attach the SHA-256 hash of the incident file: it proves your account was not rewritten afterwards.
24 to 72 hours: the detailed report
Severity assessment, indicators of compromise, measures taken and recovery schedule. This is also the document your cyber insurer will request: produce it once, use it twice.
On the same topic