NIS2 Directive incident reporting timelines: 24h early warning vs 72h notification — who handles what in your org?
NIS2 Article 23 requires: - 24h: early warning (without details) - 72h: initial notification with assessment - 1 month: detailed report with mitigation status In practice: - Who in your team files the 24h early warning? SOC analyst on-call or CISO directly? - How do you handle the handoff from 24h to 72h? We found our incident response playbooks didn't map cleanly to NIS2's three-phase reporting. - Does your regulator (BSI for us) provide a portal, or is this still email-based? Also curious about cross-border: if you're an EU entity with US cloud infrastructure, does the 24h clock start when your SOC detects it, or when your US provider notifies you?