DOC-006 ← Document Portal

Cybersecurity Incident Reporting Procedure

Step by step: from detection to final report – 24h / 72h / 1 month deadlines
Document Number
DOC-006
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ CISO
Approved by
▸ Board / CEO
Legal Basis
Art. 23 NIS2; Art. 33–34 GDPR
Related Documents
DOC-005 | DOC-007 | DOC-004
🚨 QUICK RESPONSE CARD – P1/P2 INCIDENT
REPORT IMMEDIATELY TO:
▸ CISO: [24/7 telephone]
▸ Helpdesk: [internal number]
DO NOT:
✗ Do not delete logs or files
✗ Do not inform media without approval
✗ Do not shut down systems without CISO approval
CSIRT (significant incident):
▸ [National CSIRT contact]
DPA (personal data breach):
▸ DPA contact | 72h

1. Scope and Application

This procedure describes the detailed steps, forms and deadlines required when reporting cybersecurity incidents to internal and external stakeholders. It is used in conjunction with DOC-005 (classification, definitions) and DOC-007 (technical handling).

The procedure applies to all incidents registered by the organisation. The obligation to notify CSIRT applies only to significant incidents (level P1 and selected P2 per the criteria in DOC-005 section 2.3).

2. Reporting Timeline – Significant Incident

T+0 – Incident detected
Event detected / reported
Employee, SIEM system, IDS/IPS alert or supplier detects the incident. Immediate notification to CISO. Initiate Initial Form (Annex A).
T+1h – Initial assessment
CISO: assessment and classification
Is this a significant incident under NIS2? If YES → 24h clock starts. Activate Response Plan (DOC-007).
T+24h – EARLY WARNING (MANDATORY)
Notification to competent CSIRT
Channel: ▸ [National CSIRT contact] or appropriate sector CSIRT.
Content: information on incident, indication of cross-border impact (if applicable).
Use Early Warning Form (Annex B).
T+72h – INCIDENT NOTIFICATION (MANDATORY)
Full notification to CSIRT + DPA (if data breach)
Content: incident assessment, severity classification, service impact, IoCs, actions taken.
Use Incident Notification Form (Annex C).
In parallel: DPA notification if personal data breach.
T+1 month – FINAL REPORT
Final report to CSIRT
Full description: root cause (RCA), chronology, remediation actions, preventive measures.
Use Final Report Form (Annex D).

3. Detailed Process Steps

Phase 1: Detection and internal reporting

1 Event detection – by an employee, monitoring system, SIEM alert, supplier notification or external security researcher
2 Do not destroy evidence – do not delete files, logs, emails. Keep everything.
3 Report immediately – CISO (tel. ▸ [number]) and/or via ticketing system ▸ [name]. Complete Initial Form (Annex A).
4 Isolation (if necessary) – if device is infected, disconnect it from the network (LAN/Wi-Fi), but do not cut power without CISO approval (you will lose RAM data).

Phase 2: Assessment and classification (CISO)

5 Initial assessment – CISO assesses: what type of incident (category from DOC-005 section 4), what level (P1–P4), is this a significant incident requiring notification.
6 Escalation – for P1 and P2: Board notification. For P1: activate BCP if required (DOC-011).
7 Open register – create entry in Incident Register (number INC-YYYY-NNN).

Phase 3: Containment and eradication

8 Containment – isolate affected systems, block accounts, change passwords, filter network traffic. Details in DOC-007.
9 Forensic evidence collection – disk images, logs, memory dumps, network traffic captures (PCAP).
10 Eradication – remove malware, close vulnerability, verify systems.

Phase 4: Recovery

11 Recovery from backup – in accordance with procedure DOC-012 and BCP DOC-011.
12 Verification – testing of restored systems before returning to production.

Phase 5: External reporting

13 Early warning to CSIRT – no later than 24h from detection of a significant incident.
14 Notification to CSIRT – no later than 72h from detection.
15 DPA notification (if applicable) – no later than 72h from confirming personal data breach.

Phase 6: Analysis and closure

16 Post-Incident Review (PIR) – root cause analysis (RCA), documentation of lessons learned.
17 Final report to CSIRT – within 1 month of notification.
18 Documentation update – update Risk Register (DOC-003), policies, procedures if needed.

Annex A – Initial Incident Notification Form (internal)

📋
Completed by any employee or the first person detecting the incident. Send to CISO immediately.
INITIAL INCIDENT NOTIFICATION FORM
Date and time of detection▸ DD/MM/YYYY HH:MM
Reporter (name)
Reporter's contact▸ [phone / email]
What was observed?▸ [description of event – what, where, when]
Affected systems / devices▸ [system names, IP addresses, computer numbers]
Any actions taken? Which?▸ [e.g. disconnected from network / nothing done]
Are other people aware?▸ [yes/no – who]
Estimated impact (preliminary)▸ [e.g. systems unavailable / data exposed / nothing visible]

Annex B – Early Warning Form to CSIRT (T+24h)

🕐
Deadline: 24 hours from detection of a significant incident. Completed by CISO.
EARLY WARNING – CSIRT NOTIFICATION
Reporting entity (name, ID)▸ [full organisation name, Registration Number]
Sector / type of service▸ [NIS2 sector, type of key/important service]
Contact person (CISO)▸ [First Last Name, phone, email]
Date/time of detection▸ DD/MM/YYYY HH:MM
Date/time of notification▸ DD/MM/YYYY HH:MM
Brief incident description▸ [incident type, affected systems, preliminary scope]
Does incident have cross-border impact?▸ [YES / NO / UNKNOWN]
Preliminary severity assessment▸ [Low / Medium / High / Critical]
Remediation actions taken▸ [isolation, containment – what has been done]

Annex C – Incident Notification Form to CSIRT (T+72h)

🕐
Deadline: 72 hours from detection of a significant incident. Completed by CISO.
INCIDENT NOTIFICATION – CSIRT
Internal reference number▸ INC-YYYY-NNN
Entity / sector
Incident type (category)▸ [MAL/PHI/NET/WEB/ACC/DAT/INS/SUP/PHY/OTH]
Severity level▸ [P1/P2/P3/P4]
Affected systems / services
Estimated number of affected users
Detailed incident description▸ [chronology, attack vector, scope]
Indicators of compromise (IoC)▸ [IPs, domains, hashes, malware signatures]
Remediation actions taken
Current incident status▸ [Ongoing / Contained / Closed]
Was personal data breached?▸ [YES (DPA notified DD/MM) / NO]
CSIRT support required?▸ [YES / NO – describe need]

Annex D – Final Report Form to CSIRT (T+1 month)

INCIDENT FINAL REPORT
Reference number▸ INC-YYYY-NNN
Detection date / Closure date▸ DD/MM/YYYY / DD/MM/YYYY
Root cause▸ [description of root cause – vulnerability, human error, etc.]
Incident chronology▸ [timeline: detection, containment, eradication, recovery]
Impact on services / data▸ [downtime, number of affected persons, financial losses]
Remediation measures implemented
Lessons learned▸ [what was changed, which procedures updated]
Preventive measures▸ [future plans]

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0 ▸ DD/MM/YYYY ▸ Initial release ▸ Board
DOC-006 Incident Reporting Procedure | v1.0 | NIS2/ISMS