A security incident is not a question of if, but of when. NIS2 requires systematic preparation — we explain the structure, roles, and operational response.
§ 30 (2) No. 2 BSIG obligates affected entities to take measures to manage security incidents. The trigger is not every security event, but only a significant security incident.
Employees must know who to contact — before an incident occurs. Low-threshold reporting processes determine whether the BSI reporting deadlines can be met at all.
An interdisciplinary team with clearly defined responsibilities — actively involved, not merely informed.
Concrete instructions for the most likely scenarios — regularly rehearsed, not merely documented.
The actual work begins after the BSI notification. These three phases are not prescribed by law in detail, but without them sustainable damage limitation is not possible.
From practice: In exercises, things regularly stall after just a few minutes: who classifies the incident as significant? IT management and the data protection officer disagree, and executive management has no clear view. Exercises under realistic conditions reveal more in two hours than a year of maintaining documentation.
We develop your response plans, train your incident team, and support your first exercise — so the framework works in practice, not just on paper.
Request Consultation Now