Incident Handling Playbook
Operational procedures for meeting the Article 23 strict reporting timelines under the NIS2 Directive.
1
The Early Warning
A brief notification to the CSIRT/Authority. Focus is on speed, not full technical accuracy.
✓ Confirm if incident is "Significant"
✓ Notify national CSIRT via secure portal
✓ Indicate potential cross-border impact
✓ Initial identification of threat actor (if known)
Telecom Detail: Report signaling storms (SS7) or core network outages affecting >1% of national subscriber base.
2
Incident Notification
A more detailed update once the incident has been stabilized or contained.
✓ Update initial assessment of severity
✓ Provide technical Indicators of Compromise (IoCs)
✓ Document containment steps taken
✓ Preliminary root cause analysis
Telecom Detail: Specify if the breach involves the HLR/HSS or AMF (5G) and if subscriber privacy is at high risk.
3
The Final Report
The definitive document ending the reporting cycle. Must be legally and technically robust.
✓ Comprehensive root cause analysis
✓ Final list of affected systems and users
✓ Long-term remediation plan
✓ Post-mortem and process improvement
Telecom Detail: Update vendor relationship records (Art 21.2e) if a third-party RAN/Core vendor was a factor.
TOOLS // OPERATIONAL_READY
Required Evidence Kit
Ensure your SOC has these artifacts ready for every reported incident to satisfy national regulators.
Traffic Logs
Netflow/IPFIX records showing the vectors of the attack.
Comm. Logs
Internal and external communication timestamps.
Forensic Images
Memory dumps or disk snapshots of affected nodes.