← Back to Guidance Portal

Incident Handling Playbook

Operational procedures for meeting the Article 23 strict reporting timelines under the NIS2 Directive.

1
T < 24 HOURSNIS2 Art 23.4.a

The Early Warning

A brief notification to the CSIRT/Authority. Focus is on speed, not full technical accuracy.

✓ Confirm if incident is "Significant"
✓ Notify national CSIRT via secure portal
✓ Indicate potential cross-border impact
✓ Initial identification of threat actor (if known)
Telecom Detail: Report signaling storms (SS7) or core network outages affecting >1% of national subscriber base.
2
T < 72 HOURSNIS2 Art 23.4.b

Incident Notification

A more detailed update once the incident has been stabilized or contained.

✓ Update initial assessment of severity
✓ Provide technical Indicators of Compromise (IoCs)
✓ Document containment steps taken
✓ Preliminary root cause analysis
Telecom Detail: Specify if the breach involves the HLR/HSS or AMF (5G) and if subscriber privacy is at high risk.
3
T < 1 MONTHNIS2 Art 23.4.c

The Final Report

The definitive document ending the reporting cycle. Must be legally and technically robust.

✓ Comprehensive root cause analysis
✓ Final list of affected systems and users
✓ Long-term remediation plan
✓ Post-mortem and process improvement
Telecom Detail: Update vendor relationship records (Art 21.2e) if a third-party RAN/Core vendor was a factor.
TOOLS // OPERATIONAL_READY

Required Evidence Kit

Ensure your SOC has these artifacts ready for every reported incident to satisfy national regulators.

🛡️
Traffic Logs

Netflow/IPFIX records showing the vectors of the attack.

📧
Comm. Logs

Internal and external communication timestamps.

💻
Forensic Images

Memory dumps or disk snapshots of affected nodes.