← Back to Guidance Portal

Incident Handling Playbook

Operational procedures for meeting the Article 23 strict reporting timelines under the NIS2 Directive.

1
T < 24 HOURSNIS2 Art 23.4.a

The Early Warning

A brief notification to the CSIRT/Authority. Focus is on speed, not full technical accuracy.

Confirm if incident is "Significant"
Notify national CSIRT via secure portal
Indicate potential cross-border impact
Initial identification of threat actor (if known)
Telecom Detail: Report signaling storms (SS7) or core network outages affecting >1% of national subscriber base.
2
T < 72 HOURSNIS2 Art 23.4.b

Incident Notification

A more detailed update once the incident has been stabilized or contained.

Update initial assessment of severity
Provide technical Indicators of Compromise (IoCs)
Document containment steps taken
Preliminary root cause analysis
Telecom Detail: Specify if the breach involves the HLR/HSS or AMF (5G) and if subscriber privacy is at high risk.
3
T < 1 MONTHNIS2 Art 23.4.c

The Final Report

The definitive document ending the reporting cycle. Must be legally and technically robust.

Comprehensive root cause analysis
Final list of affected systems and users
Long-term remediation plan
Post-mortem and process improvement
Telecom Detail: Update vendor relationship records (Art 21.2e) if a third-party RAN/Core vendor was a factor.
TOOLS // OPERATIONAL_READY

Required Evidence Kit

Ensure your SOC has these artifacts ready for every reported incident to satisfy national regulators.

🛡️
Traffic Logs

Netflow/IPFIX records showing the vectors of the attack.

📧
Comm. Logs

Internal and external communication timestamps.

💻
Forensic Images

Memory dumps or disk snapshots of affected nodes.