Module 2 of 3 · 50 minutes
Incidents, suppliers and the 24 hour clock
By the end of this module you will be able to
- State the three stages of NIS2 incident reporting and their deadlines
- Explain what makes an incident significant
- Describe what a first hour looks like when something goes wrong
- Explain why NIS2 customers send security questionnaires to suppliers
- Answer a supplier questionnaire honestly and usefully
Work through it
1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.
Watch: Emma and George talk it through
3 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.
Emma George, the bit that worries people is the 24 hours. Report an incident in a day? We'd still be working out what happened.
George And nobody expects you to have worked it out. NIS2 Article 23 has three stages. An early warning within 24 hours of becoming aware. A fuller incident notification within 72 hours. And a final report within one month.
Emma What goes in the early warning?
George Very little. That it happened, whether it looks malicious, and whether it could affect other countries. It's deliberately light. They don't want the full story in a day. They want to be told.
Emma And when does the clock start?
George When the organisation becomes aware. Not when the investigation finishes. That's the point people miss.
Emma Does every little thing count?
George No, it has to be significant. Severe operational disruption or financial loss, or considerable damage to other people. But the wording is caused or capable of causing. Something you contained can still be reportable.
Emma So if in doubt?
George Make the early warning and correct it later. That's the safer course.
Emma Realistically, who notices first? It's not going to be me.
George No, and it's almost never the security lead. It's whoever is at the screen. So they need one thing. Who to tell, at any hour, without fear of blame.
Emma And then?
George In order. Write down the time you became aware, because every deadline runs from it. Contain what you can without destroying evidence. Tell the person who owns the decision to report. Tell affected customers. And keep a log of what was known and decided, and when.
Emma Why customers so early?
George Because your contract probably requires it, and their own clock may have started. Which brings us to the questionnaire you got.
Emma Yes. Why are they asking me forty questions?
George Supply chain security is one of the ten measures. A covered organisation has to consider each direct supplier's vulnerabilities and practices. So they ask, and they write it into the contract. Security measures, a right to audit, and a duty to tell them about incidents fast.
Emma I'm tempted to tick yes to everything.
George Don't. A no with a date beside it is more useful to them than a yes that turns out to be untrue. And an untrue answer in a contract is a liability of a different kind.
Emma What do they check first?
George Three things. Multi-factor authentication. Backups you've actually tested. And staff training. Only tick those if you can show them.
Emma And one practical test?
George Ask a member of staff at random. If your screen showed a ransom note at two in the morning on a Sunday, who would you ring? If they can't answer, the deadline is already lost.
The written material
Three reports, three deadlines
Article 23 of NIS2 requires a covered organisation to report a significant incident to its national authority or incident response team in stages. An early warning without undue delay and in any event within 24 hours of becoming aware. An incident notification within 72 hours, updating the early warning with an initial assessment. And a final report no later than one month after the notification.
The clock starts when the organisation becomes aware, not when the investigation is finished. The early warning is deliberately light: what has happened, whether it looks malicious, and whether it could affect other countries. Nobody expects the full story in a day. They expect to be told.
What counts as significant
An incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the organisation, or if it has affected or is capable of affecting other people by causing considerable material or non-material damage.
Note the words capable of. An incident that could have been severe can be reportable even if you contained it. When in doubt, the safer course is to make the early warning and correct it later.
The first hour
A 24 hour deadline is only met by an organisation that has decided in advance who does what. The first person to notice is rarely a manager and almost never the security lead. They need to know one thing: who to tell, at any hour, without fear of blame.
Then, in order: write down the time you became aware, because every deadline runs from it. Contain what you can without destroying evidence. Tell the person who owns the decision to report. Tell customers whose service is affected, because your contract probably requires it and their own clock may have started. Keep a log of what was known and decided, and when.
Why your customer sends you a questionnaire
Supply chain security is one of the ten measures in Article 21. A covered organisation must consider the vulnerabilities of each direct supplier and the quality of their security practices. So it asks, and it writes requirements into contracts: security measures, the right to audit, and above all a duty to tell them about incidents quickly, often within 24 hours so that they can meet their own deadline.
Answer honestly. A no with a date beside it is more useful to a customer than a yes that turns out to be untrue, and an untrue answer in a contract is a liability of a different kind. Read the incident clause before you sign, and make sure the person who would notice an incident knows it exists.
Knowledge check
The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.
The learning itself stays free and open. You are reading all of it right now without an account.
Was this module useful? Tell us in two minutes, it decides what we improve next.