Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.6.8 Information Security Event Reporting

Control Objective

The organisation shall provide a mechanism for personnel to report observed or suspected information security events through appropriate channels in a timely manner.

Policy Statement

anDREa maintains multiple accessible reporting channels to ensure that observed or suspected security events are captured, escalated, and addressed without delay. Mandatory, annual training ensures all personnel understand how to identify and report events, supporting our strict commitment to the 24-hour statutory notification timelines mandated by NIS 2 and GDPR.


Incident Reporting Channels

Personnel and interested parties can report any potential security anomaly, threat, or policy violation through the following official channels:

  • Internal Ticketing: Submit an incident ticket directly within the Security-Related Incidents Department queue.
  • Dedicated Email: Send an explicit alert to security@andrea-cloud.com (monitored by Quality & Assurance and the Management Team).
  • Rapid Chat Escalation: Alert the response team via the dedicated, internal SECURITY Google Chat Group.
  • Direct Liaison: Contact a member of the Management Team directly.

Regardless of the initial intake channel utilized, all confirmed or highly suspected events must be formally registered in the centralized ticketing system to preserve an auditable trail.


Critical Escalation & NIS 2 Compliance

To guarantee alignment with regional regulatory frameworks, anDREa enforces a strict emergency reporting tier based on operational impact:

  • Urgency Trigger: Any event causing or threatening severe operational disruption, platform downtime, or financial impact must be reported immediately.
  • Immediate Actions: Personnel must instantly use the Emergency Escalation Form or submit an incident with "P1" (Priority 1) Ticket Status.
  • Statutory Compliance: This rapid escalation pathway ensures that the Management Team can evaluate the event and meet the mandatory 24-hour initial reporting deadline to government Computer Security Incident Response Teams (CSIRTs) and regulatory bodies under NIS 2 and GDPR guidelines.

Administration & Cross-References