N.1.22 Reporting incidents to external parties
Control Overview
This control mandates that the organization implements a formalized procedure to meet its strict legal and contractual incident notification obligations. Under the NIS 2 directive, entities must maintain clear mechanisms to report "significant incidents" to competent national authorities, government bodies, and Computer Security Incident Response Teams (CSIRTs) within mandatory statutory timelines (such as the initial 24-hour early warning and 72-hour incident notification rules). Additionally, the control requires that contractually mandated notifications to clients, suppliers, and other external stakeholders are executed systematically, ensuring transparent communication and minimizing financial or reputational damage.
Applicability Note: This control is fully applicable to the anDREa platform and establishes the mandatory regulatory interface between our internal operations and external regulatory oversight bodies.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement incorporates statutory reporting directly into our ISO/IEC 27001-based ISMS, linking technical impact analysis to our external compliance workflows.
We have expanded our incident response procedures with a dedicated NIS 2 Significant Incident Reporting module. This module provides clear, objective criteria to determine if an incident reaches the regulatory threshold of "significant" (such as severe operational disruption, substantial financial impact, or material downstream damage to our clients). Ultimate accountability for executing these external declarations is assigned directly to the Director. Furthermore, this workflow runs alongside our existing GDPR data breach reporting protocols, ensuring that both data privacy and critical infrastructure notification paths are executed simultaneously and without friction.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.26 - Response to information security incidents | Controls the execution of communication routing, notification templates, and formal external reports during a breach. |
| ISO/IEC 27001 | A.05.31 - Legal, statutory, regulatory and contractual requirements | Mandates a complete register of all external legal and contractual requirements to ensure organizational compliance. |
| Incident Framework | NIS 2 Significant Incident Reporting Protocol | The formal procedure defining significance thresholds, regulatory contact matrices, and mandatory statutory timelines (24h / 72h). |
| Continuity Governance | Disaster Recovery Plan | Direct operational guidelines defining secure, out-of-band communication channels for notifying external stakeholders outside of business hours. |
| Privacy Operations | Data Breach Procedure | Dedicated regulatory workflow specifically governing GDPR-mandated notifications to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected data subjects. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Clear threshold definitions, operational communication protocols, and regulatory notification workflows are fully operationalized and bound to executive authority.