Glossary
Security Incident
An event with an actual impact on the availability, authenticity, integrity or confidentiality of data or services. NIS 2 imposes strict notification deadlines for significant incidents.
A security incident is, under NIS 2, an event that compromises the availability, authenticity, integrity or confidentiality of transmitted, stored or processed data, or of services offered by information systems.
"Significant" incidents
NIS 2 introduces the concept of a "significant" incident, which must be notified to the authorities. An incident is significant if it:
- Has caused or is likely to cause severe operational disruption or financial losses
- Has affected or is likely to affect other individuals or organisations by causing considerable material or non-material damage
Notification timeline (NIS 2, Art. 23)
| Step | Deadline | Content |
|---|---|---|
| Early warning | 24 hours | Initial report, likely nature of the incident |
| Incident notification | 72 hours | Initial assessment, indicators of compromise |
| Intermediate report | On request | Update on the incident's status |
| Final report | 1 month after notification | Full analysis, corrective measures |
Who to notify
In France, notifications must be sent to ANSSI (or the relevant sector-specific CSIRT) via the dedicated reporting portal.