Skip to main content
PLATFORM · INCIDENT & RESILIENCE

The clock starts the moment you know.

Under NIS2, an incident is not done when it is fixed. The reporting clock — early warning within 24 hours, full notification within 72, final report within a month — starts at the moment you become aware, whether or not anyone has opened the right spreadsheet.

TruSecure's structured incident workflows start the regulatory clock automatically at logging, pre-build each report stage from the last, and connect to business-continuity and resilience-testing evidence for DORA and ISO 22301. The timeline below is the obligation itself — the product is organized around it:

0H
Incident logged
Clock starts automatically
24H
Early warning
Cross-border? Unlawful?
72H
Full notification
Severity + impact assessment
1 MO
Final report
Root cause + remediation

How it works

  1. Log

    An incident is recorded once — from a connected SIEM/SOAR alert, a ticketing system, or by hand. Logging starts the regulatory clock automatically.

  2. Classify

    Severity, cross-border impact and unlawful-access questions are structured into the workflow, because the 24-hour early warning depends on the answers.

  3. Report

    Each report stage is pre-built from the last: the 72-hour notification inherits the early warning; the final report inherits both, plus root cause and remediation.

  4. Learn

    The post-incident review feeds back into the control model — the weakness the incident exposed becomes a tracked remediation, not a lesson that evaporates.

Which regulations it maps to

Incident and resilience obligations · by framework
FrameworkWhat it expectsCitation
NIS2Staged incident reporting against hard deadlinesArt. 23
DORAIncident classification, reporting and resilience testingArt. 17 · 19
ISO 22301Business-continuity capability, exercised on evidenceTesting program

Where the signals come from

SIEM/SOAR connectors supply detections and case data; ITSM connectors supply incident tickets and remediation tracking; collaboration connectors preserve the communication log around an incident — approvals included — for the audit trail.

See all integrations

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.