The clock starts the moment you know.
Under NIS2, an incident is not done when it is fixed. The reporting clock — early warning within 24 hours, full notification within 72, final report within a month — starts at the moment you become aware, whether or not anyone has opened the right spreadsheet.
TruSecure's structured incident workflows start the regulatory clock automatically at logging, pre-build each report stage from the last, and connect to business-continuity and resilience-testing evidence for DORA and ISO 22301. The timeline below is the obligation itself — the product is organized around it:
How it works
- Log
An incident is recorded once — from a connected SIEM/SOAR alert, a ticketing system, or by hand. Logging starts the regulatory clock automatically.
- Classify
Severity, cross-border impact and unlawful-access questions are structured into the workflow, because the 24-hour early warning depends on the answers.
- Report
Each report stage is pre-built from the last: the 72-hour notification inherits the early warning; the final report inherits both, plus root cause and remediation.
- Learn
The post-incident review feeds back into the control model — the weakness the incident exposed becomes a tracked remediation, not a lesson that evaporates.
Which regulations it maps to
| Framework | What it expects | Citation |
|---|---|---|
| NIS2 | Staged incident reporting against hard deadlines | Art. 23 |
| DORA | Incident classification, reporting and resilience testing | Art. 17 · 19 |
| ISO 22301 | Business-continuity capability, exercised on evidence | Testing programme |
Where the signals come from
SIEM/SOAR connectors supply detections and case data; ITSM connectors supply incident tickets and remediation tracking; collaboration connectors preserve the communication log around an incident — approvals included — for the audit trail.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
