Zweite Schicht DE, Deutsche Fassung Book a call

Use case

Updated

From the on-call service's phone call to the final report: a workflow that meets the NIS2 reporting duty after a security incident and keeps management in the picture.

A food manufacturer, around 600 employees, three plants, deliveries to retailers every morning from five o'clock. The night from Friday to Saturday, 02:10: the on-call service rings the head of IT. Ransomware has taken hold of production planning, and a ransom demand is sitting on two servers. From this call, the clock is running: 24 hours to the early warning to the Federal Office for Information Security (BSI), 72 hours to the notification, and the customers whose deliveries will be missing on Monday should not learn about it from the press. We give you the software your crisis team uses to work through this night according to plan. Legal advice is not part of it, and the reporting stays with you.

Sketch of a server rack with its door open, three units half pulled out and a rotating beacon on top, next to it a table with a telephone and a wall clock showing a quarter past three.

Duty

What the law requires

The German NIS2 Implementation Act has applied since 6 December 2025. Essential and important entities report significant security incidents to the BSI in three stages.

Reporting duties under NIS2 and the new BSI Act
Legal basisDirective (EU) 2022/2555 (NIS2 Directive), transposed in Germany by the NIS2 Implementation Act with the new BSI Act (BSIG), in force since 6 December 2025
Who is affectedEssential and important entities in 18 sectors, including energy, transport, health, water, waste, chemicals, food, the manufacture of machinery, vehicles, electronics and medical devices, digital services and postal services, as a rule from 50 employees or €10 million in turnover and balance sheet total
TriggerA significant security incident, for example one that causes severe operational disruption or financial losses, or can cause considerable damage to others
DeadlinesEarly warning within 24 hours of becoming aware, notification within 72 hours with an initial assessment, severity, impact and indicators of compromise, final report within one month
RecipientThe BSI, with which the entities concerned had to register by 6 March 2026
Customer informationRecipients of your services must be informed without undue delay when ordered by the BSI, if the incident could affect the provision of the service (Section 35 BSIG)
ManagementMust implement and oversee the security measures and is personally liable towards the entity for breaches of duty (Section 38 BSIG)
FineUp to €10 million or 2 percent of annual turnover for essential entities, up to €7 million or 1.4 percent for important entities
Legal position as ofOctober 2026. We build the workflow; the legal assessment of whether an incident is significant and must be reported stays with your legal department or law firm.

Clock

The workflow, hour by hour

The tool takes in every alert, proposes a classification, starts the clock and prepares every notification. Nothing goes out that a person has not approved. Hour zero is the moment you become aware, not the moment someone arrives at the office.

  1. Minute 0

    The alert arrives, whatever the channel

    An alarm from your security monitoring or the antivirus software on your computers, a call to the IT hotline, a report from your IT service provider or a tip from an employee: every incoming report becomes a case, with a timestamp, the systems affected and the sites.

  2. Hour 1

    Classification with a proposal and reasons

    The workflow proposes whether the incident is significant and gives its reasons against the criteria: severe operational disruption, financial loss, damage to others. It shows which deliveries depend on the systems concerned. Your information security officer confirms or changes the classification, at night via an approval link.

  3. Hours 1 to 3

    Management and crisis team

    The workflow calls the crisis team together according to your list and gives management a one-page situation report: what is known, which deadlines are running, which decisions are pending. Because NIS2 requires management itself to implement and oversee the measures, the moment it was informed is recorded with a timestamp.

  4. by hour 24

    Early warning to the BSI

    The early warning may be rough: that a significant incident has occurred, whether an unlawful act is suspected and whether it may have cross-border impact. The workflow writes the draft, sends reminders after eight, sixteen and twenty hours and escalates to management if nobody has approved it. The BSI's acknowledgement of receipt goes into the log.

  5. by hour 72

    Notification with an initial assessment

    The workflow gathers the findings of the forensic team and the IT service provider from the ticketing system and writes the draft: initial assessment, severity, impact, indicators of compromise such as suspicious file names and network addresses. Whatever is missing, it requests with a deadline. The waves of the cascade run in parallel.

  6. by month 1

    Final report from the log

    The workflow produces the final report from the case: description, cause, severity, the times of every step, measures taken, scope of customer information. Whatever is still open is stated openly.

  7. afterwards

    Lessons and trial run

    The lessons go into your rules and templates. Twice a year a made-up incident runs through the entire workflow, so that the telephone numbers are right and management has practised its role.

Cascade

Who learns what has happened, and when

In stages according to how they are affected. Each wave has a draft, a person who approves it and a point in time in the log.

The waves of the cascade with recipient, channel, content and approval
WaveRecipientChannelContentApproval
1, in the first hoursManagement, crisis team, information security, plant managersCall according to the alert list, mobile message, separate crisis channelOne-page situation report, deadlines, pending decisionsInformation security
2, by hour 24Suppliers and service providers with access to your network, plus your insurerCall to the emergency contacts, email from the template, claim notification as your policy requiresBlock and check access, contact personCrisis team
3, hours 24 to 72Customers whose deliveries or services are affected, starting with those with fixed delivery windowsCall from the sales team with a call note, email in the customer's languageWhat is known, which deliveries are affected, who can be reachedManagement
4, ongoingEmployees at all sitesNotice board, message to the shift supervisorsWhich systems are blocked, how the shift carries onCrisis team and head of HR
5, within the three deadlinesThe BSI, with early warning, notification and final reportThe BSI's reporting channel, submitted by a personMandatory details for each stage, taken from the caseManagement

You set the order, the templates and the alert list in the analysis. The workflow matches confirmations to the case and follows up when no answer comes. Anyone it cannot reach goes onto a list for the crisis team to call back.

Approval

What stays with your people

  • The classification. The workflow proposes and gives reasons. Whether an incident is significant is decided by your information security officer, in case of doubt with the legal department.
  • Approval by management. NIS2 deliberately places responsibility at the top. The workflow brings management into the picture early and concisely; the approval has to come from management itself.
  • Every notification to the BSI. No draft goes out without approval.
  • Every wave of the cascade. Wording, recipients and timing are confirmed beforehand.
  • The technical decisions. Disconnecting the network, restoring systems, commissioning forensics: these are decided by IT and your service providers.

Integration

Which systems the workflow sits in

The reporting chain reads from your systems and runs separately from the production network, because an attack can hit exactly those systems.

System integration in detail

  • IncomingSecurity monitoring, antivirus software, hotline, service providers, reports from employees
  • CaseThe ticketing system your IT already uses, such as Jira or ServiceNow
  • ImpactERP with deliveries, CRM with customer contacts, list of service providers
  • CommunicationAlert list, email sending with templates per language, separate crisis channel
  • AuthorityThe BSI's reporting channel. Authority portals rarely have an interface: the workflow pre-fills the notification, a person enters it, and the timestamp goes into the log.

Evidence

The log is the evidence

When the BSI asks when you became aware and when you reported, the answer is an export: every step with a timestamp, from the classification and the moment management was informed to every wave and every notification.

Management, which is personally liable, can use it to show that it was informed and exercised oversight. The auditor and the insurer receive the same export. And because the incidents that were not significant are documented too, you can show that you checked, not just that you reported.

Often it is the same incident that starts several clocks. If personal data is affected, such as personnel files, the General Data Protection Regulation (GDPR) starts a second clock, to a second authority, the data protection supervisory authority: without undue delay and where feasible within 72 hours. If the attack affects one of your own products, the Cyber Resilience Act comes on top. The workflow keeps all the clocks in one case, with separate drafts and approvals.

Experience

What we bring

The building blocks of this reporting chain have been running at our customers for years. Reading incoming items at scale, matching them to the right case and routing them to the right team is something we know from a technology distributor with twelve sites, where enquiries from twelve sites across Europe reach the right team according to rules. Applying a set of rules to an entire inventory and classifying every finding with reasons is something we built at a fuel cell manufacturer, along with its service portal and ticketing system. Cases with log and approval run every night in our own operations.

We put the chain under the BSI's deadline into operation together with your IT. It is only accepted after a made-up incident on a night you choose. That trial run has to show that the alert list really wakes someone up, that management has its situation report within the first hour and that the workflow keeps running even without your email system. We show you a sample log of such a trial run in the first call.

Read the case studies

Price

Price and scope

The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks, longer with several duties and languages. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. Any more precise figure in advance would be guesswork: one plant with one alert list and six sites in three countries, each with its own service providers, do not need the same tool. What determines the price:

  • number of incoming channels, from monitoring to the on-call phone
  • number of systems from which the impact on customers and suppliers is determined
  • number of languages, sites and recipient groups in the cascade
  • whether the workflow covers only NIS2 or also reporting data breaches and duties under the Cyber Resilience Act

Data flow: incident data and customer lists stay on your server or in a German data centre. The AI components run on open models on your own servers or via EU data centres; an incident description never goes to a model that trains on it. Data flow per service.

Related

Related use cases

Further reading: Monitoring and maintaining an AI workflow and AI data protection in companies: three ways.

Questions

Questions about the reporting chain under NIS2

What the head of IT and management ask beforehand. More answers under Questions and answers.

Does the AI decide whether an incident is significant?

No. It proposes a classification and gives its reasons against the criteria: operational disruption, financial loss, damage to others. The decision is made by your information security officer, in case of doubt with the legal department. The clock still counts from the moment you became aware, so that the check does not eat into the 24 hours.

What use is the workflow if the attack takes down our IT?

That is why the reporting chain runs separately from your production network, on its own server or in a German data centre, with its own login. The alert list and contacts are mirrored there regularly. If your email system fails, the workflow reaches the crisis team by telephone and mobile message.

Why does management have to be involved itself?

Because NIS2 requires management to implement and oversee the measures, and it is personally liable towards the entity for breaches of duty. In the first hours, the workflow gives management a one-page situation report, obtains its approvals and records both with a timestamp.

Who is there at night and at the weekend, and who is liable for what?

At night the workflow runs without people beside it: it opens the case, starts the clock and calls the people on your on-call list until someone confirms. Your emergency plan remains the basis. As part of ongoing operation we monitor that the workflow is running, with response times on working days; round-the-clock standby is agreed separately. If the workflow itself fails, the alert list, templates and customer list are ready as an export, and your crisis team carries on by hand. Your entity remains responsible for meeting the deadlines towards the BSI; we are liable for the tool under our terms and conditions.

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices