Book an Appointment

Incident Response & digital forensics

How organisations detect, contain and investigate security incidents in a structured, court-admissible way – and which reporting deadlines run in parallel.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

24hours to the NIS2 early warning after becoming aware
72hours: NIS2 notification in any event, GDPR where feasible
6CSF 2.0 functions structuring the Rev. 3 lifecycle
4basic steps of evidence handling under ISO/IEC 27037

Security incidents are no longer rare exceptions: they occur frequently, and according to NIST, recovery often takes weeks to months. Incident response is therefore not an isolated process run by a specialist team, but an integral part of cyber risk management – which is exactly how NIST SP 800-61 Rev. 3 (April 2025) frames it, superseding the 2012 classic and aligning fully with the Cybersecurity Framework 2.0. In parallel to the technical response, regulatory clocks are ticking: NIS2 requires an early warning within 24 hours, and the GDPR a notification to the supervisory authority where feasible within 72 hours. Organisations that preserve evidence in a forensically sound manner from the outset keep all options open – from root cause analysis to criminal prosecution.

The Essentials at a Glance

Six topic blocks — tap to expand.

The IR lifecycle under SP 800-61 Rev. 3

Rev. 3 structures incident response along the six functions of the NIST CSF 2.0 — tap a phase.

Govern · Identify · Protect
  • Prevents incidents and reduces their impact.
  • Anchors incident response in risk management.
GovernIdentifyProtectrisk management

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

NIST · 2025

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

Current IR guideline (April 2025), supersedes Rev. 2 of 2012; new lifecycle model along the six CSF 2.0 functions with ID.IM as a continuous improvement loop.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 23 reporting obligations: early warning within 24 hours, notification within 72 hours, final report no later than one month after the notification, informing the recipients of the services.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 33: notification of personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours; Art. 34: communication to data subjects in case of high risk.

ISO/IEC · 2012

ISO/IEC 27037:2012 – Guidelines for identification, collection, acquisition and preservation of digital evidence

International guideline for the four basic steps of digital evidence preservation and for maintaining evidence integrity.

CISA · 2021

Cybersecurity Incident & Vulnerability Response Playbooks

Example playbooks referenced by NIST SP 800-61r3 with operational procedures for incident and vulnerability response.

NIST · 2006

NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

Methodological framework for tabletop exercises, simulations and tests, referenced by SP 800-61r3 under ID.IM-02.

How resilient is your incident response capability?

In a no-obligation initial consultation, we jointly assess where your IR process stands today – from roles and playbooks to reporting channels and forensic readiness.