Book an Appointment

Incident Response & digital forensics

How organisations detect, contain and investigate security incidents in a structured, court-admissible way – and which reporting deadlines run in parallel.

Security incidents are no longer rare exceptions: they occur frequently, and according to NIST, recovery often takes weeks to months. Incident response is therefore not an isolated process run by a specialist team, but an integral part of cyber risk management – which is exactly how NIST SP 800-61 Rev. 3 (April 2025) frames it, superseding the 2012 classic and aligning fully with the Cybersecurity Framework 2.0. In parallel to the technical response, regulatory clocks are ticking: NIS2 requires an early warning within 24 hours, and the GDPR a notification to the supervisory authority where feasible within 72 hours. Organisations that preserve evidence in a forensically sound manner from the outset keep all options open – from root cause analysis to criminal prosecution.

The Essentials at a Glance

01

The IR lifecycle under NIST SP 800-61 Rev. 3

Rev. 3 (April 2025) replaces the four-phase lifecycle of the 2012 predecessor (Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident Activity) with a model built around the six functions of the NIST CSF 2.0. Govern, Identify and Protect form the preparation: they prevent incidents, reduce their impact and anchor incident response in risk management. Detect, Respond and Recover constitute the actual incident response – from detection and analysis through containment and eradication to recovery, including notifications and communication. What is new is the role of continuous improvement: lessons learned feed back into all functions at any time via the Improvement category (ID.IM), not only after the incident has been closed.

02

Roles and dedicated crisis organisation

Incident response only succeeds with clearly assigned roles: leadership steers the response and decides on far-reaching measures such as shutting down or rebuilding critical services; incident handlers verify the incident, collect and analyse data and evidence, prioritise actions and limit the damage. SP 800-61r3 emphasises that many internal and external parties are involved as well – such as legal, data protection, communications, service providers and cloud providers. In German crisis management, the dedicated crisis organisation known as the besondere Aufbauorganisation (BAO) has become established practice: a predefined crisis team with its own escalation and decision-making paths that relieves the line organisation in an emergency. Decision-making authority and reachability must be defined before the incident, not during it.

03

The reporting clock: NIS2 and the GDPR run in parallel

Under Art. 23 of the NIS2 Directive (EU) 2022/2555, essential and important entities report significant incidents in stages to the CSIRT or the competent authority – in Germany to the BSI under the amended BSI Act: an early warning within 24 hours of becoming aware, a notification with an initial assessment without undue delay and in any event within 72 hours, and a final report no later than one month after the notification; affected recipients of the services must be informed without undue delay. If personal data are compromised, Art. 33 GDPR additionally requires a notification to the data protection supervisory authority without undue delay and, where feasible, within 72 hours; where there is likely a high risk, the data subjects must also be informed without undue delay under Art. 34 GDPR. A single incident can therefore start several clocks at once – which is why responsibilities, reporting channels and text templates belong in the playbook in advance.

04

Forensic principles: evidence preservation and chain of custody

ISO/IEC 27037:2012 describes the four basic steps for handling potential digital evidence: identification, collection, acquisition and preservation. Integrity and traceability are central – working copies instead of originals, cryptographic hash values and an unbroken chain of custody documenting who accessed what and when. SP 800-61r3 makes it clear: even if no prosecution is intended, collected incident data is to be treated as evidence and handled according to the organisation's evidence preservation and retention procedures, maintaining integrity and provenance. In practice, this means securing volatile data such as memory before persistent storage media – and not hastily rebuilding compromised systems, as this destroys evidence and prevents root cause analysis.

05

IR retainers and playbooks: readiness before the emergency

SP 800-61r3 explicitly mentions contracted incident handlers alongside in-house teams, such as a SOC outsourced to a managed security provider or a cloud provider's IR team. An IR retainer regulates this access contractually in advance: defined response times, clarified confidentiality and data processing questions, and an onboarding with points of contact, knowledge of the environment and pre-provisioned access – so that no time is lost on contract and access issues in an emergency. Playbooks translate the IR plan into concrete steps per scenario, such as ransomware, compromised accounts or data exfiltration; as an example, NIST references CISA's Cybersecurity Incident & Vulnerability Response Playbooks (2021). Reporting deadlines, decision points and communication channels belong directly in the playbooks.

06

Exercises as a maturity driver

The CSF 2.0 explicitly anchors exercises in the improvement process: under ID.IM-02, improvements are derived from security tests and exercises – including jointly with suppliers and relevant third parties. Formats range from tabletop discussions through simulations to technical tests; the methodological foundations are described in NIST SP 800-84. Exercises test under realistic conditions what works on paper: reachability, the BAO's decision-making paths, meeting the 24- and 72-hour deadlines and the quality of the playbooks. The results flow back as lessons learned into plans, playbooks and training – making incident response maturity measurable and growing with every iteration.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

NIST · 2025

NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

Current IR guideline (April 2025), supersedes Rev. 2 of 2012; new lifecycle model along the six CSF 2.0 functions with ID.IM as a continuous improvement loop.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 23 reporting obligations: early warning within 24 hours, notification within 72 hours, final report no later than one month after the notification, informing the recipients of the services.

Amtsblatt der EU / EUR-Lex · 2016

Verordnung (EU) 2016/679 (DSGVO)

Art. 33: notification of personal data breaches to the supervisory authority without undue delay and, where feasible, within 72 hours; Art. 34: communication to data subjects in case of high risk.

ISO/IEC · 2012

ISO/IEC 27037:2012 – Guidelines for identification, collection, acquisition and preservation of digital evidence

International guideline for the four basic steps of digital evidence preservation and for maintaining evidence integrity.

CISA · 2021

Cybersecurity Incident & Vulnerability Response Playbooks

Example playbooks referenced by NIST SP 800-61r3 with operational procedures for incident and vulnerability response.

NIST · 2006

NIST SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

Methodological framework for tabletop exercises, simulations and tests, referenced by SP 800-61r3 under ID.IM-02.

How resilient is your incident response capability?

In a no-obligation initial consultation, we jointly assess where your IR process stands today – from roles and playbooks to reporting channels and forensic readiness.