Experiences of CrowdStrike global IT outage
In July 2024, CrowdStrike's security software update caused global chaos. This event highlighted the delicate balance between security and system stability.
Our S.O.S. line:
+49 89 262 025954
Our team of experts is ready to assist your organization in the event of a cyberattack.
detailsGovernance, Risk and Compliance Csaba Krasznay todayOctober 18, 2024

Today is the day when the NIS2 become effective in all European member states.
Meanwhile, the European Union is still enhancing cybersecurity across the region, as evidenced by the recent developments in legislative measures.
Two essential documents – the Commission Implementing Regulation laying down rules for the application of Directive (EU) 2022/2555 and its accompanying annex – form a comprehensive framework that builds upon Directive (EU) 2022/2555, also known as the NIS2 Directive, which is critical for strengthening cybersecurity risk management and incident handling.
These regulations provide detailed technical and methodological requirements for organizations, particularly those providing DNS services, cloud computing, content delivery networks, and online platforms. Coupled with the European Commission’s press release, which outlines the broader regulatory goals, the EU aims to fortify its digital infrastructure against rising cyber threats.
This blog will explore the key incident handling elements from these regulations, emphasizing their importance in improving incident detection, reporting, and response and gives an overview for everyone under the NIS2 Directive.
At the heart of the regulations lies a clear and structured incident handling policy. Entities covered by the NIS2 Directive are required to establish a policy that outlines roles, responsibilities, and procedures for detecting, analyzing, and responding to incidents. This policy must also cover post-incident activities such as recovery, documentation, and reporting (3.1.1).
Key elements of this policy include:
These requirements ensure that entities are not only prepared for incidents but also capable of handling them systematically and efficiently.
To detect incidents in a timely manner, the regulations mandate continuous monitoring and logging of network and information systems. This process enables the detection of suspicious events that may escalate into significant incidents.
The regulation highlights:
Entities must establish criteria for assessing and classifying events to determine whether they qualify as incidents. This includes a triage system that helps prioritize incidents based on their potential impact on network security.
The assessment process involves:
An effective incident response framework is vital to mitigating the damage caused by cyberattacks. The regulation mandates documented procedures for containing, eradicating, and recovering from incidents.
Key steps include:
Entities must report incidents that are classified as significant according to predefined criteria outlined in the implementing regulation. An incident is considered significant if it leads to operational disruptions, financial losses, or material damage to individuals or businesses.
To determine whether an incident qualifies as significant, entities should assess:
Entities must notify the relevant national authorities promptly, providing an initial report followed by detailed updates as more information becomes available. This ensures that incidents are addressed at the appropriate regulatory level, helping to mitigate broader risks across the sector.
The EU’s latest cybersecurity regulations aim to create a unified and robust framework that emphasizes both proactive and reactive measures to safeguard digital infrastructure. For DNS providers, cloud services, and other essential entities, the focus on incident handling, continuous monitoring, and reporting of significant incidents ensures a higher standard of preparedness. The structured approach provided by these regulations fosters a more resilient cybersecurity landscape, promoting quick recovery from incidents and minimizing the risk of widespread disruption.
By adhering to these regulations, organizations can not only comply with EU directives but also enhance their own security posture, ensuring a safer environment for their customers and stakeholders alike.
Sources:
Commission Implementing Regulation (EU) …/… of 17 October 2024: https://ec.europa.eu/newsroom/dae/redirection/document/109217
Annex to the Commission Implementing Regulation, Brussels, 17.10.2024: https://ec.europa.eu/newsroom/dae/redirection/document/109218
European Commission Press Release on Cybersecurity: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_5342
Written by: Csaba Krasznay
Cyber Threat Intelligence Csaba Krasznay / August 26, 2024
In July 2024, CrowdStrike's security software update caused global chaos. This event highlighted the delicate balance between security and system stability.
Governance, Risk and Compliance Csaba Krasznay / October 18, 2024
NIS2 Directive takes effect today in the EU. We highlight key incident handling elements, enhancing detection, reporting and response under the new regulations.
Governance, Risk and Compliance Csaba Krasznay / August 22, 2023
Building cybersecurity is expensive. In a threat environment that is changing daily, newer and newer defence technologies are emerging that would need to be operated in a highly skills-scarce environment. Moreover, new cybersecurity technologies require knowledge that may not be available in the professional domain, such as artificial intelligence. However, compliance requirements such as NIS2 ...