Do you have an incident?

Our S.O.S. line:

+49 89 262 025954

Our team of experts is ready to assist your organization in the event of a cyberattack.

details

Cybersecurity Incident Handling in the Context of NIS2 Regulation

Governance, Risk and Compliance Csaba Krasznay todayOctober 18, 2024

Background

The EU’s latest cybersecurity regulations provide detailed guidance for service providers on detecting, managing, and reporting incidents, ensuring swift recovery and the protection of digital infrastructure.

Today is the day when the NIS2 become effective in all European member states.

Meanwhile, the European Union is still enhancing cybersecurity across the region, as evidenced by the recent developments in legislative measures.

Two essential documents – the Commission Implementing Regulation laying down rules for the application of Directive (EU) 2022/2555 and its accompanying annex – form a comprehensive framework that builds upon Directive (EU) 2022/2555, also known as the NIS2 Directive, which is critical for strengthening cybersecurity risk management and incident handling.

These regulations provide detailed technical and methodological requirements for organizations, particularly those providing DNS services, cloud computing, content delivery networks, and online platforms. Coupled with the European Commission’s press release, which outlines the broader regulatory goals, the EU aims to fortify its digital infrastructure against rising cyber threats.

This blog will explore the key incident handling elements from these regulations, emphasizing their importance in improving incident detection, reporting, and response and gives an overview for everyone under the NIS2 Directive.

Incident Handling Policy and Roles (Annex, Section 3)

At the heart of the regulations lies a clear and structured incident handling policy. Entities covered by the NIS2 Directive are required to establish a policy that outlines roles, responsibilities, and procedures for detecting, analyzing, and responding to incidents. This policy must also cover post-incident activities such as recovery, documentation, and reporting (3.1.1).

Key elements of this policy include:


  • Categorization of incidents: Entities must implement a system that categorizes incidents based on predefined criteria (3.1.2). This helps in effectively prioritizing responses based on the severity and potential impact of incidents.
  • Incident response roles: Specific roles should be assigned to competent employees to manage and respond to incidents, ensuring a coordinated and swift reaction. This is crucial for timely containment and recovery.
  • Communication and escalation plans: Effective communication mechanisms should be in place for incident escalation and internal/external reporting. This ensures that all relevant stakeholders are informed promptly, reducing the likelihood of delayed responses.

These requirements ensure that entities are not only prepared for incidents but also capable of handling them systematically and efficiently.

Monitoring and Logging to Detect Incidents (Annex, Section 3.2)

To detect incidents in a timely manner, the regulations mandate continuous monitoring and logging of network and information systems. This process enables the detection of suspicious events that may escalate into significant incidents.

The regulation highlights:


  • Automated monitoring: Where feasible, entities should automate monitoring activities to minimize human error and detect anomalies more efficiently (3.2.2). Automation also helps in reducing false positives and false negatives, improving the overall accuracy of detection.
  • Log management: Logs must be reviewed regularly to identify unusual trends and detect potential threats early. This practice ensures that even subtle warning signs of cyberattacks do not go unnoticed.
  • Time synchronization: Entities should ensure that all systems are synchronized with accurate time sources to correlate logs from different systems. This measure aids in assessing the sequence of events leading to an incident, which is crucial for forensic investigations.

Event Assessment and Classification (Annex, Section 3.4)

Entities must establish criteria for assessing and classifying events to determine whether they qualify as incidents. This includes a triage system that helps prioritize incidents based on their potential impact on network security.

The assessment process involves:


  • Predefined criteria for classification: These criteria must be established in advance to ensure that incidents are evaluated consistently. The use of a well-structured triage system allows entities to address critical incidents with higher urgency.
  • Correlation and analysis of logs: To understand the root cause of incidents, entities are required to analyze correlated log data. This helps in identifying patterns of recurring incidents or targeted attacks.

Incident Response and Post-Incident Reviews (Annex, Sections 3.5 and 3.6)

An effective incident response framework is vital to mitigating the damage caused by cyberattacks. The regulation mandates documented procedures for containing, eradicating, and recovering from incidents.

Key steps include:


  • Incident containment: Once detected, the priority is to prevent the incident from spreading to other systems. Entities must establish mechanisms to quickly isolate affected systems.
  • Eradication and recovery: After containment, the next steps involve eradicating the root cause and restoring affected systems. Post-incident activities are equally important as they ensure a full recovery.
  • Post-incident reviews: Conducting a post-incident review allows entities to identify the root causes and learn from their experiences. These reviews contribute to enhancing the organization’s incident response strategy by incorporating lessons learned into future prevention and mitigation measures.

Significant Incident Reporting (Commission Implementing Regulation, Article 3)

Entities must report incidents that are classified as significant according to predefined criteria outlined in the implementing regulation. An incident is considered significant if it leads to operational disruptions, financial losses, or material damage to individuals or businesses.

To determine whether an incident qualifies as significant, entities should assess:


  • Operational disruption: This includes the complete or partial unavailability of essential services, such as healthcare or emergency services, which may result in severe consequences.
  • Material or non-material damage: Incidents causing death, injury, or considerable harm to individuals’ health must be reported. Moreover, significant financial losses incurred by the entity due to the incident also trigger the reporting obligation.

Entities must notify the relevant national authorities promptly, providing an initial report followed by detailed updates as more information becomes available. This ensures that incidents are addressed at the appropriate regulatory level, helping to mitigate broader risks across the sector.

Conclusion

The EU’s latest cybersecurity regulations aim to create a unified and robust framework that emphasizes both proactive and reactive measures to safeguard digital infrastructure. For DNS providers, cloud services, and other essential entities, the focus on incident handling, continuous monitoring, and reporting of significant incidents ensures a higher standard of preparedness. The structured approach provided by these regulations fosters a more resilient cybersecurity landscape, promoting quick recovery from incidents and minimizing the risk of widespread disruption.

By adhering to these regulations, organizations can not only comply with EU directives but also enhance their own security posture, ensuring a safer environment for their customers and stakeholders alike.

 

Sources:

Commission Implementing Regulation (EU) …/… of 17 October 2024: https://ec.europa.eu/newsroom/dae/redirection/document/109217

Annex to the Commission Implementing Regulation, Brussels, 17.10.2024: https://ec.europa.eu/newsroom/dae/redirection/document/109218

European Commission Press Release on Cybersecurity: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_5342

 

Written by: Csaba Krasznay

Previous post

Similar posts

Governance, Risk and Compliance Csaba Krasznay / August 22, 2023

Reflections on Financing European Cyberdefence

Building cybersecurity is expensive. In a threat environment that is changing daily, newer and newer defence technologies are emerging that would need to be operated in a highly skills-scarce environment. Moreover, new cybersecurity technologies require knowledge that may not be available in the professional domain, such as artificial intelligence. However, compliance requirements such as NIS2 ...

Read more trending_flat