The 24-Hour Clock by Kai London
The hardest part of NIS2 reporting is not the form. It is deciding, within hours and on partial information, whether what you are looking at is a significant incident — and then saying so in writing without overstating or understating it. This book is about that decision and the discipline around it.
What the book covers
The reporting sequence
Early warning, incident notification and final report as a single workflow, with the internal handoffs each stage requires.
Significance assessment
Practical criteria for judging significance quickly, and how to document the reasoning either way.
Drafting under uncertainty
Language that is accurate about what is known, unknown and assumed — and holds up when facts change.
Roles and authority
Who decides, who signs, who speaks to the authority, and how that works out of hours.
Parallel obligations
Coordinating with data protection, sectoral, financial and contractual notification duties without contradiction.
Evidence and rehearsal
The record a supervisory authority may later ask for, and how to exercise the clock before it starts.
This book offers general guidance and is not legal advice. NIS2 is implemented differently across member states; take qualified advice on the obligations that apply to your entity. It is independent and carries no endorsement by or affiliation with any regulator or standards body.
Who it is for
CISOs and incident response leads, compliance and legal counsel, crisis managers, and executives at essential and important entities who must sign off notifications quickly.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.