NIS2 · Incident reporting

The 24-Hour Clock by Kai London

The hardest part of NIS2 reporting is not the form. It is deciding, within hours and on partial information, whether what you are looking at is a significant incident — and then saying so in writing without overstating or understating it. This book is about that decision and the discipline around it.

Coming soonAll books

What the book covers

The reporting sequence

Early warning, incident notification and final report as a single workflow, with the internal handoffs each stage requires.

Significance assessment

Practical criteria for judging significance quickly, and how to document the reasoning either way.

Drafting under uncertainty

Language that is accurate about what is known, unknown and assumed — and holds up when facts change.

Roles and authority

Who decides, who signs, who speaks to the authority, and how that works out of hours.

Parallel obligations

Coordinating with data protection, sectoral, financial and contractual notification duties without contradiction.

Evidence and rehearsal

The record a supervisory authority may later ask for, and how to exercise the clock before it starts.

This book offers general guidance and is not legal advice. NIS2 is implemented differently across member states; take qualified advice on the obligations that apply to your entity. It is independent and carries no endorsement by or affiliation with any regulator or standards body.

NIS2NIST CSF 2.0ISO 27035Incident response

Who it is for

CISOs and incident response leads, compliance and legal counsel, crisis managers, and executives at essential and important entities who must sign off notifications quickly.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.