Crisis Management Frameworks

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Crisis Management Frameworks

Crisis management is defined as ‘an institutional and organisational design process’, a ‘[broad] structure [that] encompasses decision-makers [with specific roles and actions]’. In general terms, crisis management is understood as ‘making and effecting difficult decisions under difficult circumstances. With NIS2, MS have to develop a specific framework for cyber crisis management – including processes for business continuity and disaster recovery, designate or establish one or more competent authorities responsible for the management of large-scale cybersecurity incidents and crises (cyber crisis management authorities). Member States shall ensure that those authorities have adequate resources to carry out, in an effective and efficient manner, the tasks assigned to them. Member States shall ensure coherence with the existing frameworks for general national crisis management

However, because cyber crises tend to have a transboundary nature, any cyber crisis management framework must remain part of an overarching crisis management for overall coherence. This overarching crisis management framework is an integral part of the cybersecurity strategy and it set the structures for preparing, responding and recovering from major incidents that involve critical infrastructure.

In addition, MS should organise regular exercises and crisis management simulations as part of their preparedness processes to respond to large-scale cyber crisis, often including of cross-border nature.

Organising Exercises and Simulations: National cybersecurity strategies should incorporate regular cybersecurity exercises to test emergency plans, identify vulnerabilities, and improve sector cooperation. These exercises foster resilience by simulating real-world threats, from cyber-attacks to natural disasters, and ensure that national response teams can effectively coordinate across sectors and borders.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

National cyber crisis response plan and NCCN integration: Belgium’s 2026 national cyber crisis response plan integrates cyber incidents and crises into the general national emergency-management framework. The CCB provides cyber expertise and coordination, while nationally significant cyber crises are coordinated with the National Crisis Centre (NCCN), whose 24/7 service supports cross-government information flow, escalation and urgent decision-making. The plan defines responsibilities, information-exchange channels, preparedness measures and involvement of relevant public and private stakeholders.

Sources: https://ccb.belgium.be/news/belgium-adopts-new-national-cyber-crisis-response-plan

Croatia flag
Croatia

National Cyber Crisis Management Programme & Coordination for Cyber Crisis Management: Croatia's plan for handling a major cyberattack or cyber crisis, adopted by the Government on 9 January 2025 under the Cybersecurity Act. It sets out the resources, procedures and responsibilities for managing cyber crises across three levels - technical, operational, and strategic-political - aligned with the country's wider crisis-management system and the EU framework. It also establishes a new inter-agency body, the Coordination for Cyber Crisis Management, chaired by NCSC-HR, which brings together the key national authorities (intelligence, police, military, financial and telecom regulators, and others) to share information and coordinate the response. NCSC-HR also represents Croatia in the EU cyber crisis network (EU-CyCLONe). 

Sources: https://ncsc.hr/hr/nacionalni-program-upravljanja-kibernetickim-krizama 
https://vlada.gov.hr/vijesti/vlada-donijela-nacionalni-program-upravljanja-kibernetickim-krizama/43627 
https://ncsc.hr/UserDocsImages/ostalo/National_Cyber_Crisis_Management_Programme.pdf 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 

Denmark flag
Denmark

NOST — National Operational Staff: NOST is Denmark's highest operational crisis coordination forum. NOST is activated when Denmark is affected by incidents requiring cross-sector coordination, including extreme weather, prolonged power outages, serious accidents, cyber incidents or attacks on critical infrastructure.

Sources: https://samsik.dk/krisestyring/nost/
https://politi.dk/om-politiet/samarbejde/den-nationale-operative-stab-nost

The Central Operational Communications Response Team (DCOK): DCOK supports NOST communicatively by coordinating communication efforts across the authorities. The purpose is to ensure that relevant, precise and coordinated action-oriented information about the incident is passed on to the public and the media as soon as possible.

Sources: https://samsik.dk/krisestyring/nost/
https://politi.dk/om-politiet/samarbejde/den-nationale-operative-stab-nost

National Crisis Management System: Denmark operates a structured national crisis-management system comprising local, regional and national crisis-management bodies. The framework is designed to support coordinated responses to disasters, hybrid threats, cyber incidents and other emergencies requiring cross-sector cooperation.

Sources: https://www.brs.dk/globalassets/brs---beredskabsstyrelsen/dokumenter/krisestyring-og-beredskabsplanlagning/2021/-crisis-management-in-denmark-.pdf
https://www.brs.dk/da/nyheder-og-publikationer/publikationer2/alle-publikationer/2021/crisis-management-in-denmark/

New joint 24/7 situation centre: The Danish Government announced the establishment of a 24/7 situation centre linked to NOST, alongside a national cyber operations centre and cyber monitoring network. These measures aim to strengthen detection, coordination, response and crisis management for cyber and hybrid threats.

Sources: https://mssb.dk/nyheder/nyhedsarkiv/2025/december/regeringen-nyt-faelles-247-situationscenter-i-lyset-af-hybridkrig/
https://mssb.dk/media/ywqbp0rh/baggrundsnotat.pdf

National Crisis Management Exercises: Denmark regularly conducts national crisis-management exercises to test and improve coordination between authorities, sectors and critical infrastructure operators. The 2025 National Crisis Management Exercise involved around 100 participants and simulated hybrid crisis scenarios.

Sources: https://samsik.dk/artikler/2025/11/national-krisestyringsoevelse-samler-100-aktoerer-fra-hele-samfundet/

Estonia flag
Estonia

Cyber crisis management and national coordination framework: Cyber incidents are integrated into Estonia's national crisis-management and contingency-planning system. The national risk assessment identifies dependencies between critical services, and RIA's cyber reserve provides specialist support when a major incident occurs. Public information is delivered through kriis.ee, the 1247 helpline, public broadcasting and EE-ALARM. 

Sources: https://www.riigikantselei.ee/en/national-risk-assessment/crisis-preparedness/estonias-activities-recent-years

Finland flag
Finland

Creating a national cyber crisis management framework: Developing and maintaining a national cyber crisis management plan, in accordance with the NIS2 requirements (ART9).

Sources: https://traficom.fi/fi/julkaisut/laajamittaisten-kyberturvallisuuspoikkeamien-ja-kriisien-hallinta-suomessa 

Integrating cybersecurity tighter into the Finnish Comprehensive security model and the Security Committee: Finland manages cyber crises through its comprehensive security model, in which the Security Committee coordinates preparedness across ministries and society. The revised Cyber Security Strategy makes cyber security an integral part of this model and, for the first time, adds response and countermeasures as a dedicated area, with objectives extending to 2035.

Sources: https://turvallisuuskomitea.fi/en/
Finland’s Cyber Security Strategy 2024–2035

 

Germany flag
Germany

BSI IT crisis management (IT-Krisenreaktionszentrum): The BSI's arrangements for managing IT crises of national significance. When the situation escalates beyond routine handling, the National IT Situation Centre and CERT-Bund transitions into the National IT Crisis Reaction Centre, coordinating the technical response across federal administration and critical-infrastructure operators and feeding the government's overall crisis management.

Sources: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Reaktion/reaktion_node.html 

LÜKEX national strategic crisis-management exercise: The cross-state and federal strategic crisis-management exercise series coordinated by the Federal Office of Civil Protection and Disaster Assistance (BBK). Held roughly every two years, it rehearses coordinated national responses to major hazards and has included large-scale cyber and IT-failure scenarios, testing decision-making and cooperation between the federal government and the Länder.

Sources: https://www.bbk.bund.de/DE/Themen/Krisenmanagement/Uebungen/LUEKEX/luekex_node.html 

Hungary flag
Hungary

National cyber crisis-management framework & EU-CyCLONe representation: Hungary's framework for managing large-scale cyber incidents and crises under the Cybersecurity Act (Act LXIX of 2024), transposing NIS2. The National Cyber Security Centre of Hungary (NCSC HU), within the Special Service for National Security (SSNS), acts as the national cyber crisis-management authority and single point of contact, coordinating the response to large-scale and cross-border incidents together with the national defence cybersecurity authority and the wider government crisis-management system. NCSC HU represents Hungary in the EU cyber crisis liaison organisation network (EU-CyCLONe); Hungary chaired EU-CyCLONe during its EU Council Presidency and took part in the executive-level BlueOLEx 2024 exercise, testing cross-border crisis coordination. Crisis-preparedness is further developed through Chapter V of the National Cybersecurity Action Plan (2025–2030).

Sources: https://en.nki.gov.hu/
https://nki.gov.hu/incidens/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
https://kormany.hu/dokumentumtar/nemzeti-kiberbiztonsagi-akcioterv-2025-2030

Liechtenstein flag
Liechtenstein

Cyber Crisis Organisation (Fachstab Cyber): Liechtenstein’s National Strategy for Protection Against Cyber Risks 2025 provides for the establishment of a national crisis organisation to manage large-scale cybersecurity incidents and crises. Under the “Cyber-Krisenorganisation” project, the National Cyber Security Unit (Stabsstelle Cyber-Sicherheit, SCS) developed a concept for a “Fachstab Cyber” (cyber expert staff) that fully takes into account the existing national command and crisis-management structures. The Government acknowledged the concept and mandated the SCS with its implementation, including the set-up of the Fachstab Cyber, as reported in the Government’s 2025 Accountability Report.

Sources: https://www.llv.li/serviceportal2/amtsstellen/stabstelle-regierungskanzlei/rb_2025_ii-01-praesidiales-finanzen-mpf-2025.pdf

Malta flag
Malta

Critical Infrastructure Protection Directorate: The Critical Infrastructure Protection Directorate provides services to promote cybersecurity information sharing across public administration, the private sector and society. It enables agreed procedures and information sharing tools, and establishes early warning systems as part of an operational and coordination framework for cybersecurity response. 

Sources: https://maltacip.gov.mt/en/services/ 
https://maltacip.gov.mt/servizzi/ 

CIP Unit: The CIP Unit coordinates national critical infrastructure protection and emergency management activities through sectoral coordination forums, Security Liaison Officers (SLOs), Emergency Liaison Officers (ELOs), information-sharing platforms, and national planning mechanisms. The unit supports preparedness, coordination, risk assessment, and the exercise of operator security plans across critical infrastructure and emergency organisations, while facilitating emergency management activities that incorporate both operational and cyber elements. 

Sources: https://maltacip.gov.mt/en/the-department/cip-unit/ 
https://maltacip.gov.mt/dipartimenti/cip-unit/ 

Malta National Emergency Plan: The National Emergency Plan sets out Malta’s national framework for emergency preparedness, coordination and response, including the roles and responsibilities of the entities involved in national emergency management. The plan is an all-hazards national emergency instrument and is not specific to cybersecurity, but provides the overarching national crisis management structure within which cyber incidents affecting critical infrastructure would be managed. 

Sources: https://sustainability.gov.mt/wp-content/uploads/2023/05/2019-Malta-Emergency-Plan.pdf 

Netherlands flag
Netherlands

National crisis-management structure for digital incidents: The national crisis structure provides the interministerial framework for decisions during major digital incidents. In practice, NCTV coordinates the wider crisis process, while NCSC-NL contributes cyber expertise, situational awareness and operational liaison. This division links strategic crisis management with the technical response to the incident. 

Source: https://www.nctv.nl/onderwerpen/n/nederlandse-cybersecuritystrategie-2022-2028 

National Crisis Plan Digital (Landelijk Crisisplan Digitaal): The National Crisis Plan Digital defines roles, information flows and escalation arrangements for large-scale digital incidents, giving public authorities, critical-sector organisations and crisis partners a common basis for coordination. The plan turns the national crisis structure into practical procedures that can be applied during an event. 

Source: https://www.nctv.nl/documenten/2022/12/23/landelijk-crisisplan-digitaal 

ISIDOOR national cyber-crisis exercise: ISIDOOR tests how government bodies and critical-sector partners apply national cyber-crisis arrangements under realistic conditions. Participants practise communication, decision-making, information exchange and escalation. As a result, the lessons from the exercise are used to identify gaps and improve crisis plans and procedures. 

Source: https://www.ncsc.nl/producten-en-diensten/isidoor 

Poland flag
Poland

National incident-response system and crisis coordination: Poland’s national cyber-crisis framework links the three national-level CSIRTs with the Government Centre for Security and strategic coordination by the Government Plenipotentiary for Cybersecurity. It provides a standing structure for escalation, inter-agency coordination and government response to serious incidents.

Sources: https://www.gov.pl/web/baza-wiedzy/nowelizacja-ustawy-o-krajowym-systemie-cyberbezpieczenstwa
https://www.gov.pl/web/rcb

Government Centre for Security (RCB) and EU-CyCLONe: The Government Centre for Security coordinates whole-of-government crisis management, while Poland participates in EU-CyCLONe for cross-border cyber-crisis coordination. Exercises and preparedness activities test communication, escalation and joint decision-making arrangements.

Sources: https://www.gov.pl/web/rcb
https://www.enisa.europa.eu/topics/eu-incident-response-and-cyber-crisis-management/eu-cyclone

Portugal flag
Portugal

National Plan for Response to Large Scale Cybersecurity Crises and Incidents: Article 13 of the Cybersecurity Legal Framework requires a national plan establishing the objectives and arrangements for managing large scale cybersecurity crises and incidents. The plan must be approved by a resolution of the Council of Ministers, remain coherent with Portugal’s general national crisis management frameworks, and be implemented and monitored by the National Cybersecurity Centre in close cooperation with the authorities represented in the cybersecurity crisis cabinet. Article 85 requires approval of the plan within six months following the entry into force of Decree Law No. 125/2025. 

Sources: https://files.diariodarepublica.pt/1s/2025/12/23400/0000400068.pdf 

Secretary General of the Internal Security System (SG-SSI): The Secretary General of the Internal Security System is designated as the national authority for managing large scale cybersecurity crises and incidents (Article 21). When a large-scale cybersecurity crisis or incident is declared, the Secretary General convenes the Cybersecurity Crisis Cabinet, which includes representatives of the Judicial Police, Security Intelligence Service, Strategic Defence Intelligence Service, National Cybersecurity Centre and Cyber Defence Operations Command. 

Sources: https://files.diariodarepublica.pt/1s/2025/12/23400/0000400068.pdf 

Cybersecurity Risk and Crisis Communication Framework: The Cybersecurity Risk and Crisis Communication Framework aims to support organizations in their communication in cybersecurity risk and crisis management.  This Framework was built to help organizations communicate in risk management processes and response to cybersecurity incidents, supporting the creation of communication plans to follow in crisis situations, listing steps, identifying essential professionals and functions in the communication team, and promoting the continuous improvement of the communication plans in place. 

Sources: https://www.cncs.gov.pt/en/referencial-de-comunicacao/ 
https://www.cncs.gov.pt/pt/referencial-de-comunicacao/ 

Risk Management Guide: The guide assists organisations in conducting cybersecurity risk management processes independently. It enables organisations to assess risks affecting information assets and determine security measures that can improve resilience. The guide provides practical support for implementing cybersecurity risk management activities. 

Sources: https://www.cncs.gov.pt/en/gestao-de-risco/ 
https://www.cncs.gov.pt/pt/gestao-de-risco/ 
https://www.cncs.gov.pt/docs/guia-de-gestao-dos-riscos.pdf 

Slovakia flag
Slovakia

National Response Plan for Large-scale Cybersecurity Incidents and Cyber Crises (Národný plán reakcie na rozsiahle kybernetické bezpečnostné incidenty a kybernetické krízy): The plan was developed pursuant to the amended National Cybersecurity Act and is intended to define preparedness measures, crisis management responsibilities, crisis response procedures, information exchange mechanisms, required resources, and coordination with EU level crisis management activities. Official government consultation documents show that the plan was submitted for review and approval in 2026. However, no public evidence was identified confirming that the plan entered into force or became operational.

Sources: https://www.slov-lex.sk/elegislativa/legislativne-procesy/SK/LP/2026/101

Cyber Crisis Management Function under the National Cybersecurity Act (Zákon o kybernetickej bezpečnosti

Amendments to the National Cybersecurity Act effective from 1 January 2025 introduced the concepts of cyber crises, a national response plan for cyber crises, and designate the National Security Authority as the authority responsible for cyber crisis management and coordination of large scale cybersecurity incidents and cyber crises. The legal framework exists, but implementation mechanisms remain dependent on the national response plan.

Sources: https://static.slov-lex.sk/pdf/SK/ZZ/2024/366/ZZ_2024_366_20250101.pdf

Slovenia flag
Slovenia

National Authority for Cyber Crisis Management: Slovenia has formally designated the Government Information Security Office (URSIV) as the authority responsible for managing large-scale cyber incidents and cyber crises. URSIV coordinates national response activities, informs the Government and the National Security Council when required, and serves as the national authority participating in the EU-CyCLONe network for cyber crisis coordination. 

Sources: https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/  

National Cyber Incident Response Plan (Nacionalni načrt odzivanja na kibernetske incidente – NOKI): Slovenia has adopted a National Cyber Incident Response Plan setting out incident classification, reporting thresholds, communication procedures, information sharing arrangements, escalation processes and crisis management phases. The framework covers preparation, detection, containment, mitigation, recovery and communication. 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Dokumenti/2022-03-NOKI.pdf 

https://pisrs.si/pregledPredpisa?id=ZAKO8934  

Participation in EU-CyCLONe and European Cyber Crisis Coordination: Slovenia participates in the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe), which supports cross-border coordination during major cyber incidents and cyber crises. URSIV acts as Slovenia’s representative within this framework and coordinates information exchange at European level. 

Sources: https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/information-and-cyber-security-division/  

National Cybersecurity Crisis Management Framework aligned with EU Cyber Blueprint: Slovenia formally supported the EU Cyber Blueprint initiative and recognised the need for a national cyber crisis response framework with clearly defined procedures, roles and escalation arrangements. Government sources note that ZInfV-1 provides the legal basis for crisis management roles and national crisis response arrangements. 

Sources: https://www.gov.si/novice/2025-04-17-slovenija-podprla-evropski-nacrt-za-krizno-upravljanje-kibernetske-varnosti/ 

National Communication Plan for Cybersecurity Incidents: Slovenia has adopted a National Communication Plan for responding to cyber incidents. The framework establishes communication responsibilities, public information procedures, incident communication levels, stakeholder coordination arrangements and cooperation between URSIV and the Government Communication Office (UKOM). 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/PR/Nacionalni-komunikacijski-nacrt-odzivanja-v-primeru-kibernetskih-incidentov_URSIV_UKOM.pdf 

Business Continuity and Crisis Preparedness Framework: Under ZInfV-1, organisations are required to establish business continuity and recovery arrangements. URSIV provides model documentation for business continuity policies and business continuity plans covering crisis situations, service disruptions, critical process recovery and resilience planning. 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Vzorcna-dokumentacija/4_POLITIKA-NEPREKINJENEGA-POSLOVANJA_ver_1.0.pdf 

Spain flag
Spain

National cyber crisis management (National Security Department, DSN): The Department of National Security (DSN) provides the permanent coordination and situation-management capability for national cyber crises within the National Security System. It supports inter-ministerial information exchange, escalation and activation of the competent national-security structures. 

Sources: https://www.dsn.gob.es/es/estructuras-de-seguridad-nacional/comites-especializados/consejo-nacional-de-ciberseguridad 
https://www.dsn.gob.es/es/estructuras-de-seguridad-nacional/comites-especializados/comite-de-situacion 

National Cybersecurity Council and Situation Committee: The National Cybersecurity Council directs cross-government cybersecurity coordination and advises the National Security Council. When a cyber incident escalates into a broader national-security crisis, the Situation Committee supports the strategic and political management of the response. 

Sources: https://www.dsn.gob.es/es/estructuras-de-seguridad-nacional/comites-especializados/consejo-nacional-de-ciberseguridad 
https://www.dsn.gob.es/es/estructuras-de-seguridad-nacional/comites-especializados/comite-de-situacion