Crisis Management Frameworks

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Crisis Management Frameworks

Crisis management is defined as ‘an institutional and organisational design process’, a ‘[broad] structure [that] encompasses decision-makers [with specific roles and actions]’. In general terms, crisis management is understood as ‘making and effecting difficult decisions under difficult circumstances. With NIS2, MS have to develop a specific framework for cyber crisis management – including processes for business continuity and disaster recovery, designate or establish one or more competent authorities responsible for the management of large-scale cybersecurity incidents and crises (cyber crisis management authorities). Member States shall ensure that those authorities have adequate resources to carry out, in an effective and efficient manner, the tasks assigned to them. Member States shall ensure coherence with the existing frameworks for general national crisis management

However, because cyber crises tend to have a transboundary nature, any cyber crisis management framework must remain part of an overarching crisis management for overall coherence. This overarching crisis management framework is an integral part of the cybersecurity strategy and it set the structures for preparing, responding and recovering from major incidents that involve critical infrastructure.

In addition, MS should organise regular exercises and crisis management simulations as part of their preparedness processes to respond to large-scale cyber crisis, often including of cross-border nature.

Organising Exercises and Simulations: National cybersecurity strategies should incorporate regular cybersecurity exercises to test emergency plans, identify vulnerabilities, and improve sector cooperation. These exercises foster resilience by simulating real-world threats, from cyber-attacks to natural disasters, and ensure that national response teams can effectively coordinate across sectors and borders.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

National Cyber Crisis Management Programme & Coordination for Cyber Crisis Management: Croatia's plan for handling a major cyberattack or cyber crisis, adopted by the Government on 9 January 2025 under the Cybersecurity Act. It sets out the resources, procedures and responsibilities for managing cyber crises across three levels - technical, operational, and strategic-political - aligned with the country's wider crisis-management system and the EU framework. It also establishes a new inter-agency body, the Coordination for Cyber Crisis Management, chaired by NCSC-HR, which brings together the key national authorities (intelligence, police, military, financial and telecom regulators, and others) to share information and coordinate the response. NCSC-HR also represents Croatia in the EU cyber crisis network (EU-CyCLONe). 

Sources: https://ncsc.hr/hr/nacionalni-program-upravljanja-kibernetickim-krizama 
https://vlada.gov.hr/vijesti/vlada-donijela-nacionalni-program-upravljanja-kibernetickim-krizama/43627 
https://ncsc.hr/UserDocsImages/ostalo/National_Cyber_Crisis_Management_Programme.pdf 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 

Denmark flag
Denmark

NOST — National Operational Staff: NOST is Denmark's highest operational crisis coordination forum. NOST is activated when Denmark is affected by incidents requiring cross-sector coordination, including extreme weather, prolonged power outages, serious accidents, cyber incidents or attacks on critical infrastructure.

Sources: https://samsik.dk/krisestyring/nost/
https://politi.dk/om-politiet/samarbejde/den-nationale-operative-stab-nost

The Central Operational Communications Response Team (DCOK): DCOK supports NOST communicatively by coordinating communication efforts across the authorities. The purpose is to ensure that relevant, precise and coordinated action-oriented information about the incident is passed on to the public and the media as soon as possible.

Sources: https://samsik.dk/krisestyring/nost/
https://politi.dk/om-politiet/samarbejde/den-nationale-operative-stab-nost

National Crisis Management System: Denmark operates a structured national crisis-management system comprising local, regional and national crisis-management bodies. The framework is designed to support coordinated responses to disasters, hybrid threats, cyber incidents and other emergencies requiring cross-sector cooperation.

Sources: https://www.brs.dk/globalassets/brs---beredskabsstyrelsen/dokumenter/krisestyring-og-beredskabsplanlagning/2021/-crisis-management-in-denmark-.pdf
https://www.brs.dk/da/nyheder-og-publikationer/publikationer2/alle-publikationer/2021/crisis-management-in-denmark/

New joint 24/7 situation centre: The Danish Government announced the establishment of a 24/7 situation centre linked to NOST, alongside a national cyber operations centre and cyber monitoring network. These measures aim to strengthen detection, coordination, response and crisis management for cyber and hybrid threats.

Sources: https://mssb.dk/nyheder/nyhedsarkiv/2025/december/regeringen-nyt-faelles-247-situationscenter-i-lyset-af-hybridkrig/
https://mssb.dk/media/ywqbp0rh/baggrundsnotat.pdf

National Crisis Management Exercises: Denmark regularly conducts national crisis-management exercises to test and improve coordination between authorities, sectors and critical infrastructure operators. The 2025 National Crisis Management Exercise involved around 100 participants and simulated hybrid crisis scenarios.

Sources: https://samsik.dk/artikler/2025/11/national-krisestyringsoevelse-samler-100-aktoerer-fra-hele-samfundet/

Hungary flag
Hungary

National cyber crisis-management framework & EU-CyCLONe representation: Hungary's framework for managing large-scale cyber incidents and crises under the Cybersecurity Act (Act LXIX of 2024), transposing NIS2. The National Cyber Security Centre of Hungary (NCSC HU), within the Special Service for National Security (SSNS), acts as the national cyber crisis-management authority and single point of contact, coordinating the response to large-scale and cross-border incidents together with the national defence cybersecurity authority and the wider government crisis-management system. NCSC HU represents Hungary in the EU cyber crisis liaison organisation network (EU-CyCLONe); Hungary chaired EU-CyCLONe during its EU Council Presidency and took part in the executive-level BlueOLEx 2024 exercise, testing cross-border crisis coordination. Crisis-preparedness is further developed through Chapter V of the National Cybersecurity Action Plan (2025–2030).

Sources: https://en.nki.gov.hu/
https://nki.gov.hu/incidens/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
https://kormany.hu/dokumentumtar/nemzeti-kiberbiztonsagi-akcioterv-2025-2030

Netherlands flag
Netherlands

National crisis-management structure for digital incidents: The national crisis structure provides the interministerial framework for decisions during major digital incidents. In practice, NCTV coordinates the wider crisis process, while NCSC-NL contributes cyber expertise, situational awareness and operational liaison. This division links strategic crisis management with the technical response to the incident. 

Source: https://www.nctv.nl/onderwerpen/n/nederlandse-cybersecuritystrategie-2022-2028 

National Crisis Plan Digital (Landelijk Crisisplan Digitaal): The National Crisis Plan Digital defines roles, information flows and escalation arrangements for large-scale digital incidents, giving public authorities, critical-sector organisations and crisis partners a common basis for coordination. The plan turns the national crisis structure into practical procedures that can be applied during an event. 

Source: https://www.nctv.nl/documenten/2022/12/23/landelijk-crisisplan-digitaal 

ISIDOOR national cyber-crisis exercise: ISIDOOR tests how government bodies and critical-sector partners apply national cyber-crisis arrangements under realistic conditions. Participants practise communication, decision-making, information exchange and escalation. As a result, the lessons from the exercise are used to identify gaps and improve crisis plans and procedures. 

Source: https://www.ncsc.nl/producten-en-diensten/isidoor