Incident Preparedness and Response

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Incident Preparedness and Response

Incident Preparedness and Response (IPR) is a critical strategic objective that focuses on establishing frameworks, protocols, and cooperation mechanisms to effectively manage and mitigate cybersecurity incidents. This objective encompasses a proactive approach to cybersecurity threats, integrating key activities such as incident handling, reporting, analysis, and response coordination at national and international levels. Central to IPR is the role of national/governmental CSIRTs (Computer Security Incident Response Teams), which serve as the main coordinating bodies for incident management, ensuring collaboration among public and private sector stakeholders. The strategy should identify the measures ensuring preparedness for, responsiveness to and recovery from incidents, including cooperation between the public and private sectors.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

CERT.be incident response and urgent assistance: CERT.be, one of the two operational departments of Belgium’s national CSIRT, analyses, contains, mitigates and helps eradicate cyberattacks. It provides second-line technical expertise to essential entities and Belgian public administrations; important entities may receive limited best-effort assistance. Incident email intake operates during published office hours, while urgent telephone assistance is available 24/7, in cooperation with the National Crisis Centre, for NIS2 incidents and critical infrastructure.

Sources: https://ccb.belgium.be/cert
https://ccb.belgium.be/cert/report-incident

National and European cyber-crisis exercises: The CCB and National Crisis Centre test and refine Belgium’s cyber-crisis procedures through national and European exercises. A national tabletop exercise on 23 October 2025 simulated ransomware and telecommunications disruption in the energy sector to test decision-making, communication and information exchange. During Cyber Europe 2026, Belgium tested incident notification, triage, national crisis procedures and coordination with the CSIRTs Network and EU-CyCLONe in a cross-border rail and maritime scenario.

Sources: https://ccb.belgium.be/news/national-cyber-crisis-exercise-tests-cooperation-communication-and-response
https://ccb.belgium.be/news/belgium-tests-cyber-crisis-response-during-cyber-europe-2026

 

Croatia flag
Croatia

National multi-CSIRT structure (NCSC-HR, CERT.hr) and national SOC: Croatia's operational incident-response architecture. Two national CSIRTs share responsibility by sector: NCSC-HR (within SOA) is the central authority, government CERT and CSIRT for the majority of NIS2 sectors, runs the national SOC, and coordinates all Croatian CSIRTs; CERT.hr (within CARNET) is the CSIRT for citizens, the private/public sector generally and five sectors (banking, financial market infrastructure, digital infrastructure/ccTLD registry, research, education); CERT.hr provides reactive (incident handling, coordination of significant incidents, warnings) and proactive services (advisories, monitoring, training). 

Sources: https://gov.hr/hr/nacionalni-cert/1230 
https://gov.hr/en/national-cert/1230 
https://www.cert.hr/csirt_specifikacija/ 

Incident-reporting mechanism (PiXi): The operational route for triggering national response and testing readiness. Categorised entities must notify significant incidents to their competent CSIRT via the national PiXi platform (early warning within 24h, notification within 72h, final report within 1 month, per the Regulation); if PiXi is unavailable, incidents are reported by submitting the official forms to the competent CSIRT by email, per NCSC-HR's General guidelines on significant-incident notification. Croatia also tests preparedness through EU exercises - in Cyber Europe 2024, CERT.hr acted as national coordinator, gathering 78 experts from companies and institutions (incl. HAKOM, Hrvatski Telekom, A1, SPAN, APIS-IT) to rehearse response to a simulated attack on critical infrastructure. 

Sources: 

https://ncsc.hr/hr/smjernice-i-upute 
https://www.carnet.hr/en/kiberneticka-vjezba-cyber-europe-2024/ 

Denmark flag
Denmark

SektorCERT: SektorCERT is the cybersecurity centre for Danish critical infrastructure sectors. It supports participating organisations through cyber threat intelligence sharing, threat assessments, cyber incident information exchange and a large-scale sensor network.

Sources: https://sektorcert.dk/

CSIRT International Cooperation through the Danish Defence Intelligence Service: Denmark's national CSIRT and Government CERT is placed in the Danish Defence Intelligence Service.. It provides warnings, threat information, incident handling support and cybersecurity services to government entities and operators of critical infrastructure, strengthening national incident preparedness and response capabilities.

Sources: https://tf-csirt.org/trusted-introducer/directory/teams/cfcs/
https://www.fe-ddis.dk/da/arbejdsomrade-a/Cybertruslen/

Estonia flag
Estonia

CERT-EE incident response: CERT-EE monitors Estonian cyberspace and coordinates the response to incidents affecting public authorities and essential services. It also provides additional protection for the state network, including measures against denial-of-service attacks. RIA's operations centre supports this work through continuous monitoring of government systems and is expanding towards a government security operations centre. 

Sources: https://www.ria.ee/en/what-expect-cyberspace-2026
https://www.ria.ee/en/cyber-security/handling-cyber-incidents-cert-ee

National cyber exercises and preparedness: RIA also organises national cyber exercises to test preparedness for serious incidents. In practice, Cyber Reserve 2025, conducted with the electricity system operator Elering, simulated an attack on the power supply. Another exercise with PERH and CR14 tested the response to a cyber incident in a hospital.

Sources: https://www.ria.ee/en/cyber-security/cyber-defence-critical-infrastructure/preparedness-crises-and-cyber-exercises

Fraud-prevention awareness and public guidance: Estonia applies a multi-stakeholder approach to fraud prevention, combining the efforts of law-enforcement authorities, financial-sector organisations and public agencies. Regular awareness activities by the Police and Border Guard Board, the Estonian Banking Association, the Financial Supervision Authority and other partners address phishing, investment scams, payment fraud and social engineering. These initiatives strengthen practical digital behaviour and societal resilience against cyber-enabled fraud.

Sources: https://www.politsei.ee/et/juhend/kelmused
https://www.politsei.ee/et/juhend/kuberkuriteod
https://pangaliit.ee/
https://www.fi.ee/et/hoiatused

Finland flag
Finland

Implementing and developing cyber incident response and situational awareness (NCSC-FI): As the national CSIRT, the NCSC-FI receives and analyses reports, coordinates the handling of incidents, issues alerts and advisories, and supports affected organisations in recovery. It maintains the operational capability that underpins Finland's incident preparedness and response.

Sources: https://www.kyberturvallisuuskeskus.fi/en/our-services/monitoring-and-incident-response

Organising four annual national cyber exercises (KYHA exercises): Four annual national cyber exercises (KYHA exercises) are aimed to municipality and critical infrastructure organizations, Finnish state administration organizations, security authorities and healthcare organizations. The Ministry of Transport and Communications enables the national cyber exercises, and Security Committee assists in coordination and implementation of exercises.

Sources: https://valtioneuvosto.fi/-/1410829/turvallisuusviranomaisten-kyberharjoitus-vahvisti-valmiuksia-valtiollista-kybervaikuttamista-vastaan?languageId=en_US
https://jyvsectec.fi/en/national-cyber-exercises/

Organising national cybersecurity exercises, such as TAISTO and TIETO: The NCSC-FI organises the recurring TAISTO exercise series, in which public- and private-sector organisations rehearse their response to data-security and data-protection incidents. The exercises test procedures, cooperation and notification obligations, improving national readiness.
The TIETO exercise is organised by the National Emergency Supply Organisation NESO.

Sources: https://dvv.fi/taisto
https://teknologiateollisuus.fi/digipooli/en/tieto26-exercise-puts-the-focus-on-crisis-preparedness-in-food-sector/ 

Maintaining HAVARO national monitoring and early-warning system: HAVARO is the NCSC-FI's national detection capability for serious information-security threats, especially for critical-infrastructure providers and central government. Sensors detect malicious or abnormal network traffic and the NCSC-FI analyses the anomalies and warns affected organisations. Originally launched in 2011, it is continuously modernised. The service is jointly provided with commercial security operations centres and financed by the National Emergency Supply Agency; the complementary Autoreporter system tackles malware traffic with telecommunications operators.

Sources: https://www.kyberturvallisuuskeskus.fi/fi/palvelumme/havainnointi-ja-avunanto/havaro

Germany flag
Germany

CERT-Bund incident response: The Computer Emergency Response Team for Germany's federal authorities - CERT-Bund - receives and analyses reports, correlates them with the national situation picture, issues targeted warnings and guidance, and coordinates the handling of incidents with affected federal bodies, operators and international partners on a 24/7 basis.

Sources: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Reaktion/CERT-Bund/cert-bund_node.html 

BSI Mobile Incident Response Teams (MIRT): Specialist teams that the BSI can deploy to support federal authorities and critical-infrastructure operators during severe cyber incidents. The MIRTs assist on site with analysis, containment and recovery, strengthening national response capacity beyond remote coordination.

Sources: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Reaktion/reaktion_node.html 

Hungary flag
Hungary

National CSIRT incident-handling capability - National Cyber Security Centre of Hungary (NCSC HU) :Hungary's national computer security incident response team, operated by the National Cyber Security Centre of Hungary (NCSC HU) within the Special Service for National Security (SSNS), is the central operational body for incident preparedness and response. It runs a 24/7 duty service receiving incident reports, provides reactive services (incident registration, reporter feedback, investigation, coordination of remediation, log analysis and root-cause reconstruction) and proactive services (vulnerability management, threat monitoring and advisories). It is the designated national CSIRT for all NIS2 sectors, DORA and critical infrastructure, participates in cyber-defence exercises, delivers training and awareness, cooperates with the central IT provider (NISZ Zrt.) and produces quarterly management reports. NCSC HU is FIRST-member and Trusted Introducer accredited.

Sources: https://nki.gov.hu/szolgaltatasok/tartalom/incidenskezeles/
https://en.nki.gov.hu/

Statutory incident-reporting mechanism (24h/72h/1-month) and exercise participation: The operational route for triggering national response, under the Cybersecurity Act (Act LXIX of 2024) and Government Decree 418/2024. In-scope entities must report significant incidents to the National Cyber Security Centre of Hungary (NCSC HU) through a three-phase timeline: an early warning within 24 hours, an incident notification within 72 hours (with severity/impact assessment and indicators of compromise), and a final report within one month; interim reports and immediate telephone notification are required for high-impact or large-scale incidents. Reports are submitted primarily through the dedicated NCSC HU reporting portal (incidens.nki.gov.hu), with anonymous reporting also available. Hungary tests preparedness through EU exercises, taking part in Cyber Europe 2024 (June 2024), which rehearsed response to a large-scale attack on the energy sector across the EU.

Sources: https://incidens.nki.gov.hu/
https://nki.gov.hu/intezet/tartalom/incidens-bejelentes/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
https://njt.jog.gov.hu/jogszabaly/2024-418-20-22

Liechtenstein flag
Liechtenstein

CSIRT.LI: CSIRT.LI serves as Liechtenstein's national Computer Security Incident Response Team under the NIS framework. It functions as the national coordinator for cybersecurity incidents and provides incident triage, incident coordination and incident-resolution support. CSIRT.LI operates incident-notification channels, supports essential and important entities, issues warnings and alerts, produces situational information based on reported incidents, and assists organisations in responding to cybersecurity incidents.

Sources: https://www.llv.li/en/national-administration/national-cyber-security-unit/csirt
https://www.llv.li/de/landesverwaltung/stabsstelle-cybersicherheit/csirt

TIBER-EU LI (Financial Sector): The Financial Market Authority (FMA) adopted TIBER-EU LI as the national implementation of the European threat-led penetration testing framework for financial intermediaries. According to the FMA, the framework is used to assess preparedness for handling ICT-related incidents, identify weaknesses and gaps in digital operational resilience, test cyber-defence capabilities through realistic attack scenarios, and improve operational readiness and resilience within the financial sector.

Sources: https://www.fma-li.li/en/supervision-regulation/dora/tiber-eu-li
https://www.fma-li.li/fma-li/documents/rechtsgrundlagen/mitteilungen/fma-mitteilung-2025-3-en.pdf

Malta flag
Malta

CSIRT Malta incident preparedness and response capabilities: CSIRT Malta monitors and analyses cyber threats, vulnerabilities and incidents at national level, provides early warnings, alerts and announcements, responds to incidents, provides assistance to affected entities, performs dynamic risk and incident analysis, and provides situational awareness regarding cybersecurity. 

Sources: https://maltacip.gov.mt/en/the-department/csirtmalta/ 
https://maltacip.gov.mt/dipartimenti/disclamer/ 

Cyber Threat Intelligence Team (CTI) and govmtCSIRT: The Cyber Threat Intelligence Team and govmtCSIRT collect, collate and analyse cyber threat information, coordinate threat-hunting activities, maintain a central threat intelligence repository, disseminate cyber threat intelligence to stakeholders, and coordinate activities with Maltese and international CSIRTs and CERTs. 

Sources: https://mita.gov.mt/portfolio/cyber-threat-intelligence-team-cti-and-government-computer-security-incident-response-team-govmtcsirt/ 

Netherlands flag
Netherlands

NCSC-NL national CSIRT and 24/7 incident response: NCSC-NL performs the national CSIRT function and remains available around the clock for serious cyber incidents. It provides technical analysis, advice, coordination and practical response support to eligible organisations and vital sectors. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

National Detection Network for early warning: The National Detection Network strengthens preparedness by sharing indicators and other detection information before or during an incident. Organisations can integrate these indicators into monitoring, prepare triage decisions and coordinate initial containment, shortening the time between receiving a warning and taking operational action. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

ISIDOOR preparedness exercises: ISIDOOR exercises test whether public and private partners can recognise, escalate and manage a national cyber crisis. In practice, the scenarios expose weaknesses in communication, decision-making and operational coordination. As a result, lessons are then used to improve plans, procedures and the readiness of participating organisations. 

Source: https://www.ncsc.nl/producten-en-diensten/isidoor 

Poland flag
Poland

CERT Polska incident response and technical assistance: CERT Polska provides technical incident assistance for citizens and organisations within its constituency. It receives and triages reports, coordinates handling with affected and partner entities, analyses malware and indicators, advises on mitigation and uses findings to warn other organisations exposed to the same threat.

Sources: https://cert.pl/en/
https://incydent.cert.pl/

KSC-EXE national cybersecurity exercises: The Ministry of Digital Affairs and the Government Plenipotentiary for Cybersecurity use the recurring KSC-EXE tabletop exercise to test the National Cybersecurity System under simulated cyber-crisis conditions. KSC-EXE 2025 involved more than 100 representatives from competent ministries, all three national-level CSIRTs, sectoral CSIRTs, the Government Centre for Security, prosecutors, the telecom regulator and CBZC. The exercise tested communication, incident escalation, inter-agency coordination, response procedures and alignment with the amended KSC/NIS2 framework.

Sources: https://www.gov.pl/web/baza-wiedzy/ksc-exe-2025-cwiczenia-krajowego-systemu-cyberbezpieczenstwa

Portugal flag
Portugal

Portuguese CSIRTs Network (Rede Nacional de CSIRT – RNCSIRT): RNCSIRT is Portugal’s operational forum for sharing incident information and coordinating response among CSIRTs from different sectors. The network establishes trusted relationships for cooperation and mutual assistance in incident handling, develops national incident indicators, supports proactive and reactive countermeasures, and creates instruments for prevention and rapid response during large-scale incidents. 

Sources: https://www.cncs.gov.pt/en/csirt/ 
https://www.redecsirt.pt/ 

CERT.PT: CERT.PT is Portugal's national cybersecurity incident response team, integrated within within National Cybersecurity Centre (CNCS). It coordinates cybersecurity incident response involving public administration, essential and important entities, and the wider national cyberspace. CERT.PT also represents Portugal in the European CSIRTs Network. 

Sources: https://www.cncs.gov.pt/en/certpt/ 
https://www.cncs.gov.pt/pt/certpt/ 

National Cybersecurity Exercise (ExNCS): CNCS plans and conducts ExNCS to develop national capabilities for preventing, monitoring, detecting, reacting to, analysing and correcting cybersecurity incidents and cyberattacks. The exercise trains participating entities, tests preparedness and cooperation, and uses real-time incident scenarios. 

Sources: https://www.cncs.gov.pt/pt/exercicio-nacional-ciberseguranca/ 
https://www.cncs.gov.pt/en/national-cybersecurity-exercise/ 

Incident Response: Minimum Capabilities: CNCS provides a five-phase model for developing minimum technical, human and procedural incident-response capabilities. 

Sources: https://www.cncs.gov.pt/pt/certpt/roadmap/ 
https://www.cncs.gov.pt/docs/ir-modelo-maturidade-pt-2018pdf.pdf 

Slovakia flag
Slovakia

National Cybersecurity Incident Management System in Public Administration: National project aimed at enhancing SK-CERT infrastructure capacities and establishing specialised facilities for the comprehensive management of cybersecurity incidents in line with the statutory responsibilities of CSIRT units.

Sources: https://www.nbu.gov.sk/narodny-projekt-narodny-system-riadenia-incidentov-kybernetickej-bezpecnosti-vo-verejnej-sprave/

National Cyber Security Centre SK-CERT (Národné centrum kybernetickej bezpečnosti SK-CERT): SK-CERT, established by National Security Authority,   provides national and strategic activities in the field of cyber security management, threat analysis as well as coordination of national security incident resolution. The National Cyber Security Centre also aids governance, development, management and support of cyber security competence centers, including training, educational activities, and research.

Sources: https://www.sk-cert.sk/en/about-us/index.html
https://www.sk-cert.sk/sk/o-nas/index.html

Government CSIRT.SK: CSIRT.SK (Computer Incident Response Team) is part of Cyber Security department at the Ministry of Investment, Regional Development and Informatisation of the Slovak Republic. It provides services related to incident handling processes and restoration of the informational and communication systems in the public sector, and also offers preventive and educational services. The role and tasks of the teams are also embedded in the National Cybersecurity Act.

Historically, it was established by Resolution of the Government of the Slovak Republic No. 479/2009 of 1 July 2009

Sources: https://mirri.gov.sk/en/sections/informatization/csirt/about-csirt/
https://www.csirt.sk/o-nas.html

Kyber2025 Conference and Incident Response Training Activities (Konferencia Kyber2025 – Čo sa deje a čo nás čaká?): SK-CERT and the National Security Authority organised cybersecurity preparedness activities in 2025, including sessions on ransomware incident response and incident handling, as well as practical technical workshops covering detection, monitoring, vulnerability management and response capabilities. These activities support preparedness and capability development for handling cybersecurity incidents.

Sources: https://www.sk-cert.sk/sk/kyber2025-co-sa-deje-a-co-nas-caka/index.html

Slovenia flag
Slovenia

National Cyber Incident Response Plan (NOKI): Slovenia has adopted a National Cyber Incident Response Plan (NOKI), which establishes incident classification, reporting procedures, escalation mechanisms, communication arrangements and response phases including preparation, detection, containment, mitigation and recovery. 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Dokumenti/2022-03-NOKI.pdf 

https://pisrs.si/pregledPredpisa?id=ZAKO8934  

National CSIRT Capability (SI-CERT and SIGOV-CERT): Slovenia operates dedicated CSIRT capabilities through SI-CERT and SIGOV-CERT, which receive incident reports, provide technical assistance, support incident management and coordinate response activities. SI-CERT serves organisations and the wider public, while SIGOV-CERT supports public administration entities. 

Sources: https://www.cert.si/prijava-incidenta/ 

https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/sigov-cert-division/   

Incident Response Plans and CSIRT Notification Protocol Templates: URSIV provides model documentation including a dedicated “Incident Response Plan with CSIRT Notification Protocol”. The template supports organisations in defining response teams, roles, responsibilities, escalation procedures, detection mechanisms and communication processes. 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Vzorcna-dokumentacija/6_NACRT-ODZIVANJA-NA-INCIDENTE_ver_1.0.pdf 

Training on Incident Preparedness and Response Planning: URSIV conducts workshops and training programmes on incident preparedness, response planning and development of documented incident response systems. Training covers detection, classification, notification, response procedures, responsibilities and post-incident analysis. 

Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Dogodki/Seminarji-z-ENISO/M8-Nacrti-odzivanja-in-pripravljenost.pdf 

SI-CERT Incident Handling and Technical Support Service: SI-CERT provides operational support during incidents, including assistance with investigation, incident analysis, malware analysis and mitigation advice. Organisations can submit incidents along with logs, malicious files and technical evidence for analysis. 

Sources: https://www.cert.si/prijava-incidenta/ 

Spain flag
Spain

INCIBE-CERT incident response for businesses and citizens: INCIBE-CERT provides the national incident-reporting and response channel for businesses, citizens and other entities in its constituency. It triages notifications, assesses impact and urgency, supports containment and mitigation, and coordinates affected parties through Spain’s incident-management framework. 

Sources: https://www.incibe.es/en/incibe-cert/publications/guides-and-studies/guides/spanish-national-guidelines-reporting-and-managing-cyber-incidents 

CCN-CERT incident response for public-sector systems: CCN-CERT leads incident handling for public administrations and other organisations within its remit. Its early-warning, reporting and technical-assistance capabilities support detection, assessment, containment and coordinated response while providing a central exchange point for public-sector incident information. 

Sources: https://www.ccn-cert.cni.es/en/incident-management.html 

CSIRT-MIR-PJ cyber incident response, evidence preservation and cybercrime investigation: The link between a cyberattack and the resulting cybercrime, together with its challenges, such as translating initial evidence into legally admissible evidence before a court, preserving evidence during the urgent mitigation phase when there is a risk of its destruction, ensuring agile information exchange among the targeted entity, CSIRTs, LEAs, and other stakeholders, as well as conducting threat hunting activities and issuing rapid alerts, constitutes one of the core responsibilities of the CSIRT-MIR-PJ, which operates within the Cybersecurity Coordination Office. 

Sources: https://occ.ses.mir.es/publico/occ/laOCC.html