Incident Preparedness and Response

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Incident Preparedness and Response

Incident Preparedness and Response (IPR) is a critical strategic objective that focuses on establishing frameworks, protocols, and cooperation mechanisms to effectively manage and mitigate cybersecurity incidents. This objective encompasses a proactive approach to cybersecurity threats, integrating key activities such as incident handling, reporting, analysis, and response coordination at national and international levels. Central to IPR is the role of national/governmental CSIRTs (Computer Security Incident Response Teams), which serve as the main coordinating bodies for incident management, ensuring collaboration among public and private sector stakeholders. The strategy should identify the measures ensuring preparedness for, responsiveness to and recovery from incidents, including cooperation between the public and private sectors.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

National multi-CSIRT structure (NCSC-HR, CERT.hr) and national SOC: Croatia's operational incident-response architecture. Two national CSIRTs share responsibility by sector: NCSC-HR (within SOA) is the central authority, government CERT and CSIRT for the majority of NIS2 sectors, runs the national SOC, and coordinates all Croatian CSIRTs; CERT.hr (within CARNET) is the CSIRT for citizens, the private/public sector generally and five sectors (banking, financial market infrastructure, digital infrastructure/ccTLD registry, research, education); CERT.hr provides reactive (incident handling, coordination of significant incidents, warnings) and proactive services (advisories, monitoring, training). 

Sources: https://gov.hr/hr/nacionalni-cert/1230 
https://gov.hr/en/national-cert/1230 
https://www.cert.hr/csirt_specifikacija/ 

Incident-reporting mechanism (PiXi): The operational route for triggering national response and testing readiness. Categorised entities must notify significant incidents to their competent CSIRT via the national PiXi platform (early warning within 24h, notification within 72h, final report within 1 month, per the Regulation); if PiXi is unavailable, incidents are reported by submitting the official forms to the competent CSIRT by email, per NCSC-HR's General guidelines on significant-incident notification. Croatia also tests preparedness through EU exercises - in Cyber Europe 2024, CERT.hr acted as national coordinator, gathering 78 experts from companies and institutions (incl. HAKOM, Hrvatski Telekom, A1, SPAN, APIS-IT) to rehearse response to a simulated attack on critical infrastructure. 

Sources: 

https://ncsc.hr/hr/smjernice-i-upute 
https://www.carnet.hr/en/kiberneticka-vjezba-cyber-europe-2024/ 

Denmark flag
Denmark

SektorCERT: SektorCERT is the cybersecurity centre for Danish critical infrastructure sectors. It supports participating organisations through cyber threat intelligence sharing, threat assessments, cyber incident information exchange and a large-scale sensor network.

Sources: https://sektorcert.dk/

CSIRT International Cooperation through the Danish Defence Intelligence Service: Denmark's national CSIRT and Government CERT is placed in the Danish Defence Intelligence Service.. It provides warnings, threat information, incident handling support and cybersecurity services to government entities and operators of critical infrastructure, strengthening national incident preparedness and response capabilities.

Sources: https://tf-csirt.org/trusted-introducer/directory/teams/cfcs/
https://www.fe-ddis.dk/da/arbejdsomrade-a/Cybertruslen/

Hungary flag
Hungary

National CSIRT incident-handling capability - National Cyber Security Centre of Hungary (NCSC HU) :Hungary's national computer security incident response team, operated by the National Cyber Security Centre of Hungary (NCSC HU) within the Special Service for National Security (SSNS), is the central operational body for incident preparedness and response. It runs a 24/7 duty service receiving incident reports, provides reactive services (incident registration, reporter feedback, investigation, coordination of remediation, log analysis and root-cause reconstruction) and proactive services (vulnerability management, threat monitoring and advisories). It is the designated national CSIRT for all NIS2 sectors, DORA and critical infrastructure, participates in cyber-defence exercises, delivers training and awareness, cooperates with the central IT provider (NISZ Zrt.) and produces quarterly management reports. NCSC HU is FIRST-member and Trusted Introducer accredited.

Sources: https://nki.gov.hu/szolgaltatasok/tartalom/incidenskezeles/
https://en.nki.gov.hu/

Statutory incident-reporting mechanism (24h/72h/1-month) and exercise participation: The operational route for triggering national response, under the Cybersecurity Act (Act LXIX of 2024) and Government Decree 418/2024. In-scope entities must report significant incidents to the National Cyber Security Centre of Hungary (NCSC HU) through a three-phase timeline: an early warning within 24 hours, an incident notification within 72 hours (with severity/impact assessment and indicators of compromise), and a final report within one month; interim reports and immediate telephone notification are required for high-impact or large-scale incidents. Reports are submitted primarily through the dedicated NCSC HU reporting portal (incidens.nki.gov.hu), with anonymous reporting also available. Hungary tests preparedness through EU exercises, taking part in Cyber Europe 2024 (June 2024), which rehearsed response to a large-scale attack on the energy sector across the EU.

Sources: https://incidens.nki.gov.hu/
https://nki.gov.hu/intezet/tartalom/incidens-bejelentes/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
https://njt.jog.gov.hu/jogszabaly/2024-418-20-22

Netherlands flag
Netherlands

NCSC-NL national CSIRT and 24/7 incident response: NCSC-NL performs the national CSIRT function and remains available around the clock for serious cyber incidents. It provides technical analysis, advice, coordination and practical response support to eligible organisations and vital sectors. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

National Detection Network for early warning: The National Detection Network strengthens preparedness by sharing indicators and other detection information before or during an incident. Organisations can integrate these indicators into monitoring, prepare triage decisions and coordinate initial containment, shortening the time between receiving a warning and taking operational action. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

ISIDOOR preparedness exercises: ISIDOOR exercises test whether public and private partners can recognise, escalate and manage a national cyber crisis. In practice, the scenarios expose weaknesses in communication, decision-making and operational coordination. As a result, lessons are then used to improve plans, procedures and the readiness of participating organisations. 

Source: https://www.ncsc.nl/producten-en-diensten/isidoor