NISG 2026 course All courses

Lesson 4.3 · 7 min

Handling incidents, backups, keeping going

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Handling incidents

Point (b) requires incident handling § 32(4)(b) NISG 2026. Under the EU catalogue § 2 NISV 2026 this includes (Implementing Regulation (EU) 2024/2690, Annex point 3):

Business continuity

Point (c) requires business continuity, such as backup management and disaster recovery, and crisis management § 32(4)(c) NISG 2026:

Note the link to the reporting duty: if an incident leads to activating crisis management or a disaster recovery plan, the incident is significant in any case § 5(1) no. 9 NISV 2026 (lesson 5.1).

Checklist

Quiz

Where should backups be kept under the EU catalogue?

  1. At the managing director's home
  2. On a second drive in the same server
  3. Only in the IT provider's cloud
  4. At secure locations, not on the same network as the system and far enough from the main site
Show the answer

The answer is D: At secure locations, not on the same network as the system and far enough from the main site. Implementing Regulation (EU) 2024/2690, Annex point 4.2.2(c), through § 2 NISV 2026.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.