NISG 2026 course All courses

Lesson 5.1 · 7 min

When an incident is significant

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

Incident and significant incident

A cyber security incident is an event that compromises the availability, authenticity, integrity or confidentiality of data or services § 3 no. 30 NISG 2026. You only have to report significant incidents. An incident is significant if it § 35(1) NISG 2026:

  1. has caused or can cause severe disruption of the entity's services or severe financial loss for it;
  2. has affected or can affect other natural or legal persons by causing considerable material or non-material damage.

The assessment takes into account, among other things, how far other sectors depend on your service, possible effects on the environment, safety and health, your market share, the area affected, the systems affected and how serious the threat is § 35(2) NISG 2026.

The NISV 2026's nine criteria

An incident is significant in any case if any one of these is met § 5(1) NISV 2026:

  1. a direct financial loss of more than €500,000 or 5% of the previous year's turnover, whichever is lower, has occurred or can occur;
  2. trade secrets or information that must be kept secret have leaked or can leak;
  3. a person has died or can die;
  4. serious harm to a person's health has occurred or can occur;
  5. there has been a successful, suspected malicious and unauthorised access to systems that is likely to cause severe disruption;
  6. the criteria for recurring incidents are met (§ 7);
  7. a service has been unavailable or limited for more than 100,000 users or 10% of users, whichever is lower, for more than 24 hours, or this can happen;
  8. a service has been unavailable or limited for users in at least one federal state for more than 24 hours, or this can happen;
  9. the incident has led to activating crisis management or disaster recovery plans.

"Can cause" means, according to the explanatory notes, that in the ordinary course of things the effect is to be expected soon. For no. 5 it isn't enough that disruption is possible; there must be more reasons for severe disruption than against. Direct losses include replacing hardware and software, staff and overtime, contractual penalties, compensation, lost revenue, communications, legal advice and forensics; they don't include fines, routine maintenance, routine training, improvements after the incident or insurance premiums. If the loss can't be determined exactly, it is estimated (notes on the NISV 2026).

What doesn't count, and what adds up

Incidents that aren't significant may still be reported

Incidents, cyber threats and near misses can be reported voluntarily § 37(1) NISG 2026, even without giving your identity § 37(3). Other reporting duties, such as for personal data breaches under the GDPR, are not affected (Federal Office, reporting duty and deadlines).

Checklist

Quiz

An attack leads to activating the disaster recovery plan; the damage is below €500,000. Is the incident significant?

  1. Yes, activating disaster recovery plans makes it significant in any case
  2. Only if customers are affected
  3. No, the loss threshold isn't reached
  4. Only if the CSIRT says so
Show the answer

The answer is A: Yes, activating disaster recovery plans makes it significant in any case. § 5(1) no. 9 NISV 2026: each of the nine criteria is enough on its own.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.