Lesson 5.3 · 6 min
An example: ransomware on a Friday evening
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- The file server is encrypted. A medium-sized machinery maker, an important entity. Planning has stopped, and a ransom note is on the screen.
- Crisis team activated: significant. With crisis management activated, the incident is significant in any case. The 24 hours run from becoming aware.
- Early warning to the national CSIRT. Short: what is known, a suspected crime, possible effects abroad. On Saturday the CSIRT responds with initial feedback.
- Notification with an initial assessment. Within 72 hours of becoming aware: severity, impact, indicators of compromise. Customers with delayed deliveries have been informed.
- Final report. Root cause: phishing and remote access without MFA. What has been fixed, what is ongoing, and what the review has changed.
In detail
A made-up example: a machinery maker with 180 staff, an important entity under Annex 2. An outside provider looks after its IT. This is how an incident can run under the rules from lessons 4.3, 5.1 and 5.2.
The timeline
| When | What happens | Basis |
|---|---|---|
| Fri 19:30 | The night shift reports through the agreed channel: files on the server won't open, there is a ransom note. | reporting channel, Annex point 3.3 |
| Fri 20:15 | The IT provider confirms encryption. Affected systems are disconnected, logs secured. | containment, evidence, point 3.5 |
| Fri 21:00 | The management activates the crisis team and the continuity plan. The incident is now significant in any case; awareness at the latest now. | § 5(1) no. 9 NISV 2026 |
| Fri 23:00 | Early warning through NIS2-Services to the national CSIRT: crime suspected, yes; customers in Germany, cross-border effects possible. | § 34(2) no. 1 NISG 2026 |
| Sat 23:00 | The CSIRT's initial feedback at the latest; on request, advice and guidance on reporting to the police. | § 34(4) |
| Sat, Sun | Restoring from the offline backups in the order of the continuity plan: ERP and shipping first, then the rest. | points 4.1, 4.2 |
| Mon 9:00 | Customers with affected deliveries are informed, with what they can do. | § 34(3) |
| Mon 18:00 | Notification: initial assessment, severity, impact, indicators of compromise. Due by Mon 21:00 at the latest, 72 hours after becoming aware. | § 34(2) no. 2 |
| by Mon + 1 month | Final report: description, type of threat, root cause, remedies, effects abroad. If handling is still going on, a progress report instead. | § 34(2) nos. 4, 5 |
To check at the same time
- Data protection: if personal data is affected, the duty to notify the data protection authority under Art. 33 GDPR also applies, within 72 hours. The NIS report doesn't replace it (Federal Office, reporting duty and deadlines).
- Other countries: a report in Austria doesn't automatically meet reporting duties in other countries (FAQ on reporting).
- Recurrence: were there incidents with the same cause in the last six months? § 7 NISV 2026
Afterwards
The review finds: a phishing email led to credentials for remote access that still had no MFA. The lessons feed into the measures: MFA for all remote access, phishing training, remote maintenance only time-limited, a date for the next restore test (Implementing Regulation (EU) 2024/2690, Annex point 3.6). The management reviews the security policy and the risk assessment, as foreseen after every significant incident (points 1.1.2, 2.1.4).
What the example shows
The deadlines can only be met if it is settled beforehand who decides, who reports, how to get into the USP and where the contacts are. Awareness can't be put off by waiting for more precise information.
Checklist
- We have walked through our process once with an example like this.
- Who activates the crisis team is settled, and everyone knows the 24 hours then run.
- Our offline backups are enough to restore ERP and shipping in a weekend.
- With every incident we also check the reporting duty under Art. 33 GDPR.
- After every significant incident there is a review, and its results feed into the measures.
Quiz
The notification went in on Monday at 18:00. When is the final report due if handling is finished by then?
- With the next self-declaration
- Within one month of the notification
- At the end of the calendar year
- Within 72 hours of the notification
Show the answer
The answer is B: Within one month of the notification. § 34(2) no. 4 NISG 2026: within one month of sending the notification; if handling is still going on, a progress report first (no. 5).
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 34, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 5, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 7, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Federal Office for Cyber Security: reporting duty and deadlines, in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: reporting, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.