NISG 2026 course All courses

Lesson 5.3 · 6 min

An example: ransomware on a Friday evening

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

A made-up example: a machinery maker with 180 staff, an important entity under Annex 2. An outside provider looks after its IT. This is how an incident can run under the rules from lessons 4.3, 5.1 and 5.2.

The timeline

WhenWhat happensBasis
Fri 19:30The night shift reports through the agreed channel: files on the server won't open, there is a ransom note.reporting channel, Annex point 3.3
Fri 20:15The IT provider confirms encryption. Affected systems are disconnected, logs secured.containment, evidence, point 3.5
Fri 21:00The management activates the crisis team and the continuity plan. The incident is now significant in any case; awareness at the latest now.§ 5(1) no. 9 NISV 2026
Fri 23:00Early warning through NIS2-Services to the national CSIRT: crime suspected, yes; customers in Germany, cross-border effects possible.§ 34(2) no. 1 NISG 2026
Sat 23:00The CSIRT's initial feedback at the latest; on request, advice and guidance on reporting to the police.§ 34(4)
Sat, SunRestoring from the offline backups in the order of the continuity plan: ERP and shipping first, then the rest.points 4.1, 4.2
Mon 9:00Customers with affected deliveries are informed, with what they can do.§ 34(3)
Mon 18:00Notification: initial assessment, severity, impact, indicators of compromise. Due by Mon 21:00 at the latest, 72 hours after becoming aware.§ 34(2) no. 2
by Mon + 1 monthFinal report: description, type of threat, root cause, remedies, effects abroad. If handling is still going on, a progress report instead.§ 34(2) nos. 4, 5

To check at the same time

Afterwards

The review finds: a phishing email led to credentials for remote access that still had no MFA. The lessons feed into the measures: MFA for all remote access, phishing training, remote maintenance only time-limited, a date for the next restore test (Implementing Regulation (EU) 2024/2690, Annex point 3.6). The management reviews the security policy and the risk assessment, as foreseen after every significant incident (points 1.1.2, 2.1.4).

What the example shows

The deadlines can only be met if it is settled beforehand who decides, who reports, how to get into the USP and where the contacts are. Awareness can't be put off by waiting for more precise information.

Checklist

Quiz

The notification went in on Monday at 18:00. When is the final report due if handling is finished by then?

  1. With the next self-declaration
  2. Within one month of the notification
  3. At the end of the calendar year
  4. Within 72 hours of the notification
Show the answer

The answer is B: Within one month of the notification. § 34(2) no. 4 NISG 2026: within one month of sending the notification; if handling is still going on, a progress report first (no. 5).

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.