Insights

The 24-hour rule: what happens when a cyber incident hits

From the founder, Tromsø·19 July 2026·5 min read

NIS2 gives you a staged deadline when a serious incident hits: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month. It sounds simple on paper. During an actual incident, 24 hours is short.

What the clock actually requires

The deadlines are not three versions of the same report. They are three different jobs, under pressure, while operations may be down:

  • Within 24 hours, an early warning: that something serious has happened, whether it looks malicious, and whether it could have cross-border impact.
  • Within 72 hours, an incident notification with an initial assessment of severity and impact, and indicators of compromise.
  • Within one month, a final report with root cause, measures, and impact. If the incident is still ongoing, you submit a progress report first.
The point of a 24-hour deadline is not to have all the answers. It is to have notified, correctly, to the right recipient, while you are still handling the incident itself.

Where most companies come undone

Not on the technology. On the boring parts. Who has the authority to notify? Where do we send it? What actually counts as “serious”? Which facts must go in the first message, and which can wait? Without answers prepared, you spend the precious first hours working out who decides, instead of handling the incident.

Prepared means ready-made templates

The companies that meet the 24-hour deadline do not improvise. They have a ready notification template, a clear chain of responsibility, and a list of who is notified and how. Then the first hour is about filling in known fields, not about working out what the fields should be.

One important clarification: as of July 2026, NIS2 is not yet Norwegian law. What applies today is the Digital Security Act, which has its own notification requirements for covered entities. NIS2 sharpens and widens this. Whichever deadline ultimately applies to you, the point is the same: the readiness must exist before the incident, not be written during it.

What you can do now

  • Clarify who has the authority to notify, and who is the deputy.
  • Build a notification template with the fields an early warning requires.
  • Agree on what triggers a notification, the threshold for “serious”.
  • Have the contact paths to the authority, insurer, and key customers ready in advance.
  • Rehearse once. A one-hour tabletop reveals the gaps cheaply.

Is your incident readiness in place?

Havvakt builds notification templates and incident readiness as part of the compliance work, so you never start from a blank page. 30 minutes, no obligation, in Norwegian or English.

Book a call

Want to understand the requirements in full? Read the NIS2 guide.

Written by Havvakt's founder. Full name and bio once Havvakt is full-time. For now, the work speaks first.