{"id":6025,"date":"2024-10-04T15:27:00","date_gmt":"2024-10-04T13:27:00","guid":{"rendered":"https:\/\/m2apartners.cz\/cybersecurity-part-three-incidents\/"},"modified":"2025-03-27T17:06:06","modified_gmt":"2025-03-27T16:06:06","slug":"cybersecurity-part-three-incidents","status":"publish","type":"post","link":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/","title":{"rendered":"Cybersecurity, Part Three &#8211; Incidents"},"content":{"rendered":"\n<p>Previous parts of this series have focused on entities and their obligations under the new draft Cybersecurity Act. This time we will discuss how cyber security incidents should be reported and managed under the draft law. <\/p>\n\n<h5 class=\"wp-block-heading\">Cyber security incident reporting and management<\/h5>\n\n<p>Within the same timeframe, i.e. no later than 1 year from the delivery of the registration decision, the provider will be obliged to report and manage cyber security incidents. We will address these obligations in the next installment of this series. <\/p>\n\n<p>A provider under the higher obligations regime will have to report to the NUCIB all cyber security incidents where intentional culpability cannot be excluded. The provider under the lower obligation regime will report to the National CERT those incidents that have a significant impact and for which intentional culpability cannot be excluded. Reports will be made via the NCIB Portal.  <\/p>\n\n<h5 class=\"wp-block-heading\">How to report incidents?<\/h5>\n\n<ol class=\"wp-block-list\">\n<li><strong>Initial report <\/strong>&#8211; will need to be made without undue delay, within 24 hours at the latest, and should include identifying details, basic information about the incident and whether it may have been caused by unlawful interference or could have a cross-border impact\n<ul class=\"wp-block-list\">\n<li>In the case of a provider in the higher duty regime, which will report all incidents, the NUCIB will indicate whether the incident has a significant impact. If it does not have a significant impact, this step ends the process. <\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Notification <\/strong>&#8211; submitted by the provider within 72 hours, this will be an update of information and initial assessment of the incident and the impact and indicators of compromise.<\/li>\n\n\n\n<li><strong>Interim report<\/strong> &#8211; the provider shall submit this at the request of NUCIB or the National CERT and shall indicate significant changes in the status of incident management.<\/li>\n\n\n\n<li><strong>Final<\/strong> Incident Resolution <strong>Report<\/strong> &#8211; will be required to be submitted within 30 days of notification.\n<ul class=\"wp-block-list\">\n<li>If the incident is still ongoing after this 30-day period, the provider shall submit an interim report on the current status of incident management. It shall then submit a final report within 30 days of the date of resolution of the incident. <\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<h5 class=\"wp-block-heading\">Incident management<\/h5>\n\n<p>The National CERT or NUCIB shall provide a statement on the incident without undue delay. The provider will be obliged to provide the necessary information and cooperation. Upon request, the NCIB shall provide methodological or technical support for the management of the incident.  <\/p>\n\n<p>The provider will also be obliged to keep records of data on cybersecurity incidents, events, threats and vulnerabilities.<\/p>\n\n<h5 class=\"wp-block-heading\">Countermeasures<\/h5>\n\n<p>The NCIB may propose appropriate countermeasures in relation to cyber incidents, events, threats and vulnerabilities:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>alert = informing the public about an incident or a breach of an obligation under the Cybersecurity Act by the NCSC or the provider,<\/li>\n\n\n\n<li>Warning = issued by NUCIB in the event of a serious threat or vulnerability,<\/li>\n\n\n\n<li>reactive countermeasures = to be carried out by the provider at the request of the NUCIB.<\/li>\n<\/ul>\n\n<p><strong><em><span style=\"text-decoration: underline;\">The bill is currently in its first reading in the Chamber of Deputies.<\/span><\/em><\/strong><\/p>\n\n<p><\/p>\n\n<p>If you would like more information in this regard, please do not hesitate to contact us.<\/p>\n\n<p>This article is for informational purposes only and does not constitute legal advice or guidance for any particular case.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Previous parts of this series have focused on entities and their obligations under the new draft Cybersecurity Act. This time we will discuss how cyber security incidents should be reported and managed under the draft law. Cyber security incident reporting and management Within the same timeframe, i.e. no later than 1 year from the delivery [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5609,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[320],"tags":[373,358,344,384,572,370],"class_list":["post-6025","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","tag-cybernetics","tag-eu-legislation","tag-legislation","tag-proposal","tag-protection","tag-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cybersecurity, Part Three - Incidents - m2apartners.cz<\/title>\n<meta name=\"description\" content=\"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity, Part Three - Incidents - m2apartners.cz\" \/>\n<meta property=\"og:description\" content=\"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal\" \/>\n<meta property=\"og:url\" content=\"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/\" \/>\n<meta property=\"og:site_name\" content=\"m2apartners.cz\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-04T13:27:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-27T16:06:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"940\" \/>\n\t<meta property=\"og:image:height\" content=\"788\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin3645\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin3645\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/\"},\"author\":{\"name\":\"admin3645\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#\\\/schema\\\/person\\\/2737d6d592b954976f2a3fdcb4e8248e\"},\"headline\":\"Cybersecurity, Part Three &#8211; Incidents\",\"datePublished\":\"2024-10-04T13:27:00+00:00\",\"dateModified\":\"2025-03-27T16:06:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/\"},\"wordCount\":524,\"publisher\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Simple-Law-Firm-Facebook-Post-1.jpg\",\"keywords\":[\"Cybernetics\",\"EU legislation\",\"legislation\",\"Proposal\",\"protection\",\"Security\"],\"articleSection\":[\"Articles\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/\",\"url\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/\",\"name\":\"Cybersecurity, Part Three - Incidents - m2apartners.cz\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Simple-Law-Firm-Facebook-Post-1.jpg\",\"datePublished\":\"2024-10-04T13:27:00+00:00\",\"dateModified\":\"2025-03-27T16:06:06+00:00\",\"description\":\"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#primaryimage\",\"url\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Simple-Law-Firm-Facebook-Post-1.jpg\",\"contentUrl\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2024\\\/10\\\/Simple-Law-Firm-Facebook-Post-1.jpg\",\"width\":940,\"height\":788},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/cybersecurity-part-three-incidents\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity, Part Three - Incidents\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/\",\"name\":\"m2apartners.cz\",\"description\":\"We focus on providing legal services to clients in the pharmaceutical and medical device industries, in corporate matters, in connection with the setting up of internal processes, in matters of zoning and construction law proceedings, in general practice, especially general contract, real estate, family and employment law.\",\"publisher\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#organization\",\"name\":\"M2A Partners\",\"url\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/cropped-cropped-FAV_512x512.png\",\"contentUrl\":\"https:\\\/\\\/m2apartners.cz\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/cropped-cropped-FAV_512x512.png\",\"width\":512,\"height\":512,\"caption\":\"M2A Partners\"},\"image\":{\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/m2apartners.cz\\\/en\\\/#\\\/schema\\\/person\\\/2737d6d592b954976f2a3fdcb4e8248e\",\"name\":\"admin3645\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g\",\"caption\":\"admin3645\"},\"sameAs\":[\"https:\\\/\\\/m2apartners.cz\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybersecurity, Part Three - Incidents - m2apartners.cz","description":"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/","og_locale":"en_US","og_type":"article","og_title":"Cybersecurity, Part Three - Incidents - m2apartners.cz","og_description":"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal","og_url":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/","og_site_name":"m2apartners.cz","article_published_time":"2024-10-04T13:27:00+00:00","article_modified_time":"2025-03-27T16:06:06+00:00","og_image":[{"width":940,"height":788,"url":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg","type":"image\/jpeg"}],"author":"admin3645","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin3645","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#article","isPartOf":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/"},"author":{"name":"admin3645","@id":"https:\/\/m2apartners.cz\/en\/#\/schema\/person\/2737d6d592b954976f2a3fdcb4e8248e"},"headline":"Cybersecurity, Part Three &#8211; Incidents","datePublished":"2024-10-04T13:27:00+00:00","dateModified":"2025-03-27T16:06:06+00:00","mainEntityOfPage":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/"},"wordCount":524,"publisher":{"@id":"https:\/\/m2apartners.cz\/en\/#organization"},"image":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#primaryimage"},"thumbnailUrl":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg","keywords":["Cybernetics","EU legislation","legislation","Proposal","protection","Security"],"articleSection":["Articles"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/","url":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/","name":"Cybersecurity, Part Three - Incidents - m2apartners.cz","isPartOf":{"@id":"https:\/\/m2apartners.cz\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#primaryimage"},"image":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#primaryimage"},"thumbnailUrl":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg","datePublished":"2024-10-04T13:27:00+00:00","dateModified":"2025-03-27T16:06:06+00:00","description":"You must register the regulated service within 60 days of meeting the conditions for registration. Registration will be done through the NUCIB Portal","breadcrumb":{"@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#primaryimage","url":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg","contentUrl":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2024\/10\/Simple-Law-Firm-Facebook-Post-1.jpg","width":940,"height":788},{"@type":"BreadcrumbList","@id":"https:\/\/m2apartners.cz\/en\/cybersecurity-part-three-incidents\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/m2apartners.cz\/en\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity, Part Three - Incidents"}]},{"@type":"WebSite","@id":"https:\/\/m2apartners.cz\/en\/#website","url":"https:\/\/m2apartners.cz\/en\/","name":"m2apartners.cz","description":"We focus on providing legal services to clients in the pharmaceutical and medical device industries, in corporate matters, in connection with the setting up of internal processes, in matters of zoning and construction law proceedings, in general practice, especially general contract, real estate, family and employment law.","publisher":{"@id":"https:\/\/m2apartners.cz\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/m2apartners.cz\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/m2apartners.cz\/en\/#organization","name":"M2A Partners","url":"https:\/\/m2apartners.cz\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/m2apartners.cz\/en\/#\/schema\/logo\/image\/","url":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2025\/03\/cropped-cropped-FAV_512x512.png","contentUrl":"https:\/\/m2apartners.cz\/wp-content\/uploads\/2025\/03\/cropped-cropped-FAV_512x512.png","width":512,"height":512,"caption":"M2A Partners"},"image":{"@id":"https:\/\/m2apartners.cz\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/m2apartners.cz\/en\/#\/schema\/person\/2737d6d592b954976f2a3fdcb4e8248e","name":"admin3645","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/baf40bb2dd82590384e4496ea9a16e5723a6284ec7fb445ad629f19905b6c337?s=96&d=mm&r=g","caption":"admin3645"},"sameAs":["https:\/\/m2apartners.cz"]}]}},"_links":{"self":[{"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/posts\/6025","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/comments?post=6025"}],"version-history":[{"count":1,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/posts\/6025\/revisions"}],"predecessor-version":[{"id":6026,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/posts\/6025\/revisions\/6026"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/media\/5609"}],"wp:attachment":[{"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/media?parent=6025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/categories?post=6025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m2apartners.cz\/en\/wp-json\/wp\/v2\/tags?post=6025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}