Contact
Silhouette of a person in front of a large screen filled with blue and green lines of data

Library

Incident response

Share via

What does an organisation do in the first 24 hours after a cyber incident?

Incident response is the structured handling of a cyber incident, from the first signal through to recovery and evaluation. The first 24 hours mainly decide whether the evidence survives and whether the organisation meets the statutory reporting deadlines. Under the Dutch Cybersecurity Act, in force since 15 August 2026, an early warning is due within 24 hours, followed by a notification within 72 hours.

Those deadlines keep running while the investigation is still under way. An organisation therefore reports on incomplete information, while recovery actions must not erase the traces that same investigation needs. That tension makes the first day difficult, not the technology.

Incident response is not a purely technical discipline. An incident affects continuity and liability at the same time. The question is not only who removes the attacker, but also who decides that.

In this article

What is incident response and when is something a cyber incident?

Incident response begins at detection and ends at the evaluation. Digital forensics is the investigative part that establishes what exactly happened. The two are often named in one breath as DFIR.

Not every alert is an incident. A blocked phishing email belongs to the normal work of administration and monitoring. There is an incident only when an attack actually affects systems or data.

The Dutch Cybersecurity Act also uses the term significant incident. The act applies that label to serious operational disruption. Financial loss or considerable damage to others can meet the threshold as well, and ministerial regulations set concrete threshold values per sector.

What happens in the first 24 hours?

The first question is whether the incident is still active. As long as an attacker has access, every recovery action changes the picture and a visible intervention may alert them. Isolation therefore comes before clean-up, and securing evidence comes before reinstallation.

The reflex to reinstall an infected machine straight away often costs the evidence that turns out to be needed later. Memory and log files disappear on a reboot, and without that data it stays unclear which information was accessed or taken. That is precisely what the supervisor will want to know afterwards.

The governance line runs in parallel. Someone decides on shutting down systems and informing customers. The moment the report goes out calls for a decision too.

When must a cyber incident be reported, and to whom?

Several reporting duties run at the same time, each with its own deadlines and its own desk. Reporting under the Dutch Cybersecurity Act happens in three steps, through a single central desk on MijnNCSC. A report there reaches both the supervisor and the sectoral Computer Security Incident Response Team, or CSIRT.

ObligationDeadlineWhere to reportEarly warning, Dutch Cybersecurity ActWithin 24 hoursMijnNCSCNotification, Dutch Cybersecurity ActWithin 72 hoursMijnNCSCFinal report, Dutch Cybersecurity ActWithin 1 month of the notificationMijnNCSCData breach notification, GDPR article 33Within 72 hoursDutch Data Protection AuthorityNotice to data subjects, GDPR article 34Without undue delay at high riskDirectly to the data subjects

The clock starts as soon as the organisation becomes aware of the incident, not once the investigation is complete. A voluntary report goes only to the CSIRT and not to the supervisor. An organisation caught by both regimes runs two timelines side by side, with different recipients and a different purpose.

What does the NCSC do, and what does it not do?

The NCSC supports incidents primarily in the identification phase. For containment, eradication and recovery the NCSC calls it essential to involve a specialised IR party in good time. Ultimate responsibility for the response stays with the affected organisation.

That distinction determines who gets called on day one. The CSIRT provides interpretation and advice on the threat. The organisation and its suppliers carry out the forensic investigation and the rebuild.

The supervisor also has a different role from the CSIRT. The CSIRT supports during the incident, the supervisor assesses compliance afterwards. The same report reaches both, but they read it with a different interest.

How does an engagement proceed after the first days?

Containment is followed by the question of how large the incident is. Investigation establishes which systems and data were affected, and which path the attacker used to get in. Without that picture recovery is guesswork, because the way in may still be open.

Recovery is rarely a matter of restoring a back-up. In a compromised identity environment the organisation replaces passwords and keys, and rebuilds the underlying trust relationships. In environments with OT there is the added question of which production can keep running during recovery.

The engagement ends with an evaluation and an improvement plan. At that same moment the organisation prepares the final report for the supervisor. Findings that do not make it into that report usually disappear from the improvement agenda as well.

When is an incident response retainer worthwhile?

A retainer sets out in advance who will come and how quickly. The value lies less in the response time than in the fact that procurement and introductions are already behind you. Without arrangements, the first day often goes to arranging access and aligning expectations.

A retainer is worthwhile above all when downtime has immediate financial or societal consequences. That applies to organisations under the Dutch Cybersecurity Act and to service providers with contractual recovery deadlines. For organisations with limited dependence on IT, the fixed fee weighs heavier than the benefit.

More important than the contract is the preparation around it. Current network documentation and log sources with sufficient retention determine how quickly an external team can really work. Without that basis the team is ready quickly, but the investigation gets going slowly.

Conclusion

Incident response determines how much damage an attack ultimately causes. The first 24 hours are about preserving evidence, containing access and meeting the reporting deadline. Those three can get in each other's way, and preparation makes the difference between a moment of panic and a moment of control.

The main limitation is that no plan determines the size of an incident in advance. What a plan does do is prevent the first decisions from making the investigation impossible.

Which DeepBlue services fit this work

DeepBlue Security & Intelligence supports organisations during incidents in complex IT and OT environments, with senior specialists only. DeepBlue processes and stores investigation data on its own infrastructure in the Netherlands. Which services fit depends on the sector and on the organisation's dependence on IT.

  • Incident response and digital forensics supports triage, containment and forensic investigation, and produces the facts needed for the notification and the final report.
  • Managed SOC provides continuous detection and response, so a significant incident is noticed while the reporting deadline still leaves room to act.
  • Penetration testing establishes whether technical measures hold under realistic attack conditions, across IT, cloud, applications, OT and identity environments.
  • Compliance and governance translates the duty of care into processes, roles and evidence, including the documentation that makes a board decision demonstrable.
  • CISO as a Service takes on the governance of incident preparation, prioritisation and reporting to executive management and the board.

If the scope of the reporting duty still has to be established, the basics are set out in The Dutch Cybersecurity Act: 15 August 2026 and in Ten supervisors, one Dutch cyber act. An incident response engagement guarantees no quick recovery. It does produce a substantiated picture of what happened and of the measures that reduce the risk of a repeat.

Sources

NCSC, Reporting duty under the Cyberbeveiligingswet | NCSC, Help and support during cyber incidents | NCSC, Incident response plan | Rijksoverheid, Cbw and Wwke in force from 15 August 2026 | Cyberbeveiligingswet, Bulletin of Acts 2026, 187 | Regulation (EU) 2016/679, GDPR

Last reviewed: 1 September 2026.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.