Skip to main content
PLATFORM · INCIDENT & RESILIENCE

The clock starts the moment you know.

Under NIS2, an incident is not done when it is fixed. The reporting clock — early warning within 24 hours, full notification within 72, final report within a month — starts at the moment you become aware, whether or not anyone has opened the right spreadsheet.

TruSecure's structured incident workflows start the regulatory clock automatically at logging, pre-build each report stage from the last, and connect to business-continuity and resilience-testing evidence for DORA and ISO 22301. The timeline below is the obligation itself — the product is organized around it:

0H
Incident logged
Clock starts automatically
24H
Early warning
Cross-border? Unlawful?
72H
Full notification
Severity + impact assessment
1 MO
Final report
Root cause + remediation

How it works

  1. Log

    An incident is recorded once — from a connected SIEM/SOAR alert, a ticketing system, or by hand. Logging starts the regulatory clock automatically.

  2. Classify

    Severity, cross-border impact and unlawful-access questions are structured into the workflow, because the 24-hour early warning depends on the answers.

  3. Report

    Each report stage is pre-built from the last: the 72-hour notification inherits the early warning; the final report inherits both, plus root cause and remediation.

  4. Learn

    The post-incident review feeds back into the control model — the weakness the incident exposed becomes a tracked remediation, not a lesson that evaporates.

Which regulations it maps to

Incident and resilience obligations · by framework
FrameworkWhat it expectsCitation
NIS2Staged incident reporting against hard deadlinesArt. 23
DORAIncident classification, reporting and resilience testingArt. 17 · 19
ISO 22301Business-continuity capability, exercised on evidenceTesting program

Where the signals come from

SIEM/SOAR connectors supply detections and case data; ITSM connectors supply incident tickets and remediation tracking; collaboration connectors preserve the communication log around an incident — approvals included — for the audit trail.

See all integrations

The monitoring loop

continuous · every 6 hours
  1. 01

    Connect

    Read-only connectors into AWS, Azure, GCP, on-premise.

    AWSAzureGCPon-prem
  2. 02

    Collect

    AI pulls compliance evidence every 6 hours — not at audit time.

    every 6 h
  3. 03

    Detect

    Gaps and control drift flagged the moment they appear.

    24/7
  4. 04

    Remediate

    Routine fixes closed automatically; the rest routed to you.

    auto
  5. 05

    Approve

    A named person decides. The approval is the record.

    logged
90% less manual evidence work100% audit-ready, every day

The 80/20 advantage. AI handles the tedium — evidence, testing, gap analysis, routine fixes. Your team keeps the interesting 20%: strategic decisions, policy exceptions, risk acceptance.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

How does TruSecure support NIS2 incident reporting?
Structured incident workflows start the regulatory clock automatically the moment an incident is logged, tracking the 24-hour early-warning and 72-hour notification deadlines with pre-built evidence at each stage.
Does it cover resilience testing?
Yes — incident workflows connect to resilience-testing evidence, covering DORA and ISO 22301 expectations alongside NIS2 incident handling.
Where does incident data come from?
Detection and incident data bridges in from the tools you already operate, so an incident lands in the governance record directly rather than being re-entered by hand.