← All news

The first 72 hours matter

Effective Organizational Response to Security Incidents (NIS2) & data breaches (GDPR)

Alexandru Gheorghe presenting "The First 72 Hours Matter" to an audience at DevTalks Romania 2026

When a security incident hits, the clock starts before anyone has agreed on what happened. NIS2 and GDPR both impose notification deadlines measured in hours, and they run whether or not your organisation is ready to answer the questions those notifications ask.

This is a summary of Alexandru Gheorghe's talk at DevTalks Romania 2026. The full slide deck is available here: Download the slides (PDF).

What NIS2 actually requires

Three obligations sit at the centre of the directive:

  • an Incident Response Policy must exist — art. 13(b) NIS2;
  • an incident management process must be defined — art. 13(g) NIS2;
  • cybersecurity incidents must be reported to the Incident Response Team (IRT) and the National Cybersecurity Authority.

The reporting timeline is staged, and each stage has its own deadline:

DeadlineWhat is due
6 hoursInitial early warning
24 hoursEarly warning
72 hoursImpact and consequences update report
30 daysFinal report

Failure to comply carries real penalties. Essential Entities face fines up to 10M EUR or 2% of annual net turnover; Important Entities up to 7M EUR or 2% of annual net turnover.

The cost nobody budgets for

Incident response is usually discussed as a technical problem. It is also a straightforward cost centre.

For a medium-sized company, an average of seven people are pulled into almost every incident, at roughly 7,500 EUR per incident over 72 hours — plus the opportunity cost of taking those seven people off their actual work.

Two things are worth noting about that figure. It assumes the people involved are not engaged constantly, and it is calculated for Romania. More importantly, it covers only the alignment overhead — the work of assessing the incident and deciding whether and how to notify. It does not include the teams who deal with the impact itself: tech and product, customer support, customer care.

The seven roles that typically converge on an incident are the CISO, DPO, Legal, CIO, Management, PR, and external consultants.

Why plans fail exactly when speed matters

In crisis escalation, time is of the essence — yet most incident management plans do not produce a quick resolution. Six recurring reasons:

  • unclear escalation paths in the first stages of incident response;
  • increased coordination overhead between decision-making stakeholders;
  • lack of appropriate expertise in most companies;
  • time-critical reporting deadlines imposed by law — 24 hours under NIS2;
  • uncertainty in the impact assessment and the required legal next steps;
  • missing traceability of actions taken, leading to loss of organizational memory.

Read together, these are not really technical failures. They are coordination failures — and they happen in the window where the legal clock is already running.

The future of incident response

That coordination gap is what Mundford is built to close: an AI agent for the first stages of a cyber security incident or data breach.

Mundford combines the essential expertise of a CISO, a lawyer and a DPO so an organisation can respond rapidly and meet strict European legal deadlines — GDPR, NIS2, DORA and the AI Act. It recommends what to do in under 30 minutes after an incident, starting with immediate legal obligations, and helps submit the correct incident notification forms to the authorities.

From incident to legal next steps in 30 minutes, without the cross-team scramble.

Talk to us

If you are working through NIS2 readiness or want your incident response process tested before it is tested for you, get in touch at hello@datatrail.eu or (+40) 723 311 237.

The slides from this talk are available as a PDF: The first 72 hours matter — DevTalks Romania 2026.